Policy Gap Analysis
Difficulty: Intermediate · Track: GRC
Compare a draft policy against a baseline checklist and find what's missing before the auditors do.
Context
A company's draft Access Control Policy is under review before their first internal audit. Policy writing and gap analysis against a baseline is core GRC work — you're checking what the draft covers against what it should cover.
Task
- Read the draft policy excerpt and the baseline checklist below.
- Find the one clause that has a specific numeric requirement.
- Identify which two baseline items are completely absent from the draft's four numbered clauses.
Draft Policy & Baseline Checklist
Answers are directly copy-pasteable from this block.
Capture the Flags
Copy each answer directly from the block above. Case-insensitive.
0/3 flags captured
Flag 1 — How many business days does the draft allow for revoking access after termination?
Hint: It's in clause 4, "Terminated employees must have...".
Flag 2 — Which baseline item about reviewing access over time is missing from the draft?
Hint: None of the 4 clauses mention re-checking who still needs access after it's been granted.
Flag 3 — Which baseline item about stronger login security is missing from the draft?
Hint: The draft only mentions passwords — not a second factor for privileged accounts.