Sample report

What you receive at the end of every full assessment.

Our full assessments conclude with clear, executive-ready reporting — designed for leadership to understand quickly and detailed enough to support audit and remediation activities.

Additional assessment formats, including ISO/IEC 27001 readiness reporting, may be tailored to the agreed engagement scope.

SAMPLE — ILLUSTRATIVE ONLY

Sample data. The organization name and findings below are illustrative, shown to demonstrate report format and structure — not an actual client engagement.

KGA PARTNERS — ASSESSMENT REPORT

NIST SP 800-53 Rev. 5 — Gap Assessment Report

Acme Technology Services, LLC  |  Illustrative Sample

Report date: [Date]

Prepared by: Sherif Kassem, CISA®

Scope: Access Control, Audit & Accountability, Risk Assessment

EXECUTIVE SUMMARY

3

High-risk findings

5

Moderate-risk findings

4

Low-risk findings

12

Total findings

The assessment identified 12 findings across the assessed control families. Three high-risk findings require immediate attention and relate to access management and audit log integrity. Five moderate-risk findings represent control design gaps that should be addressed within 60–90 days. Four low-risk findings reflect documentation or process maturity items suitable for a standard improvement cycle.


HIGH-RISK FINDINGS

HIGH
AC-2 — Account Management: Privileged accounts not reviewed on a defined schedule No formal access review process exists for privileged accounts. Accounts of terminated employees were found to remain active beyond the defined deprovisioning window. Remediation: Implement a quarterly privileged access review process with documented sign-off and integrate with HR offboarding procedures.
HIGH
AU-9 — Audit Log Protection: Logs accessible to standard users Audit logs are stored in a location accessible to non-administrative users, creating risk of tampering or deletion. Remediation: Restrict log access to authorized security personnel only; implement log integrity monitoring or SIEM forwarding to a protected destination.
HIGH
RA-3 — Risk Assessment: No documented risk assessment on file The organization has not completed a formal, documented IT risk assessment within the defined assessment period. Remediation: Conduct and document a risk assessment covering information systems, data classification, and applicable threats; establish an annual review cycle.

MODERATE-RISK FINDINGS

MODERATE
AC-17 — Remote Access: MFA not enforced for all remote access sessions Multi-factor authentication is configured for some but not all remote access pathways. Remediation: Enforce MFA across all remote access methods including VPN, RDP, and cloud management portals.
MODERATE
CM-6 — Configuration Settings: No baseline configuration documented for servers Server configurations are not documented against an approved baseline, making deviation detection and change review inconsistent. Remediation: Establish and document approved baseline configurations for servers and workstations; implement change detection against baseline.
MODERATE
SI-2 — Flaw Remediation: Patch management process not formally documented Patching occurs on an ad hoc basis without a defined schedule, documented ownership, or evidence of testing prior to deployment. Remediation: Establish a documented patch management procedure with defined timelines by severity, ownership, and evidence of completion.

LOW-RISK FINDINGS

LOW
AT-2 — Security Awareness Training: Training completion not tracked centrally Security awareness training is conducted but completion records are not centrally maintained or reviewed. Remediation: Implement a tracking mechanism for training completion with annual reporting to management.
LOW
PL-4 — Rules of Behavior: Policy acknowledgment not collected annually User acknowledgment of rules of behavior is collected at onboarding but not renewed annually. Remediation: Establish an annual re-acknowledgment process; document and retain signed acknowledgments.

TOP 5 HIGHEST-RISK FINDINGS — REMEDIATION PRIORITIES

1
AC-2 — Privileged account review process

Implement quarterly access review with HR offboarding integration

2
AU-9 — Audit log protection

Restrict log access; forward to protected SIEM destination

3
RA-3 — Risk assessment

Conduct and document annual IT risk assessment

4
AC-17 — Multi-factor authentication

Enforce MFA across all remote access pathways

5
CM-6 — Configuration baseline

Document and enforce approved server configuration baselines


SAMPLE — ILLUSTRATIVE ONLY. Sample data. The organization name and findings above are illustrative, shown to demonstrate report format and structure — not an actual client engagement.

Want a report like this for your organization?

Schedule a 20-minute discovery call to determine the right scope and framework for your situation.

Schedule a 30 Minute Meeting