nerdexam
IIBA

CBAP · Question #197

Which of the following processes measures the maturity level of the security program?

The correct answer is D. GAP analysis. GAP analysis evaluates the difference between a current security posture and a desired maturity level, making it the correct tool for measuring program maturity.

Strategy Analysis

Question

Which of the following processes measures the maturity level of the security program?

Options

  • ARisk analysis
  • BRisk mitigation
  • CRisk assessment
  • DGAP analysis

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    15% (5)
  • C
    3% (1)
  • D
    76% (25)

Why each option

GAP analysis evaluates the difference between a current security posture and a desired maturity level, making it the correct tool for measuring program maturity.

ARisk analysis

Risk analysis identifies and evaluates potential threats and their likelihood, not the maturity level of security controls or processes.

BRisk mitigation

Risk mitigation refers to the actions taken to reduce identified risks, not to measuring or benchmarking a security program's maturity.

CRisk assessment

Risk assessment evaluates the probability and impact of specific risks, not the overall capability or maturity of the security program.

DGAP analysisCorrect

GAP analysis compares the current state of a security program against a target or baseline maturity framework (such as CMMI or NIST CSF), identifying gaps that must be closed. It directly answers 'how mature are we?' by mapping existing controls and practices against defined maturity levels. The other risk-related processes focus on threats and likelihoods, not maturity measurement.

Concept tested: GAP analysis for security program maturity measurement

Source: https://www.nist.gov/cyberframework/framework

Topics

#GAP analysis#maturity assessment#current state analysis#security program

Community Discussion

No community discussion yet for this question.

Full CBAP Practice