AI Gap Analysis

Professional+

Claude-assisted owner-review drafts with SPRS deduction context

12
Critical Gaps
21
High Priority
−63 pts
SPRS Impact

Modeled SPRS Impact

Maximum deduction recovery if validated MET

If all applicable objectives for these sample entries are validated MET, the model recovers up to +17 SPRS pts: −63 → −46

3.5.3Multifactor Authentication
5-point impact
·SPRS weight: 5·+5 pts if fixed
Est. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record does not support MFA for privileged or non-privileged access to the sample system. The five-point value is a numeric SPRS deduction, not a universal risk or assessor-priority rating.

Remediation Steps

  1. 1Validate the assessed users, systems, and authentication paths with the system owner
  2. 2Select an MFA approach compatible with the validated environment and applicable requirements
  3. 3Document owner-approved exceptions and supporting safeguards, if applicable
  4. 4Retain representative configuration and test evidence for the assessment objectives
3.11.2Vulnerability Scanning
5-point impact
·SPRS weight: 5·+5 pts if fixed
Est. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record shows incomplete vulnerability-scanning coverage for the sample boundary. Actual scan frequency, coverage, findings, and corrective-action priorities require owner validation.

Remediation Steps

  1. 1Validate the assessed boundary and scanning coverage with responsible owners
  2. 2Define an owner-approved scan cadence based on applicable requirements and risk
  3. 3Track relevant findings, corrective actions, exceptions, and closure evidence
  4. 4Retain representative scan and remediation records for the assessment objectives
3.13.8Data in Transit Encryption
3-point impact
·SPRS weight: 3·+3 pts if fixed
Est. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record identifies sample transmission paths that need confidentiality safeguards. Actual CUI flows, alternative safeguards, cryptographic modules, and scope require validation.

Remediation Steps

  1. 1Inventory in-scope CUI transmission paths and applicable safeguards
  2. 2Validate the selected cryptographic modules, certificate status, operating mode, and use
  3. 3Test enforcement for the assessed paths and document owner-approved exceptions
  4. 4Retain architecture, configuration, and test evidence for the assessment objectives

Sign up to unlock AI gap narratives

Get Claude-assisted owner-review drafts with SPRS deduction context. Validate scope, risk, dependencies, effort, applicability, and evidence.

Get Started Free

Free forever · No credit card · Setup in 5 min