Policy Gap Analysis

Difficulty: Intermediate · Track: GRC

Compare a draft policy against a baseline checklist and find what's missing before the auditors do.

Context

A company's draft Access Control Policy is under review before their first internal audit. Policy writing and gap analysis against a baseline is core GRC work — you're checking what the draft covers against what it should cover.

Task

  1. Read the draft policy excerpt and the baseline checklist below.
  2. Find the one clause that has a specific numeric requirement.
  3. Identify which two baseline items are completely absent from the draft's four numbered clauses.

Draft Policy & Baseline Checklist

Answers are directly copy-pasteable from this block.

Note: Educational example — policy text is fictional and simplified for practice.

Capture the Flags

Copy each answer directly from the block above. Case-insensitive.

0/3 flags captured

Flag 1 — How many business days does the draft allow for revoking access after termination?

Question: Copy the exact number from clause 4.

Flag 2 — Which baseline item about reviewing access over time is missing from the draft?

Question: Copy the exact baseline checklist item (not covered by any of the 4 numbered clauses).

Flag 3 — Which baseline item about stronger login security is missing from the draft?

Question: Copy the exact baseline checklist item for privileged accounts.

Back to Challenges