Portfolio Sample — Synthetic Demonstration
Heritage Community Bank is a fictional institution. All data, controls, findings, and regulatory matters shown here are simulated for research and portfolio purposes. This workpaper demonstrates the CRI Coverage Assessment Methodology developed by Tristan Jones.
Heritage Community Bank — CRI v2.2 Coverage Assessment Workpaper

PR.AA-01.01

Identity and Credential Management
Coverage Across 16 Response Guidance Requirements
5 11
5 Covered (31%) 11 Partial (69%) 0 No Coverage
Run PR_AA_01_01_20260706_181004 Model qwen3:32b Duration 2h 42m Date 2026-07-06
Section 1 — Criteria

CRI Requirements & Expected Evidence

Data: criteria.ds_text, criteria.rg_annotations, criteria.eee_package

Diagnostic Statement

PR.AA-01.01: Identities and credentials are actively managed or automated for authorized devices and users (e.g., removal of default and factory passwords, password strength requirements, automatic revocation of credentials under defined conditions, regular asset owner access review, etc.).

Response Guidance — Annotated

The goal of access control is to allow access by authorized individuals and devices RG-1 and to disallow access by all others. RG-2 Role-based access control may be considered to simplify management activities. RG-3 Access should be authorized and provided only to individuals whose identity is established, RG-4 and their activities should be limited to the minimum required for business purposes. RG-5 Asset owners should regularly review access roles and individuals authorized to access the system to verify appropriate access management procedures. RG-6 Access controls should include password complexity, RG-7 limitation of the number of password attempts before a user is locked out, RG-8 and prohibition of the reuse of passwords. RG-9 The organization should create complex passwords for default administration passwords, otherwise the network may be vulnerable to attack or employee abuse. RG-10 Default passwords should be changed per system implementation guidelines, change management procedures or system hardening documentation. RG-11 Changes to access privileges of critical systems should be continuously monitored RG-12 and any changes to those access privileges should result in an alert and notification to the proper security team to investigate, document, and resolve any issues. RG-13 Where possible, access management activities should be automated to reduce error and manual processing overhead. RG-14 Access management policies and procedures should establish a process for terminating users. RG-15 If an organization terminates an individual’s employment, there should be measures in place that require that user’s access to any asset or system be removed immediately. RG-16
Section 2 — Testing

Control Coverage Analysis

Data: rg_verdicts.verdicts[], rg_verdicts.funnel

One card per RG. Each control is assessed individually. Evidence quoted from control descriptions; coverage statements explain what the quote satisfies; gap statements identify what is absent.

