IronSights

Compliance & governance

Gap analysis

An assessment that compares an organisation's current security posture against a target framework or standard, identifying the specific controls that are missing, partially implemented, or not meeting required maturity levels.

Also known assecurity gap analysiscontrol gap analysis

In plain English

A gap analysis answers the question: "What do we need to do to meet this standard?" It maps your current controls against the requirements of a framework — the Essential Eight, ISO 27001, or a client's security questionnaire — and produces a prioritised list of what needs to change, giving you a clear remediation roadmap.

Keep learning

More terms in the IronSights Glossary.