— a multi-niche blog

Closing the gap between policy vision and real-world technology outcomes

Public sector and enterprise leaders across Australia routinely sign off on sweeping digital strategies only to discover, eighteen months later, that the actual stack in production looks nothing like the blueprint. The documents describe a cloud-first, citizen-centric, data-driven future. The reality on a help-desk ticket from a regional office in Geelong or a payment portal in Parramatta tells a different story. This persistent drift is rarely caused by malice or gross negligence. It is the slow accumulation of mismatched assumptions, inherited legacy code, and cultural inertia. A structured gap analysis remains the most reliable way to make that drift visible before it calcifies into permanent risk.

A gap analysis is not an audit, although it borrows audit discipline. It is not a risk register, although risks fall out of it. Properly done, it sits between the written intent of a policy or strategy and the observable behaviour of the technology and people who must execute it. The analyst walks every paragraph of the policy forward into a question: what does this clause require the system, the team, and the workflow to actually do? They then walk backward from the live environment, asking what the system is actually doing, what the teams are actually doing, and how far that diverges from what the policy demands. The space between those two pictures is the gap, and it almost always reveals more than the original policy author intended.

The five stages below translate that principle into a working method. They draw on Australian legislative touchstones such as the Privacy Act 1988, the Security of Critical Infrastructure Act 2018, and the Protective Security Policy Framework, while remaining applicable to any organisation wrestling with the distance between written intent and operational reality. Whether the team sits in a Melbourne coworking hub, a Canberra agency, or a Perth mining headquarters, the mechanics of identifying and closing that gap follow a recognisable rhythm.

Setting the scope and stakeholders

Every credible gap analysis begins with an explicit scope statement, ideally written in a single paragraph and signed off by an executive sponsor. Without that anchor, the exercise drifts into the territory of a general IT health check, which delivers noise rather than signal. The scope should name the policy document or strategy in question, the timeframe it covers, the systems or services that fall inside the boundary, and the business units whose workflows are affected. A scope may declare, for example: "Compare the obligations of the updated Australian Cyber Security Centre Essential Eight maturity targets against the current configuration of agency endpoints, identity providers, and backup services, across all corporate and field-operations staff, for the period 1 July to 30 June."

Stakeholder mapping runs in parallel. A recurring failure mode in large Australian agencies is the assumption that policy sits with the security team and technology sits with the IT team, so the two groups can be surveyed in isolation. That separation produces beautifully complete technical inventories and beautifully complete policy documents, and almost no overlap. Real mapping identifies the people who write the policy, the people who approve it, the people who configure the systems, the people who operate them day to day, and the people who use them. Each group holds a different slice of the truth, and each slice is necessary.

Practical logistics matter here as well. Sessions in Sydney and Brisbane are easiest to schedule on Tuesdays and Wednesdays, when interstate travel calendars tend to be lightest. Melbourne offices often prefer a late-Friday wrap-up once the morning's stand-ups are out of the way. Acknowledging these rhythms, rather than fighting them, lifts attendance and improves the honesty of the answers captured.

Mapping current policy intent against live systems

With the scope locked and the right people in the room, the next step is to convert policy language into testable statements. Phrases such as "the agency will apply least-privilege access to all production data stores" must be rewritten as measurable conditions: which data stores, which identity providers, which review cadence, which exceptions are permissible, and what evidence would demonstrate compliance. Once each clause is reduced to a verifiable condition, the mapping exercise becomes mechanical rather than interpretive. The team can then walk through each condition and identify the corresponding system, configuration item, or process in the live environment.

Documentation hygiene often becomes the first casualty of this exercise. System architects may point to architecture diagrams in Confluence that were last touched two refresh cycles ago. Policy owners may cite a control library that was retired but never formally archived. The gap analyst's job is to treat the absence of evidence as evidence of absence, rather than as a reason to pause. Where a documented control cannot be produced, the gap is recorded as such, with a confidence rating and a follow-up owner.

This is also the stage where the cultural subtext surfaces. A team in Adelaide may quietly reveal that the policy on session timeout is universally overridden because the underlying single sign-on solution drops tokens every twenty-five minutes, which the business cannot tolerate during long shift handovers. That single observation reframes a policy compliance failure as a usability and procurement problem, and it almost certainly points to a wider gap between what was procured and what was specified.

