WaveGard
Policy gap analysis
Security Services
Policy Gap Analysis

A WaveGard Policy Gap Analysis project provides our clients with a
structured mentoring process for commencing the design of a new security
policy framework or evaluating an existing framework. Clients who choose the Gap Analysis ultimately benefit from an understanding of the positive components within their security policy framework as well as deficiencies that must be addressed. The process directly incorporates regulatory compliance topics and technical controls to define the initial security posture for the organization. The review result is a clearly written deliverable that identifies critical findings, recommended next steps, and areas that should be considered for further review.

A Policy Gap Analysis project often includes the following steps:

  • In-depth discussions with the client to understand the existing environment and define the goals of the security program
  • Review copies of existing policies, procedures, standards, and related documentation to understand what type of framework exists in the environment
  • Identify the regulatory considerations that are being targeted such as: SOX, HIPAA, GLBA, FISMA (C&A), PCI, or others
  • Identify a standardized approach against which the program can be mapped such as ISO 17799, COBIT, NIST, or others.
  • Analyze the information to identify areas of compliance or weakness
  • Succinctly document the findings, including recommended next steps

The Gap Analysis process is often used by our clients as a way of creating a baseline for their existing environment and for creating a roadmap for future security activities such as the creation of a robust security program. If you need help building or improving your security program, consider WaveGard's Security Program Design services.

Try WaveGard - Risk Free

Check us out with a low cost / high value Security Quick Check! Get fast, practical security analysis for your critical network elements. Read more >