An information security manager is planning the annual posture assessment and must decide how to sequence a control gap analysis and a technical vulnerability assessment for a newly acquired business unit whose control environment is largely undocumented. Which sequencing is most defensible from a management standpoint?
- APerform the gap analysis first to establish which controls should exist, then use the vulnerability assessment to test how well those controls hold up technically. Correct
- BRun only the vulnerability assessment, because exploitable technical flaws are the sole reliable evidence of where the security posture is genuinely weak.
- CRun both in parallel without reference to each other, then merge the two reports at the end so neither activity delays the other.
- DDefer both assessments until the business unit has documented its own controls, so that the analysis can rely entirely on the unit's existing records.
Why A is correct: Correct because establishing the required control baseline first gives the technical assessment a frame of reference, so deficiencies can be interpreted against what should be in place.
Why B is wrong: Tempting because technical findings are concrete, but a scan alone cannot reveal missing or undesigned controls, so it leaves governance and process gaps invisible.
Why C is wrong: Tempting because parallel work is faster, but without a control baseline the technical findings cannot be interpreted against required controls, so the merge yields a fragmented posture view.
Why D is wrong: Tempting because documentation aids analysis, but waiting on an undocumented unit leaves the acquirer blind to active risk, so deferral abdicates the manager's duty to assess posture.