AI Gap Analysis
Professional+
Claude-assisted owner-review drafts with SPRS deduction context
12
Critical Gaps
21
High Priority
−63 pts
SPRS Impact
Modeled SPRS Impact
Maximum deduction recovery if validated METIf all applicable objectives for these sample entries are validated MET, the model recovers up to +17 SPRS pts: −63 → −46
3.5.3Multifactor Authentication
5-point impact
·SPRS weight: 5·+5 pts if fixedEst. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record does not support MFA for privileged or non-privileged access to the sample system. The five-point value is a numeric SPRS deduction, not a universal risk or assessor-priority rating.Remediation Steps
- 1Validate the assessed users, systems, and authentication paths with the system owner
- 2Select an MFA approach compatible with the validated environment and applicable requirements
- 3Document owner-approved exceptions and supporting safeguards, if applicable
- 4Retain representative configuration and test evidence for the assessment objectives
3.11.2Vulnerability Scanning
5-point impact
·SPRS weight: 5·+5 pts if fixedEst. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record shows incomplete vulnerability-scanning coverage for the sample boundary. Actual scan frequency, coverage, findings, and corrective-action priorities require owner validation.Remediation Steps
- 1Validate the assessed boundary and scanning coverage with responsible owners
- 2Define an owner-approved scan cadence based on applicable requirements and risk
- 3Track relevant findings, corrective actions, exceptions, and closure evidence
- 4Retain representative scan and remediation records for the assessment objectives
3.13.8Data in Transit Encryption
3-point impact
·SPRS weight: 3·+3 pts if fixedEst. effort
Owner estimate required
AI Analysis
Fictional demo scenario: the entered record identifies sample transmission paths that need confidentiality safeguards. Actual CUI flows, alternative safeguards, cryptographic modules, and scope require validation.Remediation Steps
- 1Inventory in-scope CUI transmission paths and applicable safeguards
- 2Validate the selected cryptographic modules, certificate status, operating mode, and use
- 3Test enforcement for the assessed paths and document owner-approved exceptions
- 4Retain architecture, configuration, and test evidence for the assessment objectives
Sign up to unlock AI gap narratives
Get Claude-assisted owner-review drafts with SPRS deduction context. Validate scope, risk, dependencies, effort, applicability, and evidence.
Free forever · No credit card · Setup in 5 min