1
00:00:00,090 --> 00:00:00,930
In this lesson,

2
00:00:00,930 --> 00:00:03,900
we're going to discuss the concept of a gap analysis.

3
00:00:03,900 --> 00:00:05,760
Now, a gap analysis is a process

4
00:00:05,760 --> 00:00:07,020
of evaluating the differences

5
00:00:07,020 --> 00:00:08,940
between organization's current performance

6
00:00:08,940 --> 00:00:10,740
and its desired performance.

7
00:00:10,740 --> 00:00:12,810
The goal of the analysis is to identify areas

8
00:00:12,810 --> 00:00:15,270
where improvements can be made in order to bridge the gap

9
00:00:15,270 --> 00:00:17,550
between the current and desired states.

10
00:00:17,550 --> 00:00:20,190
Conducting a gap analysis can be a really valuable tool

11
00:00:20,190 --> 00:00:21,210
for organizations

12
00:00:21,210 --> 00:00:23,670
that are looking to improve their operations, processes,

13
00:00:23,670 --> 00:00:26,850
performance or overall cybersecurity posture.

14
00:00:26,850 --> 00:00:28,320
Now, there are several steps involved

15
00:00:28,320 --> 00:00:30,270
in conducting a gap analysis.

16
00:00:30,270 --> 00:00:32,970
The first step is to define the scope of the analysis.

17
00:00:32,970 --> 00:00:34,860
This includes identifying the specific areas

18
00:00:34,860 --> 00:00:36,690
of the organization that will be evaluated

19
00:00:36,690 --> 00:00:39,210
and the desired outcome of that analysis.

20
00:00:39,210 --> 00:00:40,620
The next step is to gather data

21
00:00:40,620 --> 00:00:42,600
on the current state of the organization.

22
00:00:42,600 --> 00:00:44,460
This can be done through surveys, interviews

23
00:00:44,460 --> 00:00:46,290
or other forms of data collection.

24
00:00:46,290 --> 00:00:47,820
Once that data has been gathered,

25
00:00:47,820 --> 00:00:49,800
it should be analyzed to identify any areas

26
00:00:49,800 --> 00:00:52,260
where the organization's current performance falls short

27
00:00:52,260 --> 00:00:54,180
of its desired performance.

28
00:00:54,180 --> 00:00:55,920
Once those gaps have been identified,

29
00:00:55,920 --> 00:00:59,160
our next step is to develop a plan to bridge those gaps.

30
00:00:59,160 --> 00:01:01,440
This can include changes to processes, systems

31
00:01:01,440 --> 00:01:03,300
or other areas of the organization

32
00:01:03,300 --> 00:01:04,620
that can help to improve the performance

33
00:01:04,620 --> 00:01:06,990
or security of your systems and networks.

34
00:01:06,990 --> 00:01:08,790
The plan should also include specific goals

35
00:01:08,790 --> 00:01:11,670
and objectives as well as a timeline for achieving them.

36
00:01:11,670 --> 00:01:12,570
For example,

37
00:01:12,570 --> 00:01:14,610
if a company wanted to migrate their data storage

38
00:01:14,610 --> 00:01:17,220
from their on-premise solution to a cloud-based solution,

39
00:01:17,220 --> 00:01:19,560
they should consider how this might affect their security.

40
00:01:19,560 --> 00:01:21,600
To ensure a smooth and secure transition,

41
00:01:21,600 --> 00:01:24,780
your company might perform a comprehensive gap analysis.

42
00:01:24,780 --> 00:01:25,613
This might begin

43
00:01:25,613 --> 00:01:27,840
by evaluating your on-premise security measures,

44
00:01:27,840 --> 00:01:30,270
which includes your firewalls, intrusion detection systems

45
00:01:30,270 --> 00:01:32,010
and data access controls.

46
00:01:32,010 --> 00:01:33,720
After documenting this current state,

47
00:01:33,720 --> 00:01:36,060
you can then compare it to the desired security standards

48
00:01:36,060 --> 00:01:37,530
for their chosen cloud provider

49
00:01:37,530 --> 00:01:39,810
which might be AWS, or Azure.

