DiscoverCertified: The CompTIA Security+ Audio CourseEpisode 14: Gap Analysis and Zero Trust Security (Domain 1)
Episode 14: Gap Analysis and Zero Trust Security (Domain 1)

Episode 14: Gap Analysis and Zero Trust Security (Domain 1)

Update: 2025-06-15
Share

Description

Security programs are only as strong as their weakest uncovered areas—and that’s where gap analysis and Zero Trust come into play. This episode introduces gap analysis as a structured approach to identifying where an organization’s current security posture fails to meet expected or required standards, often using frameworks like NIST or ISO to benchmark practices. We discuss how gap analysis involves comparing existing controls, processes, and risks against desired outcomes or compliance objectives to generate actionable remediation plans. Then we turn to Zero Trust, a transformative security model based on the principle of “never trust, always verify.” Zero Trust assumes breach and requires continuous authentication, authorization, and validation at every access point, regardless of whether a request originates inside or outside the network perimeter. By combining gap analysis with Zero Trust principles, organizations can not only uncover deficiencies, but also redesign their infrastructure to eliminate implicit trust and reduce exposure.

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Episode 14: Gap Analysis and Zero Trust Security (Domain 1)

Episode 14: Gap Analysis and Zero Trust Security (Domain 1)

Dr. Jason Edwards