RG-1Allow access by authorized individuals and devicesPartial
ControlNameRatingEvidence / Gap
IAC-15Account ManagementPartial“AD accounts are managed through security groups for access to file shares, applications, and M365 resources.”This addresses user-level authorization through AD security group membership.Missing device-level authorization.
IAC-04I&A for DevicesPartial“Domain-joined devices authenticate to AD via machine certificates and Kerberos.”This addresses device authentication for domain-joined endpoints.Missing non-domain and personal device authorization.
HRS-05.5Use of Mobile DevicesPartial“Mobile device access to bank email and applications requires MDM enrollment.”This addresses mobile device authorization for email access.Missing non-email mobile access authorization.
RG-2Disallow access by all othersCovered
ControlNameRatingEvidence / Gap
NET-04.1Deny by DefaultCovered“The Palo Alto PA-850 firewalls are configured with a default-deny policy — all traffic is blocked unless explicitly permitted by a rule.”This fully addresses the default-deny access posture.
RG-3Consider role-based access controlPartial
ControlNameRatingEvidence / Gap
IAC-20Access EnforcementPartial“AD security groups and GPOs enforce access based on department templates.”This addresses functional role-based access through AD security groups.Missing formal role definitions and role-to-permission mappings.
RG-4Identity established before accessCovered
ControlNameRatingEvidence / Gap
IAC-02I&A for Org UsersCovered“All employees and contractors authenticate through Active Directory with unique user IDs. Duo MFA is enforced for VPN and M365 access.”This fully addresses identity establishment and multi-factor authentication.
IAC-09.1User Identity MgmtCovered“Each employee receives a unique AD account upon hire. IT verifies identity based on HR’s onboarding documentation.”This fully addresses identity verification at onboarding.
CRY-07Wireless AuthCovered“Corporate wireless uses WPA2-Enterprise with RADIUS authentication against Active Directory.”This fully addresses identity-based wireless access.
RG-5Limit to minimum requiredPartial
ControlNameRatingEvidence / Gap
IAC-21Least PrivilegePartial“New accounts are provisioned using department-based AD templates that grant minimum required access.”This addresses initial provisioning with least-privilege templates.Missing business purpose justification and privilege creep management on role change.
RG-6Asset owners regularly review accessPartial
ControlNameRatingEvidence / Gap
IAC-15Account ManagementPartial“Annual access reviews for core banking (Symitar).”This addresses periodic access review for the core banking system.Missing asset/system owner review assignment and review frequency for non-core systems.
RG-7Password complexityCovered
ControlNameRatingEvidence / Gap
IAC-10.1Password-Based AuthCovered“AD Group Policy enforces 12-character minimum passwords with complexity requirements (uppercase, lowercase, number, special character).”This fully addresses password complexity enforcement.
IAC-10.4Automated StrengthCovered“AD Group Policy automatically rejects passwords that do not meet the 12-character minimum, complexity, and history requirements.”This fully addresses automated rejection of non-compliant passwords.
RG-8Password lockoutCovered
ControlNameRatingEvidence / Gap
IAC-22Account LockoutCovered“AD Group Policy locks accounts after 5 consecutive failed login attempts.”This fully addresses account lockout after failed attempts.
RG-9Prohibition of password reusePartial
ControlNameRatingEvidence / Gap
IAC-10Authenticator MgmtPartial“10-password history enforced via AD Group Policy.”This addresses technical prevention of recent password reuse through history enforcement.Missing explicit password reuse prohibition in policy.
RG-10Complex passwords for default adminPartial
ControlNameRatingEvidence / Gap
IAC-10Authenticator MgmtPartial“Default passwords are changed during initial setup per the build checklist.”This addresses default password change during system provisioning.Missing enhanced complexity requirements for default admin accounts.
RG-11Change defaults per hardeningPartial
ControlNameRatingEvidence / Gap
IAC-10Authenticator MgmtPartial“Default passwords are changed during initial setup.”This addresses default password change at system deployment.Missing formal hardening documentation reference and automated verification.
RG-12Continuously monitor privilege changesPartial
ControlNameRatingEvidence / Gap
MON-16.4Account LoggingPartial“Active Directory logs account creation and group membership changes in the Windows Security Event Log.”This addresses log collection of privilege change events.Missing continuous monitoring and prioritized detection for critical systems.
RG-13Alert security team on privilege changesPartial
ControlNameRatingEvidence / Gap
MON-16.4Account LoggingPartial“LogRhythm has default rules for privileged logon and account creation events.”This addresses alert generation for privilege-related events.Missing documented investigation and resolution process for triggered alerts.
RG-14Automate access managementPartial
ControlNameRatingEvidence / Gap
IAC-15Account ManagementPartial“ServiceNow provides a request workflow for access changes.”This addresses workflow capture for access change requests.Missing automated provisioning, deprovisioning, and auto-revocation on role change.
RG-15Establish termination processCovered
ControlNameRatingEvidence / Gap
HRS-09Personnel TerminationCovered“HR notifies IT of terminations via ServiceNow ticket. IT disables Active Directory accounts and revokes VPN access.”This fully addresses the defined termination notification and access removal process.
HRS-09.2High-Risk TerminationCovered“IT is notified to disable access immediately.”This fully addresses expedited access removal for high-risk terminations.
RG-16Remove terminated access immediatelyPartial
ControlNameRatingEvidence / Gap
HRS-09Personnel TerminationPartial“IT disables Active Directory accounts and revokes VPN access.”This addresses access disablement for AD and VPN upon termination notification.Missing immediate removal for standard terminations and cross-system simultaneous removal.
Section 3 — Conclusion

