Gap analysis
Also known as: gap assessment
A comparison of what an organisation does today with the requirements it wants to meet.
Draft - this entry has not been reviewed yet.
Formal
A structured review that holds current practice against each requirement of a chosen law, standard or framework, records each requirement as met, partly met or missing, and ranks the gaps by risk and effort into an action plan.
In plain English
Holding your half-packed suitcase against the packing list to see what you still need to buy before the trip.
In practice
A consultant sits down with the operations manager of a Danish water utility, goes through the NIS2 minimum requirements one by one and finds that no logs are kept and suppliers face no security terms; the result becomes a 12-month plan for the board.
Why it matters
Without it, time and money go to whatever feels urgent rather than the biggest holes, and there is no baseline to show progress to management or an authority later.
How to put it into practice
The usual steps, in order. Adapt them to your organisation.
- Choose the requirement baseline and scope - for example NIS2 Art. 21, ISO 27001 clauses 4-10 and Annex A, or a NIST CSF 2.0 target profile - and agree which units and outsourced services are included.
- Break the baseline down into testable statements and pick a scale, such as met, partly met and missing, or a 0-5 maturity scale with evidence criteria for each level.
- Collect evidence through interviews, document reviews and spot checks of records such as access reviews or restore tests.
- For each requirement, record the current state, the evidence seen, the target state and a description of the gap.
- Rate each gap by the risk it leaves and the effort needed to close it, and rank the gaps by risk reduction per unit of effort.
- Turn the ranked gaps into a roadmap with owners, deadlines and budget, and have management approve it.
- Feed the result into risk treatment and the security objectives, and track the actions in the same register.
- Repeat the same assessment on the same scale at fixed intervals, typically yearly or before an audit, to show progress.
Common pitfalls
- Scoring a requirement as met because a policy exists, without checking that anyone follows it.
- Assessing only the IT department when the NIS2 or ISO 27001 scope covers the whole organisation and its suppliers.
- Changing the scale between rounds, so progress cannot be compared.
- Treating the gap list as the risk assessment and closing low-risk gaps before high-risk ones.
Good guides
- NIST SP 1301 - CSF 2.0 Quick-Start Guide for Creating and Using Organizational Profiles(opens in a new tab) · NIST
- NIS2 Technical Implementation Guidance(opens in a new tab) · ENISA
- Cyber Assessment Framework (CAF)(opens in a new tab) · NCSC UK
- Vejledning i etablering og drift af et ledelsessystem for informationssikkerhed (ISMS) med udgangspunkt i ISO 27001(opens in a new tab) · Digitaliseringsstyrelsen (in Danish)
- Implementering af NIS 2 i dansk ret(opens in a new tab) · Styrelsen for Samfundssikkerhed (in Danish)
Technical deep dive
A gap analysis has three inputs: a requirement baseline, an assessment scale and evidence of current practice. The baseline must be decomposed to testable statements; NIS2 Art. 21(2) lists ten measure areas, (a) risk analysis and security policies through (j) MFA and secured communications, but each needs to be broken down, for example using Commission Implementing Regulation (EU) 2024/2690 for the digital-infrastructure and digital-service entities it covers, or national guidance, before it can be scored. ISO/IEC 27001:2022 is usually assessed clause by clause for 4-10 plus the 93 Annex A controls; NIST CSF 2.0 (February 2024) formalises the approach as a comparison between a Current Profile and a Target Profile across its six functions, now including Govern.
Scales range from binary (met/not met) through three-level (met, partial, missing) to maturity models on a 0-5 scale inspired by CMMI, where for example 0 means non-existent, 1 ad hoc, 2 repeatable, 3 defined, 4 managed and measured, and 5 optimised. The choice matters: binary scales hide progress, while maturity scales invite inflated self-scoring unless each level has explicit evidence criteria. A robust assessment records, per requirement, the current state, the evidence reviewed, the target state, the gap description, a risk rating of the gap and an estimated effort, so that prioritisation can be done on risk reduction per unit of effort rather than on perceived urgency.
Evidence depth distinguishes a gap analysis from an audit. Gap analyses are usually interview- and document-based and performed by the organisation or a consultant as advisory work, without formal sampling or independence requirements. That makes them fast, but also prone to "paper compliance": a policy exists, so the requirement is scored as met although nobody follows it. Spot checks of records, such as a sample of user access reviews or restore-test logs, sharply improve reliability. It also differs from a risk assessment: a gap analysis measures distance to a requirement set, whereas a risk assessment measures exposure to threats; a gap on a low-risk requirement may rightly be accepted, and a fully compliant organisation can still carry significant risk.
The output feeds planning: in ISO 27001 terms it informs 6.1.3 risk treatment and 6.2 objectives, and in practice it is converted into a compliance roadmap. Re-running the same assessment at fixed intervals, typically annually or before a certification or supervisory audit, turns it into a measurement of progress in the Check phase of PDCA. Scoping errors are the commonest failure: assessing only the IT department when NIS2 or ISO 27001 scope covers the whole organisation, or omitting outsourced services that still fall under the entity's responsibility.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →Gap analysis
Relationships
- Requires
- Compliance
- Unlocks
- Compliance roadmap
- Don't confuse with
- Audit
Sources & further reading
Course material
- Cyber Security Fast Track - Ordliste
- Cyber Security Fast Track - Kursuskompendium, Modul 3
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…