One card per RG. Each control is assessed individually. Evidence quoted from control descriptions; coverage statements explain what the quote satisfies; gap statements identify what is absent.
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-15 | Account Management | Partial | “AD accounts are managed through security groups for access to file shares, applications, and M365 resources.”This addresses user-level authorization through AD security group membership.Missing device-level authorization. |
| IAC-04 | I&A for Devices | Partial | “Domain-joined devices authenticate to AD via machine certificates and Kerberos.”This addresses device authentication for domain-joined endpoints.Missing non-domain and personal device authorization. |
| HRS-05.5 | Use of Mobile Devices | Partial | “Mobile device access to bank email and applications requires MDM enrollment.”This addresses mobile device authorization for email access.Missing non-email mobile access authorization. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| NET-04.1 | Deny by Default | Covered | “The Palo Alto PA-850 firewalls are configured with a default-deny policy — all traffic is blocked unless explicitly permitted by a rule.”This fully addresses the default-deny access posture. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-20 | Access Enforcement | Partial | “AD security groups and GPOs enforce access based on department templates.”This addresses functional role-based access through AD security groups.Missing formal role definitions and role-to-permission mappings. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-02 | I&A for Org Users | Covered | “All employees and contractors authenticate through Active Directory with unique user IDs. Duo MFA is enforced for VPN and M365 access.”This fully addresses identity establishment and multi-factor authentication. |
| IAC-09.1 | User Identity Mgmt | Covered | “Each employee receives a unique AD account upon hire. IT verifies identity based on HR’s onboarding documentation.”This fully addresses identity verification at onboarding. |
| CRY-07 | Wireless Auth | Covered | “Corporate wireless uses WPA2-Enterprise with RADIUS authentication against Active Directory.”This fully addresses identity-based wireless access. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-21 | Least Privilege | Partial | “New accounts are provisioned using department-based AD templates that grant minimum required access.”This addresses initial provisioning with least-privilege templates.Missing business purpose justification and privilege creep management on role change. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-15 | Account Management | Partial | “Annual access reviews for core banking (Symitar).”This addresses periodic access review for the core banking system.Missing asset/system owner review assignment and review frequency for non-core systems. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-10.1 | Password-Based Auth | Covered | “AD Group Policy enforces 12-character minimum passwords with complexity requirements (uppercase, lowercase, number, special character).”This fully addresses password complexity enforcement. |
| IAC-10.4 | Automated Strength | Covered | “AD Group Policy automatically rejects passwords that do not meet the 12-character minimum, complexity, and history requirements.”This fully addresses automated rejection of non-compliant passwords. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-22 | Account Lockout | Covered | “AD Group Policy locks accounts after 5 consecutive failed login attempts.”This fully addresses account lockout after failed attempts. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-10 | Authenticator Mgmt | Partial | “10-password history enforced via AD Group Policy.”This addresses technical prevention of recent password reuse through history enforcement.Missing explicit password reuse prohibition in policy. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-10 | Authenticator Mgmt | Partial | “Default passwords are changed during initial setup per the build checklist.”This addresses default password change during system provisioning.Missing enhanced complexity requirements for default admin accounts. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-10 | Authenticator Mgmt | Partial | “Default passwords are changed during initial setup.”This addresses default password change at system deployment.Missing formal hardening documentation reference and automated verification. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| MON-16.4 | Account Logging | Partial | “Active Directory logs account creation and group membership changes in the Windows Security Event Log.”This addresses log collection of privilege change events.Missing continuous monitoring and prioritized detection for critical systems. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| MON-16.4 | Account Logging | Partial | “LogRhythm has default rules for privileged logon and account creation events.”This addresses alert generation for privilege-related events.Missing documented investigation and resolution process for triggered alerts. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| IAC-15 | Account Management | Partial | “ServiceNow provides a request workflow for access changes.”This addresses workflow capture for access change requests.Missing automated provisioning, deprovisioning, and auto-revocation on role change. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| HRS-09 | Personnel Termination | Covered | “HR notifies IT of terminations via ServiceNow ticket. IT disables Active Directory accounts and revokes VPN access.”This fully addresses the defined termination notification and access removal process. |
| HRS-09.2 | High-Risk Termination | Covered | “IT is notified to disable access immediately.”This fully addresses expedited access removal for high-risk terminations. |
| Control | Name | Rating | Evidence / Gap |
|---|---|---|---|