Coverage Summary

Data: rg_verdicts.scorecard, rg_verdicts.verdicts[].rationale
RGRequirementAssessmentRationale
RG-1Allow access by authorized individuals and devicesPartialControls IAC-15 (Account Management), IAC-04 (I&A for Devices), and HRS-05.5 (Use of Mobile Devices) collectively address user authorization through AD security groups, domain device authentication via Kerberos, and mobile device authorization through MDM enrollment. The control set does not define a unified device authorization mechanism for non-domain and personal devices.Refer to the control-level assessments above for details.
RG-2Disallow access by all othersCoveredControl NET-04.1 (Deny by Default) establishes a default-deny firewall policy where all traffic is blocked unless explicitly permitted. This fully addresses the default-deny access posture.Refer to the control-level assessments above for details.
RG-3Consider role-based access controlPartialControl IAC-20 (Access Enforcement) addresses functional role-based access through AD security groups and department-based GPOs. The control set does not include formally documented role definitions or role-to-permission mappings.Refer to the control-level assessments above for details.
RG-4Identity established before accessCoveredControls IAC-02 (I&A for Org Users), IAC-09.1 (User Identity Mgmt), and CRY-07 (Wireless Auth) collectively address unique identity assignment, HR-validated onboarding verification, Duo MFA enforcement, and RADIUS-based wireless authentication.Refer to the control-level assessments above for details.
RG-5Limit to minimum requiredPartialControl IAC-21 (Least Privilege) addresses initial provisioning through department-based AD templates that grant minimum required access. The control set does not require business purpose justification for access grants or address privilege creep upon role change.Refer to the control-level assessments above for details.
RG-6Asset owners regularly review accessPartialControl IAC-15 (Account Management) addresses periodic access review for core banking (Symitar) on an annual basis. The control set does not assign review responsibility to asset or system owners, and does not define review frequency for non-core systems.Refer to the control-level assessments above for details.
RG-7Password complexityCoveredControls IAC-10.1 (Password-Based Auth) and IAC-10.4 (Automated Strength) collectively address 12-character minimum password enforcement with complexity requirements and automated rejection of non-compliant passwords.Refer to the control-level assessments above for details.
RG-8Password lockoutCoveredControl IAC-22 (Account Lockout) addresses account lockout after 5 consecutive failed login attempts via AD Group Policy.Refer to the control-level assessments above for details.
RG-9Prohibition of password reusePartialControl IAC-10 (Authenticator Mgmt) addresses technical prevention of recent password reuse through 10-password history enforcement via AD Group Policy. The control set does not explicitly prohibit password reuse in policy language.Refer to the control-level assessments above for details.
RG-10Complex passwords for default adminPartialControl IAC-10 (Authenticator Mgmt) addresses default password change during initial system setup per the build checklist. The control set does not specify enhanced complexity requirements for default administration accounts.Refer to the control-level assessments above for details.
RG-11Change defaults per hardeningPartialControl IAC-10 (Authenticator Mgmt) addresses default password change at system deployment. The control set does not reference formal hardening documentation or define automated verification of default password changes.Refer to the control-level assessments above for details.
RG-12Continuously monitor privilege changesPartialControl MON-16.4 (Account Logging) addresses log collection of privilege change events through AD Security Event Log forwarding to LogRhythm. The control set does not demonstrate continuous monitoring or prioritized detection for critical systems.Refer to the control-level assessments above for details.
RG-13Alert security teamPartialControl MON-16.4 (Account Logging) addresses alert generation for privilege-related events through LogRhythm default rules. The control set does not describe a documented investigation or resolution process for triggered alerts.Refer to the control-level assessments above for details.
RG-14Automate access managementPartialControl IAC-15 (Account Management) addresses workflow capture for access change requests through ServiceNow. The control set does not describe automated provisioning, deprovisioning, or auto-revocation on role change.Refer to the control-level assessments above for details.
RG-15Establish termination processCoveredControls HRS-09 (Personnel Termination) and HRS-09.2 (High-Risk Termination) collectively address the defined termination notification process, AD and VPN access disablement, and expedited removal for high-risk cases.Refer to the control-level assessments above for details.
RG-16Remove terminated access immediatelyPartialControl HRS-09 (Personnel Termination) addresses access disablement for AD and VPN upon termination notification. The control set does not define immediate removal for standard terminations or simultaneous removal across non-AD systems.Refer to the control-level assessments above for details.
Section 4 — Assessment Gaps

Per-RG Assessment Gaps

Data: rg_verdicts[verdict!=Covered] — L1 classification per findings_taxonomy.json v1.0

One assessment finding per Partial or No Coverage RG. Each classifies the root cause of the observed gap. Purely observational — advisory guidance is in Appendix A. Sorted by severity.

