In the whirlwind of managing a security program, it is easy to lose the distinction and find yourself asking, “Is this an information security risk or a gap?"
I’ve seen it over and over again: Gaps being tracked in the risk register, and risks being closed because they are considered remediated.
Another pedantic distinction is the last thing a CISO, a GRC manager, or a security analyst needs, but what if I told you there is actually a lot of value in understanding and operationalizing the distinction between a gap and a risk?
The distinction between risks and gaps could be the key to running a stronger GRC program. First, let’s define the two terms:
Aspect |
Risk |
Gap |
Formal Definition |
The possibility that some event happens that harms the organization's information security (confidentiality, integrity, and availability) and leads to financial loss. |
A deficiency in the operation of a security control. |
Simple Meaning |
Bad things can happen that may cause the company to lose money in some way. |
We are not doing the security activity that we said we were going to do. |
Resolution |
The risk will likely become acceptable after we treat it, but it rarely goes away. |
The gap goes away when we remediate it. |
Risk and value are directly correlated. That’s the chart that goes up and to the right. As the value of something increases, so does the risk associated with it. It’s true in life and it’s true in information security.
We call these somethings risk factors. Risk factors are the things that are valuable to the company. It could be the database that holds PII. It could be your corporate network where trade secrets are discussed. It could be your source code.
By starting a risk assessment with a list of risk factors, you are simplifying a complex process. Now we can ask ourselves, what kind of events could threaten these risk factors? What could go wrong for these specific things?
We call these things risk scenarios. Risk scenarios are the bad things that could happen to the risk factors. It could be a successful phishing attack or a successful Distributed Denial-of-Service (DDoS) attack. It could be a major shift in industry trends or a sudden legislative change.
We’ve listed out risk factors. We’ve identified risk scenarios. Your security controls are the things that are supposed to prevent, detect, and respond to those scenarios. A gap shows up when you realize that the control you’ve implemented is not operating effectively.
If you have a firewall (control) to prevent unauthorized access (risk scenario), a misconfiguration in the firewall (gap) undermines the control's effectiveness at protecting the information behind the firewall (risk factor).
Once you remediate the gap by fixing the misconfiguration, the gap goes away, but the risk of unauthorized access doesn’t. It may be mitigated, it may be acceptable to the company, but it still exists even though it may be small.
Below are some examples to illustrate the relationship between risks and gaps:
Example Risk |
Possible Related Gap |
Unauthorized access to sensitive customer data |
Missing two-factor authentication for user accounts |
Ransomware attack on critical business systems |
Inadequate network segmentation between user and admin environments |
Data exfiltration due to insider threats |
Lack of employee activity monitoring on sensitive systems |
Downtime from Distributed Denial-of-Service (DDoS) attacks |
No web application firewall (WAF) in place to filter traffic |
Regulatory fines for non-compliance with data protection laws |
No formalized data encryption policy |
Loss of intellectual property through phishing |
Lack of employee training on phishing identification |
Breach due to unpatched software vulnerabilities |
No defined process for timely software updates |
Physical theft of company devices |
Missing device encryption and physical security measures |
Data leaks from cloud misconfigurations |
Lack of routine cloud configuration audits |
Damage to brand reputation from a publicized breach |
Absence of an incident response communication plan |
In fullCircle GRC, we split these ideas (risks and gaps) up into three categories represented by modules:
The goal of the best security programs is to help the business achieve its goals. Information security risks and gaps are key components that help to tell a cohesive story about the status of the business’s security program. Each one plays a different role in that story.
Mastering this language can empower your team to highlight areas that are serving the business well and call out the areas that need more support or accountability. And when you do that well, you will drive value for both the security program and the business.
Interested in learning more about risk assessments or fullCircle’s risk management capabilities? Contact us today and get in touch with our tech-enabled professionals that can walk you through managing information security risks and help you identify gaps in your security program.