| HRS-09 | Personnel Termination | Partial | “IT disables Active Directory accounts and revokes VPN access.”This addresses access disablement for AD and VPN upon termination notification.Missing immediate removal for standard terminations and cross-system simultaneous removal. |
| RG | Requirement | Assessment | Rationale |
|---|---|---|---|
| RG-1 | Allow access by authorized individuals and devices | Partial | Controls IAC-15 (Account Management), IAC-04 (I&A for Devices), and HRS-05.5 (Use of Mobile Devices) collectively address user authorization through AD security groups, domain device authentication via Kerberos, and mobile device authorization through MDM enrollment. The control set does not define a unified device authorization mechanism for non-domain and personal devices.Refer to the control-level assessments above for details. |
| RG-2 | Disallow access by all others | Covered | Control NET-04.1 (Deny by Default) establishes a default-deny firewall policy where all traffic is blocked unless explicitly permitted. This fully addresses the default-deny access posture.Refer to the control-level assessments above for details. |
| RG-3 | Consider role-based access control | Partial | Control IAC-20 (Access Enforcement) addresses functional role-based access through AD security groups and department-based GPOs. The control set does not include formally documented role definitions or role-to-permission mappings.Refer to the control-level assessments above for details. |
| RG-4 | Identity established before access | Covered | Controls IAC-02 (I&A for Org Users), IAC-09.1 (User Identity Mgmt), and CRY-07 (Wireless Auth) collectively address unique identity assignment, HR-validated onboarding verification, Duo MFA enforcement, and RADIUS-based wireless authentication.Refer to the control-level assessments above for details. |
| RG-5 | Limit to minimum required | Partial | Control IAC-21 (Least Privilege) addresses initial provisioning through department-based AD templates that grant minimum required access. The control set does not require business purpose justification for access grants or address privilege creep upon role change.Refer to the control-level assessments above for details. |
| RG-6 | Asset owners regularly review access | Partial | Control IAC-15 (Account Management) addresses periodic access review for core banking (Symitar) on an annual basis. The control set does not assign review responsibility to asset or system owners, and does not define review frequency for non-core systems.Refer to the control-level assessments above for details. |
| RG-7 | Password complexity | Covered | Controls IAC-10.1 (Password-Based Auth) and IAC-10.4 (Automated Strength) collectively address 12-character minimum password enforcement with complexity requirements and automated rejection of non-compliant passwords.Refer to the control-level assessments above for details. |
| RG-8 | Password lockout | Covered | Control IAC-22 (Account Lockout) addresses account lockout after 5 consecutive failed login attempts via AD Group Policy.Refer to the control-level assessments above for details. |
| RG-9 | Prohibition of password reuse | Partial | Control IAC-10 (Authenticator Mgmt) addresses technical prevention of recent password reuse through 10-password history enforcement via AD Group Policy. The control set does not explicitly prohibit password reuse in policy language.Refer to the control-level assessments above for details. |
| RG-10 | Complex passwords for default admin | Partial | Control IAC-10 (Authenticator Mgmt) addresses default password change during initial system setup per the build checklist. The control set does not specify enhanced complexity requirements for default administration accounts.Refer to the control-level assessments above for details. |
| RG-11 | Change defaults per hardening | Partial | Control IAC-10 (Authenticator Mgmt) addresses default password change at system deployment. The control set does not reference formal hardening documentation or define automated verification of default password changes.Refer to the control-level assessments above for details. |
| RG-12 | Continuously monitor privilege changes | Partial | Control MON-16.4 (Account Logging) addresses log collection of privilege change events through AD Security Event Log forwarding to LogRhythm. The control set does not demonstrate continuous monitoring or prioritized detection for critical systems.Refer to the control-level assessments above for details. |
| RG-13 | Alert security team | Partial | Control MON-16.4 (Account Logging) addresses alert generation for privilege-related events through LogRhythm default rules. The control set does not describe a documented investigation or resolution process for triggered alerts.Refer to the control-level assessments above for details. |
| RG-14 | Automate access management | Partial | Control IAC-15 (Account Management) addresses workflow capture for access change requests through ServiceNow. The control set does not describe automated provisioning, deprovisioning, or auto-revocation on role change.Refer to the control-level assessments above for details. |
| RG-15 | Establish termination process | Covered | Controls HRS-09 (Personnel Termination) and HRS-09.2 (High-Risk Termination) collectively address the defined termination notification process, AD and VPN access disablement, and expedited removal for high-risk cases.Refer to the control-level assessments above for details. |
| RG-16 | Remove terminated access immediately | Partial | Control HRS-09 (Personnel Termination) addresses access disablement for AD and VPN upon termination notification. The control set does not define immediate removal for standard terminations or simultaneous removal across non-AD systems.Refer to the control-level assessments above for details. |
One assessment finding per Partial or No Coverage RG. Each classifies the root cause of the observed gap. Purely observational — advisory guidance is in Appendix A. Sorted by severity.