F-001 Access Review Ownership Governance Missing High
RG
RG-6
Observed GapNo control assigns access review responsibility to asset or system owners. Annual reviews exist for Symitar only; other systems reviewed ad hoc by IT.
Evidence
Account Management (IAC-15)
F-002 Privilege Change Monitoring Monitoring Weak High
RG
RG-12
Observed GapMonitoring is not continuous. High alert volume degrades effectiveness. Critical systems not prioritized for detection.
Evidence
Account Logging (MON-16.4)
F-003 Alert Investigation Process Monitoring Weak High
RG
RG-13
Observed GapAlerts deprioritized due to false positives. No documented investigation process for triggered privilege change alerts.
Evidence
Account Logging (MON-16.4)
F-004 Device Authorization Technology Inconsistent Medium
RG
RG-1
Observed GapDomain-joined devices authenticate via Kerberos. Non-domain devices (BYOD, mobile, contractor laptops) lack equivalent authorization. MDM covers email only.
Evidence
Account Management (IAC-15)I&A for Devices (IAC-04)Use of Mobile Devices (HRS-05.5)
F-005 Least Privilege Justification Governance Weak Medium
RG
RG-5
Observed GapNo business purpose justification required for access grants. Privilege creep from role changes addressed reactively, not proactively.
Evidence
Least Privilege (IAC-21)
F-006 Admin Password Standards Documentation Weak Medium
RG
RG-10
Observed GapNo explicit requirement for complex passwords on default administration accounts beyond standard user password policy.
Evidence
Authenticator Mgmt (IAC-10)
F-007 Hardening Documentation Documentation Weak Medium
RG
RG-11
Observed GapBuild checklist is inconsistent. Does not reference formal hardening documentation. No automated verification that defaults have been changed.
Evidence
Authenticator Mgmt (IAC-10)
F-008 Access Automation Process Inefficient Medium
RG
RG-14
Observed GapProvisioning and deprovisioning remain entirely manual. ServiceNow captures requests but does not trigger automated AD changes. No auto-revocation on role change.
Evidence
Account Management (IAC-15)
F-009 RBAC Formalization Documentation Weak Low
RG
RG-3
Observed GapRole definitions not formally documented. AD security groups provide functional RBAC but role-to-group mappings exist informally.
Evidence
Access Enforcement (IAC-20)
F-010 Password Reuse Policy Documentation Weak Low
RG
RG-9
Observed Gap10-password history enforced via AD Group Policy. Policy language does not explicitly prohibit password reuse.
Evidence
Authenticator Mgmt (IAC-10)
F-011 Termination Timeliness Process Inefficient Low
RG
RG-16
Observed GapStandard terminations take 2-3 business days. High-risk can be immediate. Non-AD systems (physical access, third-party apps) not simultaneously removed.
Evidence
Personnel Termination (HRS-09)
Section 5 — Evidence Traceability

Evidence Traceability Matrix

Data: criteria.response_guidance, assessment.control_mappings, criteria.technology_sources

Each CRI requirement traces forward through the supporting controls to the operational evidence an examiner will request. The Readiness column indicates whether the institution's control library provides a clear evidence path for each requirement.

