Experience in performing and interpreting gap analysis

 

Yes, I do have experience with Gap analysis. As explained in the question prior to this one, I performed Gap analysis for applications on several occasions. I've explained where I performed Gap analysis using excel forms and questionnaires to interpret gap analysis for records management for applications storing data in databases and as a BISO for the bank using the framework GDPR to validate our records retention program performed according to design. 

I will provide another example of Gap analysis where my team was responsible for identifying Gaps in lower-level environments on SQL Databases. Specifically, I gained access to databases to validate data types (Personally identifiable information, home addresses, SSN, phone numbers, employee numbers etc.) present on these SQL Databases. In some cases, we found that there existed PII data in these lower-level environments using SQL queries and screen sharing interview sessions to validate the existence of such data.


At the conclusion of this effort, we created a confluence page which allowed business owners and technical owners to provide updates on the remediation of applications that were found to be in existence of such gaps.      

Comments

Popular posts from this blog

Afterbreach: The Architect of Innovation by Demetrius Fluker

Common Encryption Standards by Demetrius Fluker

My Proof of concept for Datacenter Security