Each CRI requirement traces forward through the supporting controls to the operational evidence an examiner will request. The Readiness column indicates whether the institution's control library provides a clear evidence path for each requirement.
| CRI Requirement | Organization Controls | Expected Evidence | Technology Source | Readiness |
|---|---|---|---|---|
| RG-1 Allow access by authorized individuals and devices |
Account Management (IAC-15) I&A for Devices (IAC-04) Use of Mobile Devices (HRS-05.5) |
AD security group membership exports; Kerberos machine authentication certificates; MDM enrollment records | ADMDM |
◔ Partial |
| RG-2 Disallow access by all others |
Deny by Default (NET-04.1) | Firewall default-deny policy export; rule base review showing implicit deny | Palo Alto |
✓ Supported |
| RG-3 Consider role-based access control |
Access Enforcement (IAC-20) | AD security group configuration; GPO role assignment export; group nesting documentation | AD |
◔ Partial |
| RG-4 Identity established before access |
I&A for Org Users (IAC-02) User Identity Mgmt (IAC-09.1) Wireless Auth (CRY-07) |
AD account creation records; onboarding workflow documentation; Duo MFA enrollment logs; RADIUS authentication config | ADDuoRADIUS |
✓ Supported |
| RG-5 Limit to minimum required |
Least Privilege (IAC-21) | Department role template configuration; least-privilege group assignment documentation | AD |
◔ Partial |
| RG-6 Asset owners regularly review access |
Account Management (IAC-15) | Symitar access review reports; recertification completion records; owner sign-off artifacts | Symitar |
◔ Partial |
| RG-7 Password complexity |
Password-Based Auth (IAC-10.1) Automated Strength (IAC-10.4) |
GPO password complexity configuration export; fine-grained password policy settings | AD |
✓ Supported |
| RG-8 Password lockout |
Account Lockout (IAC-22) | GPO account lockout policy configuration; lockout threshold and duration settings | AD |
✓ Supported |
| RG-9 Prohibition of password reuse |
Authenticator Mgmt (IAC-10) | GPO password history enforcement configuration | AD |
◔ Partial |
| RG-10 Complex passwords for default admin |
Authenticator Mgmt (IAC-10) | Build checklist documenting admin password requirements; LAPS configuration export | Various |
◔ Partial |
| RG-11 Change defaults per hardening |
Authenticator Mgmt (IAC-10) | Build checklist; CIS Benchmark hardening documentation; default credential change records | Various |
◔ Partial |
| RG-12 Continuously monitor privilege changes |
Account Logging (MON-16.4) | Windows Security Event Logs (4728, 4732, 4756); SIEM log forwarding configuration | ADLogRhythm |
◔ Partial |
| RG-13 Alert security team on privilege changes |
Account Logging (MON-16.4) | SIEM alert rules for privilege escalation; investigation ticket samples; escalation procedures | LogRhythm |
◔ Partial |
| RG-14 Automate access management |
Account Management (IAC-15) | ServiceNow provisioning workflow configuration; automated approval chain documentation | ServiceNow |
◔ Partial |
| RG-15 Establish termination process |
Personnel Termination (HRS-09) High-Risk Termination (HRS-09.2) |
ServiceNow termination tickets; AD account disable logs; offboarding checklist records | ServiceNowAD |
✓ Supported |
| RG-16 Remove terminated access immediately |
Personnel Termination (HRS-09) | AD disable timestamps correlated with termination date; VPN certificate revocation logs | ADVPN |
◔ Partial |
The following guidance is advisory and separate from the assessment findings in Section 4. Business impact, exam impact, recommendations, and remediation owners reflect professional interpretation and are provided for management planning purposes.