50
00:01:39,810 --> 00:01:41,880
Then the gap analysis can be used to highlight

51
00:01:41,880 --> 00:01:44,370
that their existing data encryption methods are outdated

52
00:01:44,370 --> 00:01:46,020
and they're not in line with the cloud's

53
00:01:46,020 --> 00:01:48,150
more advanced encryption at rest protocols.

54
00:01:48,150 --> 00:01:50,460
Additionally, their on-premise access controls

55
00:01:50,460 --> 00:01:51,990
might not be able to be mapped directly

56
00:01:51,990 --> 00:01:53,880
to the cloud's identity and access management

57
00:01:53,880 --> 00:01:55,230
or IAM models.

58
00:01:55,230 --> 00:01:57,630
So this is a gap that also needs to be addressed.

59
00:01:57,630 --> 00:01:59,610
Now that the company knows their current state

60
00:01:59,610 --> 00:02:01,950
their desired state, and the difference between the two,

61
00:02:01,950 --> 00:02:04,080
they're now better equipped to plan their migration

62
00:02:04,080 --> 00:02:05,220
while ensuring they've adopted

63
00:02:05,220 --> 00:02:06,870
enhanced encryption techniques

64
00:02:06,870 --> 00:02:09,750
and made the necessary modifications to their IAM policies

65
00:02:09,750 --> 00:02:11,220
to create an overall more secure

66
00:02:11,220 --> 00:02:13,530
and seamless migration into the cloud.

67
00:02:13,530 --> 00:02:14,880
Now, in general, you're going to find

68
00:02:14,880 --> 00:02:17,130
that there are two basic types of a gap analysis.

69
00:02:17,130 --> 00:02:18,690
We have a technical gap analysis

70
00:02:18,690 --> 00:02:20,550
and a business gap analysis.

71
00:02:20,550 --> 00:02:23,340
A technical gap analysis in the world of cloud computing

72
00:02:23,340 --> 00:02:24,420
would involve evaluating

73
00:02:24,420 --> 00:02:26,790
an organization's current technical infrastructure

74
00:02:26,790 --> 00:02:27,990
and identifying any areas

75
00:02:27,990 --> 00:02:30,690
where it falls short of the technical capabilities required

76
00:02:30,690 --> 00:02:33,300
to fully utilize their security solutions.

77
00:02:33,300 --> 00:02:35,460
For example, an organization might find

78
00:02:35,460 --> 00:02:36,840
that its current network infrastructure

79
00:02:36,840 --> 00:02:38,757
is simply not fast enough to support data

80
00:02:38,757 --> 00:02:42,420
and transit encryption or a full zero trust architecture,

81
00:02:42,420 --> 00:02:45,330
or that its current security protocols are not robust enough

82
00:02:45,330 --> 00:02:47,250
to protect the data being stored at rest,

83
00:02:47,250 --> 00:02:49,650
inside of their cloud-based storage solution.

84
00:02:49,650 --> 00:02:52,530
Once those gaps have been identified, now the organization

85
00:02:52,530 --> 00:02:54,510
can develop a plan to address these issues

86
00:02:54,510 --> 00:02:57,270
and upgrade its technical infrastructure as needed.

87
00:02:57,270 --> 00:02:59,910
Now, on the other hand, we have a business gap analysis

88
00:02:59,910 --> 00:03:00,930
that involves evaluating

89
00:03:00,930 --> 00:03:03,090
the organization's current business processes

90
00:03:03,090 --> 00:03:04,410
and identifying any areas

91
00:03:04,410 --> 00:03:06,690
where they fall short of the capabilities required

92
00:03:06,690 --> 00:03:09,600
to fully utilize their new cloud-based solutions.

93
00:03:09,600 --> 00:03:11,610
For example, an organization may find

94
00:03:11,610 --> 00:03:13,380
that its current data management processes

95
00:03:13,380 --> 00:03:15,840
are not efficient enough to support cloud-based data storage

96
00:03:15,840 --> 00:03:18,000
and sharing, or that its current budgeting

97
00:03:18,000 --> 00:03:20,370
and forecasting processes are not accurate enough

98
00:03:20,370 --> 00:03:22,740
to support cloud-based financial management.

