Risk AssessmentMITRE ATT&CKD3FENDThreat MappingCRI ProfileDetection EngineeringFFIEC

CRI Threat Advisory — From Control Gaps to Threat-Informed Risk Decisions

Transform control coverage gaps into actionable threat intelligence by connecting CRI requirements to adversary behavior, defensive countermeasures, regulatory exposure, detection opportunities, and prioritized remediation. This demonstration shows how a defensible analytical chain can bridge GRC, cyber risk, and security operations while preserving evidence lineage and distinguishing assessed fact from analytical inference. AI-assisted, human-governed analysis with explicit provenance and review boundaries.

Updated 2026-07-20

Interactive artifacts included below — CRI Threat Advisory Report, CRI Threat Mapper Prompt v11.3.

Synthetic Demonstration

Heritage Community Bank is a fictional institution. All controls, gap profiles, threat mappings, regulatory assertions, and detection rules shown here are simulated for research and portfolio purposes.

The Problem

A coverage assessment tells you what is missing. It does not tell you what can go wrong because it is missing. Traditional framework assessments often stop at Full, Partial, or Gap. Risk leaders still need to understand: • Which adversary behaviors could exploit those weaknesses? • Which gaps create compound exposure across multiple requirements? • What should security operations detect or monitor? • What evidence would demonstrate remediation? • Where should limited remediation resources go first? The CRI Threat Advisory extends the assessment beyond compliance status into threat-informed risk intelligence.

My Role

I designed and developed the assessment methodology and AI-assisted analytical workflow demonstrated here, integrating control assessment, CRI requirements, MITRE ATT&CK, MITRE D3FEND, regulatory considerations, detection engineering, and evidence-based remediation into a traceable risk-analysis pipeline. My focus was not simply generating mappings. It was designing a governed reasoning process in which analytical claims remain traceable, challengeable, and subject to human judgment.

The Analytical Chain

The advisory systematically maps through a defined chain where each step builds on the prior step's output: Assessment → Threat → Defense → Detection → Remediation → Assurance The detailed lineage: CRI Requirement → Coverage Gap → ATT&CK Technique → D3FEND Countermeasure → Regulatory Exposure → Detection Logic → Evidence of Closure → Remediation Every downstream assertion remains traceable to the specific assessed gap that initiated the analysis. The gap profile uses framework requirement language, not institutional control language — a deliberate confidentiality design that enables portability without exposing institutional defenses.

What the Advisory Produces

The advisory converts an assessed CRI gap profile into five decision layers: 1. Risk exposure — residual risk and highest-consequence weaknesses 2. Threat exposure — ATT&CK techniques associated with specific gaps 3. Defensive response — D3FEND countermeasures and control improvements 4. Detection opportunity — SIEM sources, detection logic, and monitoring priorities 5. Assurance closure — KPIs, remediation actions, and evidence required to demonstrate closure

From Individual Gaps to Compound Risk

Individual control gaps can appear modest when assessed independently. Their significance changes when multiple gaps expose the organization to the same adversary technique. The advisory clusters ATT&CK techniques across CRI requirements to identify these concentrations. If one adversary technique is enabled by weaknesses across five separate requirements, remediation priority should reflect the combined exposure — not five isolated compliance findings. This moves prioritization from gap counting toward risk concentration.

Human Judgment & AI Governance

The advisory is designed as decision support, not autonomous judgment. AI accelerates research, mapping, synthesis, and hypothesis generation. Human reviewers remain accountable for validating material mappings, challenging inference, determining applicability, and approving conclusions used in risk decisions. The methodology explicitly separates: Assessed Fact — supported by assessment evidence Framework Mapping — traceable to authoritative sources Analytical Inference — generated interpretation requiring review Professional Judgment — conclusions accepted or modified by accountable humans This distinction creates a practical governance boundary for AI-assisted risk assessment.

From Assessment to Assurance

This artifact is one stage in an end-to-end assurance architecture — not a standalone AI demonstration. Governance Intent → Structured Controls → Coverage Assessment → Threat Intelligence → Detection → Remediation → Evidence of Closure Board Risk Appetite establishes governance intent and severity calibration. Control Profiler structures institutional controls into reusable metadata. CRI Coverage Assessment maps controls to CRI requirements and produces the gap profile. CRI Threat Advisory transforms that gap profile into threat-informed risk intelligence. Each stage's output feeds the next. The closed loop from assessment gap → threat mapping → detection engineering → audit test procedure → evidence of closure is what distinguishes this from generic cybersecurity analysis.

Design Decisions & Professional Judgment

Why gap profiles should be expressed in framework language, not control language — and how that design decision enables both confidentiality and portability. The difference between an advisory (research input for risk analysts) and a deliverable (audit opinion with professional liability). Why that distinction matters for AI-assisted governance. Why the analytical chain must be explicit and traceable — each mapping step is a claim that can be challenged, verified, or overridden by a human reviewer. How the advisory connects upstream (CRI assessment) to downstream (SOC detection engineering) — bridging compliance, risk management, and security operations in one governed pipeline.

Artifacts