Gap Analysis
Definition
The process of comparing what a framework requires against what an organisation has actually implemented, to identify controls that are absent, partial, or non-evidenced. In the mapping context, gap analysis also identifies framework-specific requirements that have no equivalent in the other frameworks in scope, since those cannot be covered by shared evidence.
- Purpose
- Compares framework requirements against implemented controls
- Output
- List of absent, partial, or non-evidenced controls
- Multi-framework use
- Flags requirements unique to one framework with no cross-framework equivalent
Common questions
How does gap analysis differ from a standard compliance audit?+
An audit typically confirms whether existing controls operate as designed and produces a pass or fail finding, while gap analysis starts earlier by identifying which required controls are missing or only partially built, so it is often the step performed before remediation planning rather than final sign-off.
What happens to gaps found when mapping several frameworks together?+
Requirements that have no equivalent in any other framework in scope cannot be satisfied by shared evidence, so each one needs its own dedicated control and evidence trail rather than being covered by work done for a different standard.
Why does a control marked as 'non-evidenced' still count as a gap?+
A control that exists operationally but lacks documented proof of its operation cannot be relied on in an audit or investigation, since assessors and courts generally require evidence of a control functioning, not just an assertion that it does.
Related terms
- Control Catalogue
- A structured list of security controls, each with an identifier, a statement of intent, and (in detailed catalogues) implementation guidance. Examples include...
- Control Family
- A grouping of related controls within a catalogue. NIST SP 800-53 uses 20 families identified by two-letter codes: AC (Access Control), AU...
- Crosswalk
- A published table that aligns controls from two frameworks side by side to show which controls address the same security objective. NIST,...
- Implementation Group (IG)
- A CIS Controls concept that divides the 153 safeguards across three tiers by organisational size and risk profile. IG1 (56 safeguards) covers...
- Unified Control Mapping
- An organisation-specific artefact that consolidates multiple crosswalks into a single table, adds columns for the organisation's own control implementations and evidence artefacts,...