gap_analysis
Identifies controls with weak or missing audit evidence, providing honest reasons and remediation steps for HIPAA, PCI-DSS, SOC 2, or GDPR frameworks.
Instructions
[READ] Controls with no/weak evidence, each with an honest reason + remediation.
States the design-vs-operating caveat: audit trails evidence operating effectiveness strongly and control design/configuration only partially.
Args: framework: hipaa / pci_dss / soc2 / gdpr. since / until: ISO timestamps bounding the period.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| since | No | ||
| until | No | ||
| framework | Yes |