After completing the previous step of this framework, an organization should have selected various cybersecurity controls from Stage 3: Implement that will be integrated into the information security program. It may be tempting to immediately begin implementing these controls, but a few key steps must first be taken to ensure their integration is properly planned. First, a cybersecurity gap analysis should be conducted to compare the current state of the organization's digital environment with the desired state outlined by the selected controls. Documenting this gap gives the organization a clear project scope for the information security program and helps it understand what financial resources will be needed to procure additional security platforms and technologies.
1. Define the Desired State of the Cybersecurity Environment/Posture
The controls selected from the Stage 3 control list will make up the first iteration of the information security program. The combination of desired controls from various domains creates the desired state that the organization is pursuing. It is helpful to create a formal report describing the need for the selected security controls and their purpose within the organization.
2. Assess the Current State
Now that the desired state is clearly outlined, the current state of the organization's digital environment must be assessed to determine the degree to which each control is already implemented. Some controls may be partially implemented in decentralized ways, while others may be completely absent from the environment and require implementation from scratch.
For example, an organization may have passwordless authentication enabled through Windows Hello on certain endpoints but have no enterprise-wide MFA or passwordless authentication deployment for all user accounts. In this case, passwordless authentication would have a partial compliance gap. By contrast, the organization may desire a network macrosegmentation strategy while having no VLANs or other segmentation mechanisms currently in place. In this case, macrosegmentation would have a full gap.
Identifying the current state may take considerable effort, as it requires a thorough examination of the environment. Assessing the current state of security measures is often referred to as a Security Control Assessment (SCA). Many tools, both proprietary and open source, automate this process by scanning the network environment and reporting on the presence of specified controls. Many of these platforms assess compliance against mainstream cybersecurity frameworks such as NIST SP 800-53, ISO 27001, and PCI DSS.
As part of the CyberLadder Framework, I have produced a mapping of controls from Stage 3: Implement to these mainstream frameworks. This allows security control assessments to be mapped against established frameworks and then translated into CyberLadder requirements.
It is important to remember, however, that physical and administrative controls, such as facility protection and the presence of policies and procedures, will generally need to be evaluated manually.
3. Compare the Current State to the Desired State
Once the current state of the organization's security posture has been thoroughly documented, it can be compared against the desired state created through the risk response and countermeasure selection process. Gaps can then be identified as:
- Full Gap
- Partial Gap
- No Gap
These gaps should be documented alongside the controls in question.
4. Highlight Gap Severity
The risk management process outlined in previous sections directed the selection of controls to address the cyber risks uncovered through risk assessments. The risk analysis and reporting phases also produced a severity ranking of identified risks according to their impact and likelihood. This ranking should be incorporated into the gap analysis to determine the severity of individual control gaps.
For example, the board of directors, in collaboration with cybersecurity SMEs, may have determined that the lack of MFA on employee accounts and the presence of an end-of-life (EOL) router are the organization's highest-priority risks. The selected responses were the deployment of MFA (risk mitigation) and the removal of the EOL router (risk avoidance).
However, the gap analysis may uncover that some employees independently enabled MFA, resulting in only a partial gap. Meanwhile, the deployment of a secure replacement router may represent a full gap. Even though MFA initially ranked higher during risk prioritization, these findings may shift priorities and elevate router replacement above MFA deployment.
Gap severity can be ranked using the following scale:
- Critical: Exposes high-value resources to immediate threats, violates regulations, or endangers employees.
- High: Significantly increases the organization's attack surface or threatens the confidentiality, integrity, and availability (CIA) of critical processes.
- Medium: Poses a threat to the security of the environment but does not immediately involve high-priority risks.
- Low: Involves improvements to everyday cybersecurity hygiene and operations but does not immediately address major risks.
5. Conduct a Root Cause Analysis
For an organization's cybersecurity posture to improve from the ground up, the root causes of risks and misconfigurations must be identified.
The gap analysis serves not only to identify deficiencies in cybersecurity coverage but also to uncover the underlying issues that enabled those deficiencies to exist. This process involves reviewing technical documentation such as vulnerability scans, system logs, and change records, as well as discussing the organization's cybersecurity history with key stakeholders to understand why certain controls were never implemented.
In many cases, root cause analysis points to factors such as:
- A lack of skilled personnel to implement security technologies
- Insufficient funding for security infrastructure
- Resistance to the complexity introduced by certain technologies or environmental changes
6. Assess Implementation Complexity
Every cybersecurity control must be appropriately budgeted, scoped, and planned. An organization cannot simply deploy an Active Directory domain in the middle of a workplace without planning, expertise, or supporting infrastructure.
This stage of the gap analysis requires IT personnel, cybersecurity staff, SMEs, and key stakeholders such as senior management and the board of directors to come together and reach a consensus regarding the difficulty of implementing each control.
Factors that should be evaluated include:
- Cost
- Time
- Complexity
- Required skills
- Available manpower
- Dependencies
- Potential disruption to operations
7. Determine Recommended Actions
With all relevant context gathered, each control gap can now be assigned a recommended course of action. Factors such as gap size and the resources available to procure new technology will heavily influence these recommendations.
The recommendation for each gap should include:
- Gap size
- Gap severity
- Priority
- Risk/Gap Owner
- Remediation recommendations
- New technologies, platforms, or infrastructure required
- Target timetable for remediation
These steps make up a comprehensive cybersecurity gap analysis that takes the findings of the initial risk assessment and prepares the organization for remediation activities. Once the gap analysis is complete, organizations can identify the best approach for procuring technologies, develop the initial business case for the first iteration of the information security program, and begin formal project planning for control implementation.
