gap_analysis
Identify compliance controls with missing or weak evidence for HIPAA, PCI-DSS, SOC 2, or GDPR. Get each gap's reason and remediation, while noting that audit trails prove operations but only partially validate design.
Instructions
[READ] Controls with no/weak evidence, each with an honest reason + remediation.
States the design-vs-operating caveat: audit trails evidence operating effectiveness strongly and control design/configuration only partially.
Args: framework: hipaa / pci_dss / soc2 / gdpr. since / until: ISO timestamps bounding the period.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| since | No | ||
| until | No | ||
| framework | Yes |