Interactive artifacts included below — CRI Assessment Workpaper, CRI Threat Advisory Report.
Situation
Community bank needed to demonstrate CRI Profile v2.2 coverage to regulators. Traditional keyword-matching approaches produced inconsistent results that didn't survive examiner scrutiny. No existing methodology mapped controls to CRI diagnostic statements with evidence traceability.
Responsibility
Tristan designed the entire assessment methodology end-to-end — from control profiling taxonomy through multi-stage reasoning pipeline to final coverage workpapers. No existing template or framework to follow; built from first principles using NIST, CRI, and MITRE source materials.
Judgment
Chose a threat-informed approach (MITRE ATT&CK techniques mapped to CRI requirements) rather than simple keyword matching. Designed deterministic rules for consistency with AI-assisted analysis only where human judgment would be inconsistent. Built in human review gates — AI never makes final coverage determinations unsupervised.
Deliverable
Complete assessment methodology with: control profiling classifier (18-verb taxonomy, 7 dimensions), CRI Response Guidance decomposition into assessable capabilities, multi-stage coverage pipeline, interactive workpapers with Coverage Decision Records, and findings taxonomy.
Evidence
PR.AA-01.01 workpaper assessing 568 controls against 16 capabilities. Every verdict traceable from requirement → control → evidence → rationale → conclusion.
Outcome
Methodology produces defensible coverage determinations. 31% Covered, 69% Partial for pilot DS — identifies specific gaps (service account governance, continuous privilege monitoring) with remediation guidance. Assessment artifacts survive examiner review because every conclusion links to source material.
What I Would Discuss in an Interview
How I balanced AI-assisted analysis with human accountability. Why threat-informed (MITRE) context matters for severity calibration. How the methodology handles disagreement between automated and human assessments. The design decision to separate knowledge, reasoning, quality, and reporting layers.
Artifacts
CRI Assessment Workpaper
Complete CRI v2.2 coverage assessment with interactive review mode, Coverage Decision Records, findings taxonomy, and evidence traceability matrix.
Open artifact →
CRI Threat Advisory Report
Threat advisory for PR.AA-01.01 with MITRE ATT&CK mappings, D3FEND countermeasures, regulatory exposure analysis, detection logic, and prioritized remediation.
Open artifact →