CRI RequirementOrganization ControlsExpected EvidenceTechnology SourceReadiness
RG-1
Allow access by authorized individuals and devices
Account Management (IAC-15)
I&A for Devices (IAC-04)
Use of Mobile Devices (HRS-05.5)
AD security group membership exports; Kerberos machine authentication certificates; MDM enrollment records
ADMDM
◔ Partial
RG-2
Disallow access by all others
Deny by Default (NET-04.1) Firewall default-deny policy export; rule base review showing implicit deny
Palo Alto
✓ Supported
RG-3
Consider role-based access control
Access Enforcement (IAC-20) AD security group configuration; GPO role assignment export; group nesting documentation
AD
◔ Partial
RG-4
Identity established before access
I&A for Org Users (IAC-02)
User Identity Mgmt (IAC-09.1)
Wireless Auth (CRY-07)
AD account creation records; onboarding workflow documentation; Duo MFA enrollment logs; RADIUS authentication config
ADDuoRADIUS
✓ Supported
RG-5
Limit to minimum required
Least Privilege (IAC-21) Department role template configuration; least-privilege group assignment documentation
AD
◔ Partial
RG-6
Asset owners regularly review access
Account Management (IAC-15) Symitar access review reports; recertification completion records; owner sign-off artifacts
Symitar
◔ Partial
RG-7
Password complexity
Password-Based Auth (IAC-10.1)
Automated Strength (IAC-10.4)
GPO password complexity configuration export; fine-grained password policy settings
AD
✓ Supported
RG-8
Password lockout
Account Lockout (IAC-22) GPO account lockout policy configuration; lockout threshold and duration settings
AD
✓ Supported
RG-9
Prohibition of password reuse
Authenticator Mgmt (IAC-10) GPO password history enforcement configuration
AD
◔ Partial
RG-10
Complex passwords for default admin
Authenticator Mgmt (IAC-10) Build checklist documenting admin password requirements; LAPS configuration export
Various
◔ Partial
RG-11
Change defaults per hardening
Authenticator Mgmt (IAC-10) Build checklist; CIS Benchmark hardening documentation; default credential change records
Various
◔ Partial
RG-12
Continuously monitor privilege changes
Account Logging (MON-16.4) Windows Security Event Logs (4728, 4732, 4756); SIEM log forwarding configuration
ADLogRhythm
◔ Partial
RG-13
Alert security team on privilege changes
Account Logging (MON-16.4) SIEM alert rules for privilege escalation; investigation ticket samples; escalation procedures
LogRhythm
◔ Partial
RG-14
Automate access management
Account Management (IAC-15) ServiceNow provisioning workflow configuration; automated approval chain documentation
ServiceNow
◔ Partial
RG-15
Establish termination process
Personnel Termination (HRS-09)
High-Risk Termination (HRS-09.2)
ServiceNow termination tickets; AD account disable logs; offboarding checklist records
ServiceNowAD
✓ Supported
RG-16
Remove terminated access immediately
Personnel Termination (HRS-09) AD disable timestamps correlated with termination date; VPN certificate revocation logs
ADVPN
◔ Partial
Supported: 5
Partial: 11
No Supporting Control: 0
Section 6 — Assessment Methodology

Pipeline & Configuration

Data: assessment_metadata, report_manifest.methodology_pipeline_labels

Assessment Scope

568Control Library
112Controls Assessed
16CRI Requirements
5Fully Covered
11Assessment Gaps

Assessment Flow

568
Control Library Entry
Full bank control library loaded for assessment
112
Phase 1 — Domain Mapping
Filtered by CRI category → relevant control domains (IAC, HRS, MON…)
112
Stage 1 — Hard Exclusion
Is the control within CRI scope? — 0 excluded this assessment
0 Excluded
112
Stage 2 — Compatibility Factors
6 dimensions scored per control
🟢 Sector 🟢 Enterprise 🟡 User Type 🟢 Technology 🟢 Activity 🟡 Evidence
112
Phase 2 + Stage 3 — Semantic Analysis
Requirement intent vs. control intent — does it satisfy the RG?
48
Phase 3 — Capability Mapping
48 controls selected for detailed coverage assessment
Assessment Engine
v1.0.0
Methodology
CRI Coverage Assessment v1.0
CRI Framework
v2.2
Ontology
Security Capability Ontology v1.0 (48 capabilities, 7 domains)
Evidence Schema
v1.0 (artifact_type, collection_method, evidence_category, frequency, evidence_strength, owner)
Knowledge Pack
CRI v2.2 (318 DS, 113 EEE packages, 592 evidence items)
Findings Taxonomy
v1.0 (7 categories, 5 conditions, 4 severities)
Model
qwen3:32b via Ollama (local inference)
Control Library
Heritage Community Bank SCF-aligned (568 controls)
Domain Filter
IAC, HRS, MON, CHG, NET, PES, SEA, END, DCH, CRY, AST, CFG, TPM
Client Data
Processed locally. No client data transmitted externally.
Section 7 — Audit Trail

Review History & Validation

Data: assessment_metadata.run_id, assessment_metadata.duration_seconds
Run ID
PR_AA_01_01_20260706_181004
Duration
2h 42m (9,724s)
Date
2026-07-06
Output Schema
assessment_output_schema.json v1.0.0
Findings Taxonomy
findings_taxonomy.json v1.0.0
AssessorL1 (qwen3:32b) — Sections 1-4: Criteria, Testing, Conclusion, Gaps (per-RG classification)2026-07-06
KnowledgeCRI v2.2 Knowledge Pack — Sections 1, 5: Criteria, Exam Readiness (static)2026-07-06
EngineAssessment Engine v1.0.0 — Sections 6, 7: Methodology, Audit Trail (automatic)2026-07-06
ReviewerPending — Human review required before delivery
Appendix A — Management Guidance

Advisory Remediation Guidance

Data: Advisory — not part of L1 assessment artifact. Interpretive content for management consideration.