| ID | Theme | Business Impact | Exam Impact | Recommendation | Owner |
|---|---|---|---|---|---|
| F-001 | Access Review Ownership | Inappropriate access may persist — reviewers lack business context | Examiner will request owner-conducted reviews | Assign system owners; quarterly reviews with sign-off | CISO |
| F-002 | Privilege Change Monitoring | Unauthorized changes to critical systems may go undetected | Examiner will request continuous monitoring evidence | Tiered monitoring; prioritize critical systems | SOC |
| F-003 | Alert Investigation Process | Cannot demonstrate alerts are investigated and resolved | Examiner will request investigation records | Documented investigation procedures with escalation | SOC |
| F-004 | Device Authorization | Unauthorized devices may access resources via non-domain channels | Examiner will note "individuals and devices" partially met | NAC or certificate-based auth for non-domain endpoints | Infra Eng |
| F-005 | Least Privilege Justification | Access may exceed business need after role changes | Examiner expects documented justification for grants | Require business purpose on access tickets; review on role change | CISO |
| F-006 | Admin Password Standards | Admin accounts with standard passwords more vulnerable | Examiner will request enhanced admin requirements | Document and enforce elevated admin password requirements | GRC |
| F-007 | Hardening Documentation | Unchanged defaults are a known attack vector | Examiner will request hardening docs and evidence | Link checklists to hardening guides; automate verification | GRC |
| F-008 | Access Automation | Manual processing introduces delay, error, privilege creep | Examiner will note automation requirement unmet | Integrate ServiceNow with AD provisioning | IAM |
| F-009 | RBAC Formalization | Informal roles hard to verify during access reviews | Examiner will request role-based group descriptions | Formal role definitions with permission mappings | GRC |
| F-010 | Password Reuse Policy | Low risk — technical enforcement in place; policy gap | Examiner may note policy vs. technical enforcement gap | Add explicit reuse prohibition to policy | GRC |
| F-011 | Termination Timeliness | 2-3 day window of unauthorized access on standard terms | Examiner will note "immediately" vs. 2-3 days | Immediate-disable for all terminations; extend to all systems | IAM |
Heritage Community Bank — Risk & Control Library v1.0
568 controls across 32 domains (SCF-aligned). All control IDs referenced in this assessment link directly to the source control library for full description verification.
Review procedure: Click any control ID in Sections 2–3 to open the control library, verify the full control description, then use the browser back button to return to this report.
AI-Assisted Assessment. This workpaper was produced using an AI-assisted coverage assessment methodology. All verdicts, findings, and classifications were generated by a local large language model operating under deterministic prompt instructions and a structured findings taxonomy. AI-generated output requires human review and professional judgment before use in any regulatory, compliance, or audit context.
Not a Substitute for Professional Judgment. This assessment does not constitute an audit opinion, attestation, or assurance engagement. Coverage ratings reflect the assessor’s analysis of control descriptions against CRI v2.2 Response Guidance requirements. They do not represent an opinion on the operating effectiveness of controls, the adequacy of the institution’s overall control environment, or compliance with any law, regulation, or standard.
Data Privacy. All client data was processed locally using on-premises inference. No client control descriptions, evidence, or institutional information was transmitted to any external service, cloud API, or third-party system during the production of this workpaper.
Synthetic Demonstration. Heritage Community Bank is a fictional institution created for research and portfolio purposes. All institutions, regulatory findings, control descriptions, data, and deliverables shown in this workpaper are simulated. No real client data appears in this document.
Framework Reference. CRI v2.2 is published by the Conference of State Bank Supervisors (CSBS). References to CRI diagnostic statements and response guidance are used for assessment purposes under fair use. This workpaper is not endorsed by, affiliated with, or certified by CSBS.