Evaluate an organisation's current security posture against a chosen framework (NIST, ISO 27001, CIS) and produce a gap analysis with remediation priorities.
I need a security posture gap analysis against .
Current state summary:
- Industry:
- Organisation size:
- Key controls currently in place:
- Known weaknesses or recent findings:
- Regulatory obligations:
Please produce:
1. A gap assessment table mapping current state to framework requirements
2. A RAG status (Red / Amber / Green) for each control domain
3. A prioritised remediation roadmap ordered by risk exposure
4. An estimate of implementation complexity (Low / Medium / High) per gap
5. A one-page executive summary suitable for board reporting
Flag any assumptions you're making, and ask me to confirm or correct them before you begin.