One More Pedantic Distinction in Information Security?
In the whirlwind of managing a security program, it is easy to lose the distinction and find yourself asking, “Is this an information security risk or a gap?"
I’ve seen it over and over again: Gaps being tracked in the risk register, and risks being closed because they are considered remediated.
Another pedantic distinction is the last thing a CISO, a GRC manager, or a security analyst needs, but what if I told you there is actually a lot of value in understanding and operationalizing the distinction between a gap and a risk?
The distinction between risks and gaps could be the key to running a stronger GRC program. First, let’s define the two terms:
Aspect |
Risk |
Gap |
Formal Definition |
The possibility that some event happens that harms the organization's information security (confidentiality, integrity, and availability) and leads to financial loss. |
A deficiency in the operation of a security control. |
Simple Meaning |
Bad things can happen that may cause the company to lose money in some way. |
We are not doing the security activity that we said we were going to do. |
Resolution |
The risk will likely become acceptable after we treat it, but it rarely goes away. |
The gap goes away when we remediate it. |
Risk Factors: The Relationship Between Risk and Value
Risk and value are directly correlated. That’s the chart that goes up and to the right. As the value of something increases, so does the risk associated with it. It’s true in life and it’s true in information security.

We call these somethings risk factors. Risk factors are the things that are valuable to the company. It could be the database that holds PII. It could be your corporate network where trade secrets are discussed. It could be your source code.
Risk Scenarios: What Could Go Wrong?
By starting a risk assessment with a list of risk factors, you are simplifying a complex process. Now we can ask ourselves, what kind of events could threaten these risk factors? What could go wrong for these specific things?
We call these things risk scenarios. Risk scenarios are the bad things that could happen to the risk factors. It could be a successful phishing attack or a successful Distributed Denial-of-Service (DDoS) attack. It could be a major shift in industry trends or a sudden legislative change.
But What About Information Security Gaps?
We’ve listed out risk factors. We’ve identified risk scenarios. Your security controls are the things that are supposed to prevent, detect, and respond to those scenarios. A gap shows up when you realize that the control you’ve implemented is not operating effectively.
If you have a firewall (control) to prevent unauthorized access (risk scenario), a misconfiguration in the firewall (gap) undermines the control's effectiveness at protecting the information behind the firewall (risk factor).
Information Security Risk vs. Gap: Examples to Drive the Point Home
Once you remediate the gap by fixing the misconfiguration, the gap goes away, but the risk of unauthorized access doesn’t. It may be mitigated, it may be acceptable to the company, but it still exists even though it may be small.
Below are some examples to illustrate the relationship between risks and gaps:
Example Risk |
Possible Related Gap |
Unauthorized access to sensitive customer data |
Missing two-factor authentication for user accounts |
Ransomware attack on critical business systems |
Inadequate network segmentation between user and admin environments |
Data exfiltration due to insider threats |
Lack of employee activity monitoring on sensitive systems |
Downtime from Distributed Denial-of-Service (DDoS) attacks |
No web application firewall (WAF) in place to filter traffic |
Regulatory fines for non-compliance with data protection laws |
No formalized data encryption policy |
Loss of intellectual property through phishing |
Lack of employee training on phishing identification |
Breach due to unpatched software vulnerabilities |
No defined process for timely software updates |
Physical theft of company devices |
Missing device encryption and physical security measures |
Data leaks from cloud misconfigurations |
Lack of routine cloud configuration audits |
Damage to brand reputation from a publicized breach |
Absence of an incident response communication plan |
The Risk Register: Where to Track What
In fullCircle GRC, we split these ideas (risks and gaps) up into three categories represented by modules:
- Controls & Assessments: These modules work in tandem to regularly assess the operational effectiveness of your controls.
- Risk Management: This module includes risk registers used to score and track your risks over time.
- Project Management: This module – which can integrate with Jira – can be used to track action items that come from Control Assessments or Risk Management activities:
- Management Action Plans: You can export findings from assessments to track the remediation of those gaps.
- Risk Treatment Plans: You can export risks from a risk assessment to track the treatment of those risks.
The Impact: Risks & Gaps Can Help the Business
The goal of the best security programs is to help the business achieve its goals. Information security risks and gaps are key components that help to tell a cohesive story about the status of the business’s security program. Each one plays a different role in that story.
Mastering this language can empower your team to highlight areas that are serving the business well and call out the areas that need more support or accountability. And when you do that well, you will drive value for both the security program and the business.
Interested in learning more about risk assessments or fullCircle’s risk management capabilities? Contact us today and get in touch with our tech-enabled professionals that can walk you through managing information security risks and help you identify gaps in your security program.
T.J. Capaldi
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)