CISM Certified Information Security Manager – Question0417

Which of the following is the MOST appropriate use of gap analysis?

A.
Evaluating a business impact analysis (BIA)
B. Developing a balanced business scorecard
C. Demonstrating the relationship between controls
D. Measuring current state vs. desired future state

Correct Answer: D

Explanation:

Explanation:
A gap analysis is most useful in addressing the differences between the current state and an ideal future state. It is not as appropriate for evaluating a business impact analysis (BIA), developing a balanced business scorecard or demonstrating the relationship between variables.