CompTIA Cloud Essentials+ (CLO-002)Business Principles of Cloud EnvironmentsMedium
A company is conducting a gap analysis as part of its cloud migration planning. They have identified that their current on-premises security policies and compliance frameworks (e.g., GDPR, PCI DSS) are not fully aligned with the shared responsibility model of their chosen public cloud provider. This discrepancy represents a gap in which area?
- ARegulatory/Compliance Gap
- BTechnical Gap
- CSkill Gap
- DProcess Gap
Show answer & explanationAnswer & explanation
Correct answer: A. Regulatory/Compliance Gap
A regulatory/compliance gap exists when an organization's current policies and practices, particularly those related to legal and industry regulations (like GDPR and PCI DSS), do not align with the requirements or capabilities of the cloud environment or the shared responsibility model. This requires adjusting policies or selecting a different cloud solution.
Why the other options are wrong
- B. Technical gaps relate to infrastructure, software, or system compatibility.
- C. Skill gaps relate to the expertise of personnel.
- D. Process gaps relate to operational workflows and procedures.
Regulatory/Compliance Gap
A discrepancy between an organization's existing legal, industry, or internal compliance requirements and the capabilities or responsibilities within a cloud environment.
- Often related to data residency, privacy, and security standards.
- Requires careful assessment and potential adjustments to policies or cloud architecture.
- Critical for industries like healthcare, finance, and government.
Memory trick: Gaps in Tech, Skills, Processes, and Rules.