Identifying compliance, capability, and cultural shortfalls

Once the map is complete, the analyst sorts every identified gap into one of three buckets: compliance shortfalls, capability shortfalls, and cultural shortfalls. Compliance shortfalls are the easiest to triage because they map directly onto a regulatory or contractual obligation. An unpatched internet-facing server falls here, as does a missing record of consent under the Notifiable Data Breaches scheme. These items carry the clearest urgency, and remediation paths usually involve either a configuration change or a documented compensating control approved at the appropriate authority level.

Capability shortfalls are trickier. They arise when the technology itself is broadly fit for purpose but the organisation lacks the skills, capacity, or mature processes to operate it as the policy requires. A security information and event management platform that ingests logs but produces no meaningful alerts is a capability gap rather than a compliance gap, because the technology is present and the configuration is technically correct. Resolving this category usually requires investment in training, runbooks, or additional headcount, all of which compete for budget against other priorities.

Cultural shortfalls are the slowest to surface and the hardest to address. They reveal themselves when staff quietly route around controls because they perceive them as obstacles rather than protections. A practical way to address cultural distance between distributed teams is to invest in shared learning rituals that build trust across functions. Some organisations have had success with lightweight knowledge circles that meet virtually across state borders, in the spirit of a virtual book club for policy authors and system operators. The aim is shared vocabulary, not literary criticism.

Prioritising remediation in a resource-bounded environment

Most gap analyses surface more remediation work than any single budget cycle can absorb. Prioritisation therefore becomes a discipline of its own. A simple but effective framework scores each gap on three axes: the consequence of leaving it open, the effort required to close it, and the dependency it has on other workstreams. A high-consequence, low-effort gap is an obvious first move and quickly builds momentum. A high-consequence, high-effort gap is often best handled as a business case rather than a work ticket, because the cost crosses a threshold that warrants executive approval.

Financial discipline matters here as well. When leaders debate whether to fund a new identity governance tool or expand an existing security operations centre, they often rely on shifting external benchmarks to anchor the conversation. Some procurement committees keep an eye on volatile reference points such as the gold rate today to stress-test assumptions about asset valuations and currency exposure, even in purely digital projects. The point is to remind decision makers that the value of underlying resources moves faster than annual planning cycles assume, and that any long remediation roadmap must be revisited as those baselines shift.

It is also worth designing the remediation roadmap in publicly visible increments. Australian citizens who interact with services such as myGov or the Australian Taxation Office's online systems form judgements based on small repeated interactions, not on glossy strategies. A roadmap that ships a visible improvement every quarter, even a modest one, does more for long-term trust than a single grand programme that overpromises and under-delivers.

Embedding continuous review across the technology lifecycle

A one-off gap analysis is a snapshot, and snapshots go stale. The most resilient organisations treat the gap analysis as a recurring ritual, scheduled alongside the annual policy refresh and tied to the financial year cadence that APS agencies and ASX-listed entities already operate under. The rhythm ensures that every time a policy is rewritten, the question of technological alignment is asked deliberately rather than left to drift.

Tabletop exercises and live drills are an underrated companion to this rhythm. They reveal whether the controls that look correct on paper still work when the pressure is real. Teams that want to sharpen their readiness can follow a structured path, such as the practical walk-through outlined in a guide to preparing for an incident response drill, which translates abstract controls into concrete muscle memory. Running such drills quarterly, and rotating the scenario each time, prevents the exercise from becoming theatre.

Finally, the gap analysis output should land somewhere durable. A living register, owned by a named accountable officer and reviewed at each executive committee meeting, closes the loop between finding and action. Without that final step, even the most rigorous analysis becomes another PDF on a shared drive, consulted once and quietly forgotten. With it, the distance between policy and technology becomes a managed variable rather than an open risk.

If your team is staring at a stack of policies and a stack of systems that no longer seem to speak to each other, the path forward is closer than it looks. Start by naming the scope in a single paragraph, gather the people who write the policy and the people who run the technology in the same room, and walk every clause forward into a verifiable condition. The first gaps will appear within a single working session, and from there the discipline compounds. Reach out to the e-Pragati team to discuss how a tailored gap analysis could be shaped for your own operating context.

— get in touch

Have a question or want to reach out?