← Back to Demo Home
Assessment Methodology

How Coverage Determinations Are Made

The process for assessing a bank's controls against CRI v2.2 Response Guidance

The Core Question

Every coverage assessment answers one question: does the control actually satisfy what the Response Guidance requires? The methodology shifts the question from keyword matching to capability matching.

Traditional Approach
“Which controls mention authentication?”
This Methodology
“Which capabilities does this control actually implement, and do those satisfy the requirement?”

A control that mentions authentication in passing is not the same as a control that implements authentication. The methodology reads what the control actually says it does, not whether it uses the right keywords.


The Process

Step 1
Decompose
Break each Response Guidance into individual capabilities it requires. One RG sentence may contain 2–4 distinct requirements.
Step 2
Select
Read each control in the library. Determine which controls are even in scope for this requirement — most are not.
Step 3
Assess
For each selected control, read its description against the RG capability. Does the control’s own language satisfy what the RG asks for?
Step 4
Document
Quote the evidence. State the gap. Every determination traces to source language a reviewer can verify independently.

Walkthrough — Three Ratings

The following examples are from the PR.AA-01.01 (Identity and Credential Management) pilot assessment against Heritage Community Bank’s 568-control library.

Rating: Covered

Covered Account Lockout After Failed Attempts
What the RG Requires
RG-14
The institution locks user accounts after a defined number of consecutive failed authentication attempts.
What the Control Says
IAC-22 — Account Lockout
AD Group Policy locks accounts after 5 consecutive failed login attempts for a 30-minute duration. The same policy applies to VPN authentication through AnyConnect. Duo lockout is configured after 10 failed MFA attempts.
Assessment Logic
The RG requires account lockout after failed attempts. The control explicitly states that AD locks after 5 failures and Duo locks after 10 MFA failures. Both the primary authentication path and the MFA path have lockout thresholds. The control’s own language fully satisfies the requirement.
Rating: Covered — the control addresses all aspects of the capability.

Rating: Partial

Partial Personnel Termination Access Revocation
What the RG Requires
RG-16
Access is revoked promptly upon personnel termination, including disabling credentials and recovering physical assets across all systems.
What the Control Says
HRS-09 — Personnel Termination
HR notifies IT of terminations via ServiceNow ticket. IT disables Active Directory accounts and revokes VPN access. Average time from notification to revocation is 2–3 business days. Badge deactivation is handled separately by facilities. Badge return from remote workers is inconsistent.
Assessment Logic
The RG requires prompt revocation across all systems including physical assets. The control confirms AD and VPN access are revoked — but takes 2–3 days (not prompt). Badge deactivation is a separate process. Badge return for remote workers is inconsistent. The control has a revocation process, but it does not satisfy “promptly” or “across all systems.”
Rating: Partial — the control addresses credential revocation but not the timeliness or physical asset requirements.

Rating: No Coverage

No Coverage Automated Credential Revocation
What the RG Requires
RG-16 (sub-capability)
Automated mechanisms trigger credential revocation upon termination events, without relying on manual notification processes.
What the Control Library Contains
No control in the 568-control library describes an automated trigger between HR termination events and credential revocation.
Assessment Logic
The assessor searched the full control library for any control that describes automated credential revocation triggered by HR events. HRS-09 describes a manual ServiceNow ticket process. No other control addresses automation of this workflow. The gap is not that the process is slow — the gap is that no automated mechanism exists at all.
Rating: No Coverage — no control in the library addresses this capability.

Coverage Ratings

Covered
The control fully addresses all aspects of the Response Guidance capability. The control’s own language satisfies the requirement without qualification. A single “Covered” rating means one control handles the entire capability.
Partial
The control addresses some aspects but not all. The assessor identifies specifically what is covered and what is missing. Multiple Partial controls can combine to provide full coverage when each addresses a different aspect of the requirement.
No Coverage
No control in the entire library addresses any aspect of this capability. This is not a judgment about a single control — it means the assessor searched the full library and found no match. This identifies a genuine gap in the institution’s control environment.

Key Principles

Evidence comes from control language, not inference. If the control description doesn’t say it, the assessor doesn’t assume it. A control that “probably” does something is not evidence.

Gaps are stated in the assessor’s words. Control language is quoted with attribution. Gap findings are the assessor’s professional conclusion, written without quotation marks, based on what the control library does not contain.

Every rating is independently verifiable. A reviewer can read the RG requirement, open the control library, read the control description, and confirm whether the rating is reasonable — without relying on the assessor’s interpretation alone.

Every determination can be independently reproduced using only the evidence, methodology, and decision record.