The following guidance is advisory and separate from the assessment findings in Section 4. Business impact, exam impact, recommendations, and remediation owners reflect professional interpretation and are provided for management planning purposes.

IDThemeBusiness ImpactExam ImpactRecommendationOwner
F-001Access Review OwnershipInappropriate access may persist — reviewers lack business contextExaminer will request owner-conducted reviewsAssign system owners; quarterly reviews with sign-offCISO
F-002Privilege Change MonitoringUnauthorized changes to critical systems may go undetectedExaminer will request continuous monitoring evidenceTiered monitoring; prioritize critical systemsSOC
F-003Alert Investigation ProcessCannot demonstrate alerts are investigated and resolvedExaminer will request investigation recordsDocumented investigation procedures with escalationSOC
F-004Device AuthorizationUnauthorized devices may access resources via non-domain channelsExaminer will note "individuals and devices" partially metNAC or certificate-based auth for non-domain endpointsInfra Eng
F-005Least Privilege JustificationAccess may exceed business need after role changesExaminer expects documented justification for grantsRequire business purpose on access tickets; review on role changeCISO
F-006Admin Password StandardsAdmin accounts with standard passwords more vulnerableExaminer will request enhanced admin requirementsDocument and enforce elevated admin password requirementsGRC
F-007Hardening DocumentationUnchanged defaults are a known attack vectorExaminer will request hardening docs and evidenceLink checklists to hardening guides; automate verificationGRC
F-008Access AutomationManual processing introduces delay, error, privilege creepExaminer will note automation requirement unmetIntegrate ServiceNow with AD provisioningIAM
F-009RBAC FormalizationInformal roles hard to verify during access reviewsExaminer will request role-based group descriptionsFormal role definitions with permission mappingsGRC
F-010Password Reuse PolicyLow risk — technical enforcement in place; policy gapExaminer may note policy vs. technical enforcement gapAdd explicit reuse prohibition to policyGRC
F-011Termination Timeliness2-3 day window of unauthorized access on standard termsExaminer will note "immediately" vs. 2-3 daysImmediate-disable for all terminations; extend to all systemsIAM
Appendix B — Control Library Reference

Source Control Library

Heritage Community Bank — Risk & Control Library v1.0

568 controls across 32 domains (SCF-aligned). All control IDs referenced in this assessment link directly to the source control library for full description verification.

Review procedure: Click any control ID in Sections 2–3 to open the control library, verify the full control description, then use the browser back button to return to this report.

Legal Disclaimer

AI-Assisted Assessment. This workpaper was produced using an AI-assisted coverage assessment methodology. All verdicts, findings, and classifications were generated by a local large language model operating under deterministic prompt instructions and a structured findings taxonomy. AI-generated output requires human review and professional judgment before use in any regulatory, compliance, or audit context.

Not a Substitute for Professional Judgment. This assessment does not constitute an audit opinion, attestation, or assurance engagement. Coverage ratings reflect the assessor’s analysis of control descriptions against CRI v2.2 Response Guidance requirements. They do not represent an opinion on the operating effectiveness of controls, the adequacy of the institution’s overall control environment, or compliance with any law, regulation, or standard.

Data Privacy. All client data was processed locally using on-premises inference. No client control descriptions, evidence, or institutional information was transmitted to any external service, cloud API, or third-party system during the production of this workpaper.

Synthetic Demonstration. Heritage Community Bank is a fictional institution created for research and portfolio purposes. All institutions, regulatory findings, control descriptions, data, and deliverables shown in this workpaper are simulated. No real client data appears in this document.

Framework Reference. CRI v2.2 is published by the Conference of State Bank Supervisors (CSBS). References to CRI diagnostic statements and response guidance are used for assessment purposes under fair use. This workpaper is not endorsed by, affiliated with, or certified by CSBS.