CBAP · Question #197
Which of the following processes measures the maturity level of the security program?
The correct answer is D. GAP analysis. GAP analysis evaluates the difference between a current security posture and a desired maturity level, making it the correct tool for measuring program maturity.
Question
Which of the following processes measures the maturity level of the security program?
Options
- ARisk analysis
- BRisk mitigation
- CRisk assessment
- DGAP analysis
How the community answered
(33 responses)- A6% (2)
- B15% (5)
- C3% (1)
- D76% (25)
Why each option
GAP analysis evaluates the difference between a current security posture and a desired maturity level, making it the correct tool for measuring program maturity.
Risk analysis identifies and evaluates potential threats and their likelihood, not the maturity level of security controls or processes.
Risk mitigation refers to the actions taken to reduce identified risks, not to measuring or benchmarking a security program's maturity.
Risk assessment evaluates the probability and impact of specific risks, not the overall capability or maturity of the security program.
GAP analysis compares the current state of a security program against a target or baseline maturity framework (such as CMMI or NIST CSF), identifying gaps that must be closed. It directly answers 'how mature are we?' by mapping existing controls and practices against defined maturity levels. The other risk-related processes focus on threats and likelihoods, not maturity measurement.
Concept tested: GAP analysis for security program maturity measurement
Source: https://www.nist.gov/cyberframework/framework
Topics
Community Discussion
No community discussion yet for this question.