99
00:03:22,740 --> 00:03:24,420
Once the gaps have been identified

100
00:03:24,420 --> 00:03:26,250
then the organization can develop a plan

101
00:03:26,250 --> 00:03:27,990
to move its business processes forward

102
00:03:27,990 --> 00:03:30,060
as needed to close that gap.

103
00:03:30,060 --> 00:03:32,490
Now, let's take a look at a real world example.

104
00:03:32,490 --> 00:03:34,800
At one of my formal organizations that I worked at,

105
00:03:34,800 --> 00:03:37,170
we conducted a vulnerability assessment once per week

106
00:03:37,170 --> 00:03:38,970
across the entire network.

107
00:03:38,970 --> 00:03:40,620
This vulnerability assessment was designed

108
00:03:40,620 --> 00:03:42,870
to uncover weak points in our digital infrastructure

109
00:03:42,870 --> 00:03:44,040
and systems.

110
00:03:44,040 --> 00:03:46,530
The assessment often found several software vulnerabilities

111
00:03:46,530 --> 00:03:47,670
in our different servers,

112
00:03:47,670 --> 00:03:49,860
some insufficient encryption for data in transit,

113
00:03:49,860 --> 00:03:50,693
and a few times

114
00:03:50,693 --> 00:03:53,400
we found outdated database configurations too.

115
00:03:53,400 --> 00:03:55,200
Each week, my team and I were responsible

116
00:03:55,200 --> 00:03:57,390
for looking over all the findings from the assessment

117
00:03:57,390 --> 00:03:59,430
and then determining which ones were the highest priority

118
00:03:59,430 --> 00:04:02,130
for us to fix because we never have enough time, money

119
00:04:02,130 --> 00:04:05,400
or resources to fix all of them in any given week.

120
00:04:05,400 --> 00:04:07,530
By understanding the seriousness of each finding,

121
00:04:07,530 --> 00:04:09,810
we could then create a Plan of Action and Milestones,

122
00:04:09,810 --> 00:04:11,850
known as a POA&M

123
00:04:11,850 --> 00:04:13,500
and that would outline the specific measures

124
00:04:13,500 --> 00:04:16,320
to address each vulnerability and allocate resources

125
00:04:16,320 --> 00:04:18,540
and set up timelines for each of the remediation tasks

126
00:04:18,540 --> 00:04:19,950
that we needed to perform.

127
00:04:19,950 --> 00:04:21,690
This allowed us to prioritize the patching

128
00:04:21,690 --> 00:04:23,280
of critical software vulnerabilities

129
00:04:23,280 --> 00:04:26,040
and updating those database misconfigurations first.

130
00:04:26,040 --> 00:04:28,410
At the same time, we now know what the level of security

131
00:04:28,410 --> 00:04:29,670
is that we're trying to achieve

132
00:04:29,670 --> 00:04:32,250
and our POA&M was an actionable way to get us

133
00:04:32,250 --> 00:04:34,350
from our current state to our desired state

134
00:04:34,350 --> 00:04:36,780
and this helped us continually close the gap identified

135
00:04:36,780 --> 00:04:38,370
by our ongoing gap analysis

136
00:04:38,370 --> 00:04:40,890
in terms of our vulnerability management programs.

137
00:04:40,890 --> 00:04:44,310
So remember, a gap analysis really is a powerful tool

138
00:04:44,310 --> 00:04:46,920
that can help your organization to improve its security

139
00:04:46,920 --> 00:04:47,910
and its performance

140
00:04:47,910 --> 00:04:50,520
by identifying areas where improvements can be made.

141
00:04:50,520 --> 00:04:52,260
Whether you're looking to migrate into the cloud

142
00:04:52,260 --> 00:04:54,450
or you simply want to improve the security of your systems

143
00:04:54,450 --> 00:04:55,283
and networks,

144
00:04:55,283 --> 00:04:58,230
a gap analysis can help to achieve the desired outcomes

145
00:04:58,230 --> 00:04:59,640
and results for you.

146
00:04:59,640 --> 00:05:02,100
By following the steps of a gap analysis, you can ensure

147
00:05:02,100 --> 00:05:03,750
that you have a comprehensive plan in place

148
00:05:03,750 --> 00:05:05,520
to bridge the gap between your current

149
00:05:05,520 --> 00:05:06,813
and your desired states.

