TechGuard CMA — Gap Assessment Report
Include
NIST CSF 2.0 GLBA SAFEGUARDS RULE CIS CONTROLS v8 · IG2
Cybersecurity Maturity
& Gap Assessment
Point-in-time assessment across {{ fwList }}, with a prioritized remediation roadmap and POA&M.
Prepared for
{{ coverClient }}
{{ coverSub }}
Lead assessor
{{ leadAssessor }}
Assessment date
{{ coverDate }}
Overall Maturity
{{ overallPct }}% {{ overallLevel }}
0–4 maturity scale, normalized
Controls Assessed
{{ assessedN }}
{{ openGaps }} open gaps · {{ criticalGaps }} critical
Assessment date {{ coverDate }}  ·  Assessor {{ assessor }}
Contents
This assessment report is organized into the following sections.
{{ g.label }}
{{ it }}
Executive Summary
{{ posture }}
FERPA Compliance Check (Higher-Ed)
{{ ferpaSub }}
AreaRequirementRefScoreStatus
{{ f.domain }}{{ f.question }}{{ f.ref }}{{ f.score }}{{ f.status }}
Assessed Entity
{{ e.k }}{{ e.v }}
Scope: {{ scopeText }}
Assessment Scope Diagram
Logical view of the environment handling student nonpublic personal information (NPI).
Assessment Boundary — Student NPI Environment · {{ coverClient }}

Identity & Access

Microsoft Entra ID · MFA / conditional access · Privileged access management

Core Systems

Ellucian Banner (SIS/ERP) · Financial Aid / Billing · FAFSA / EdConnect & COD

Student NPI Data Stores

File server & Microsoft 365 · Encrypted repositories · Backups (offsite VM + M365)

Security Operations

Logging / monitoring · Vulnerability & patch mgmt · Backup & recovery · SUNY SOC (partial)

▲ managed connections cross the boundary ▲
External Connections

Remote / telework users · Cloud & SaaS · Managed services (Verona) · Third-party / vendor access — through managed, monitored control points.

Out of Scope

Systems that neither store, process, nor transmit student NPI and are separated from the boundary above. Confirm separation before excluding.

Methodology & Scope

This assessment evaluates the organization against {{ fwList }}. Each control was assigned a 0–4 maturity score: 0 Not Implemented, 1 Ad-hoc, 2 Partially, 3 Largely, 4 Fully Implemented.

Scoring. Maturity is the mean 0–4 score per framework, normalized to 100. Any control scored 2 or below is treated as an open gap and carried into the POA&M and roadmap. For higher education, FERPA compliance generally satisfies the GLBA Privacy Rule for student records.

Confidentiality. Prepared by TechGuard Security · GRC Assessment Team for {{ coverClient }}. Contains sensitive security information; handle per the institution's data classification policy.

Maturity Scorecard
Normalized 0–100 maturity across all in-scope controls. Target posture is "Managed" (60%+).
0Target 60100
{{ overallPct }}% · {{ overallLevel }}
MetricValue
{{ m.label }}{{ m.value }}
Maturity Trend
{{ trendSub }}
{{ trendChart }}
SnapshotOverallCSFGLBACISOpen gaps
{{ r.date }}{{ r.overall }}{{ r.csf }}{{ r.glba }}{{ r.cis }}{{ r.gaps }}
N/A — capture at least two dated snapshots in the app's Report tab (Maturity History) to chart a trend over time.
Framework & Domain Breakdown
{{ breakdownSub }}
AreaDomainMaturityOpen gapsCoverage
{{ b.group }}{{ b.label }}{{ b.pct }}%{{ b.gaps }}{{ b.level }}
Plan of Action & Milestones (POA&M)
Controls not fully implemented, in priority order (highest risk first).
SourceRefFindingPriorityOwner
{{ g.fw }}{{ g.ref }}{{ g.title }}{{ g.priority }}{{ g.owner }}
Control Gap Risk Overview
Gap-exposure view derived from unmet controls, scored likelihood × impact (1–5). This exposure drives the phasing of the remediation plan that follows.
ScenarioSourceL×IScoreSeverity
{{ r.title }}{{ r.src }}{{ r.li }}{{ r.score }}{{ r.severity }}
Remediation Timeline
Open items phased by priority, with projected overall maturity after each phase closes.
PhaseTimeframeItemsFocusProjected maturity
{{ r.name }}{{ r.timeframe }}{{ r.count }}{{ r.focus }}{{ r.projected }}%
Remediation Roadmap — Phase Plans
Each phase's open items grouped into workstreams, with the accountable owner and representative control references.
{{ ph.name }} {{ ph.timeframe }} · {{ ph.count }} items
{{ ph.objective }}
WorkstreamItemsOwnerControl refs
{{ d.ws }}{{ d.count }}{{ d.owner }}{{ d.refs }}
Interview Findings
Key stakeholder responses gathered during assessment interviews, with the assessor's observation and risk flag.
{{ i.topic }} {{ i.flag }}
Response  {{ i.resp }}
Observation  {{ i.obs }}
Cyber-Insurance Readiness
Status of the key controls carriers underwrite. Gaps here typically drive higher premiums, coverage exclusions, or declined applications.
Underwritten controlStatus
{{ i.ctrl }}{{ i.status }}
Carriers increasingly require MFA, EDR, and tested immutable backups as baseline conditions of coverage. Closing the Phase 1 items above materially strengthens renewal position and can reduce premium exposure.
Regulatory Mapping
Statutory and contractual obligations in scope for this institution, mapped to the assessed frameworks.
RequirementCore obligationFramework mappingApplicability
{{ r.req }}{{ r.obl }}{{ r.map }}{{ r.app }}
Control-by-Control Detail
Full maturity score for every assessed control across the three frameworks. Rows scored 2 or below are open gaps carried into the POA&M.
RefControl / outcomeAreaScoreMaturity
{{ r.label }}
{{ r.ref }}{{ r.title }}{{ r.area }}{{ r.score }}{{ r.status }}
Appendix — Evidence Artifacts by Domain
Representative documentation and technical evidence collected to demonstrate each domain. Actual requirements depend on the environment and implementation.
DomainRepresentative evidence artifacts
{{ e.fam }}{{ e.art }}
Appendix — Governance Document Inventory
Policies and standards the program requires, their current state, and framework mapping. "Gap" documents are deliverables on the remediation roadmap.
DocumentMaps toCurrent stateStatusAction
{{ g.doc }}{{ g.maps }}{{ g.status }}{{ g.pillTxt }}{{ g.note }}
Glossary of Terms
Key terms and acronyms used throughout this assessment.
{{ g.t }}{{ g.d }}
How TechGuard Can Help
The findings in this report point to one root cause: no single accountable owner driving the program to done. A fractional CISO (vCISO) closes that gap directly.

TechGuard embeds a named security leader into your team — owning the risk register, holding IT and vendors accountable, and driving the remediation roadmap in this report to closure. Two right-sized engagements:

PackageCapacityInvestmentWhat’s included
Overseer 2 hrs / month $6,000 / year Executive-level advisory voice. Monthly review of open risks with prioritization guidance, validation that initiatives align to business risk, and high-level cyber-insurance & audit-readiness input. No day-to-day program ownership.
Advisor 5 hrs / month $12,000 / year Everything in Overseer, plus a monthly security review with leadership and tracked actions, a maintained risk register with monthly updates, remediation-priority guidance for IT/MSP, board talking points, and status tracking of overdue items.
12-month minimum recommended for full gap closure. Larger Leader (10 hrs/mo) and Owner (20+ hrs/mo) engagements are available for deeper program ownership.
Assessment Attestation
The undersigned attest that this assessment accurately reflects the organization's implementation of the assessed controls as of the assessment date.
{{ assessor }}
Assessor — TechGuard Security
 
Authorizing Official — {{ coverClient }}
Date: {{ coverDate }}Date: ______________________
TechGuard Security — Cybersecurity Maturity Advisor · CSF 2.0 · GLBA · CIS v8 · Assessment values are self-reported unless independently verified.