All authors

Claude Skills by GRCEngClub
github.com/GRCEngClub101 skills0 installs54 views
- Aws Inspector ExpertExpertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.Votes: 0GitHub stars: 391
- Azure Inspector ExpertExpertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.Votes: 0GitHub stars: 391
- Crowdstrike Inspector ExpertInterpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.Votes: 0GitHub stars: 391
- Datadog Inspector ExpertInterpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.Votes: 0GitHub stars: 391
- Drata Inspector ExpertInterpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.Votes: 0GitHub stars: 391
- Gcp Inspector ExpertExpertise in evaluating GCP projects for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gcloud output.Votes: 0GitHub stars: 391
- Github Inspector ExpertExpertise in evaluating GitHub repositories for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gh CLI output.Votes: 0GitHub stars: 391
- Okta Inspector ExpertExpertise in evaluating Okta configurations for compliance — policies, MFA, session management, admin accounts, lifecycle. Maps to FedRAMP/NIST/SOC2/PCI identity controls.Votes: 0GitHub stars: 391
- Poam Automation ExpertExpertise in FedRAMP POA&M lifecycle management, FedRAMP 20x VDR generation, and vulnerability classification using CISA KEV, EPSS, N-ratings, LEV/IRV, and NIST 800-53 control mappings.Votes: 0GitHub stars: 391
- Slack Inspector ExpertInterpret slack-inspector findings, explain Slack API coverage limits, and turn Slack workspace posture results into control evidence or remediation.Votes: 0GitHub stars: 391
- Snowflake Inspector ExpertInterpret Snowflake account usage findings for MFA, network policies, masking/row access policies, session timeout, and retention.Votes: 0GitHub stars: 391
- Splunk Inspector ExpertInterpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.Votes: 0GitHub stars: 391
- Tenable Inspector ExpertInterpret Tenable vulnerability-management findings for scan coverage, credentialed scans, vulnerability age, and scan access visibility.Votes: 0GitHub stars: 391
- Testssl Inspector ExpertInterpret testssl-inspector normalized findings, recommend remediations, and tie evidence back to SCF anchor controls plus SOC 2 / NIST 800-53 r5 / PCI DSS 4.0.1 / ISO 27002:2022 equivalents derived from SCF crosswalks.Votes: 0GitHub stars: 391
- Wiz Inspector ExpertUse `wiz-inspector` when Wiz CNAPP is the source of cloud posture, vulnerability, toxic-combination, or inventory evidence. Inputs: - `WIZ_CLIENT_ID` - `WIZ_CLIENT_SECRET` - `WIZ_API_URL`, for example `https://api.<region>.app.wiz.io/graphql` - optional `WIZ_AUTH_URL`, defaulting to `https://auth.app.wiz.io/oauth/token` - optional `WIZ_PROJECT_ID` to constrain collection to a Wiz project - required read-only scopes: `read:projects`, `read:issues`, `read:vulnerabilities`, `read:inventory` Run ...Votes: 0GitHub stars: 391
- Fedramp Ssp ExpertExpertise on FedRAMP SSP authoring — what the DOCX templates contain, what OSCAL 1.2.0 SSP looks like for FedRAMP, how this plugin fits alongside Compliance Trestle and oscal-cli.Votes: 0GitHub stars: 391
- Au Apra Cps 234 ExpertAPRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.Votes: 0GitHub stars: 391
- Ch Fadp ExpertSwiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.Votes: 0GitHub stars: 391
- Cis ExpertCIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.Votes: 0GitHub stars: 391
- Cmmc Assessment ObjectivesVerbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.Votes: 0GitHub stars: 391
- Cmmc ExpertCMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.Votes: 0GitHub stars: 391
- Ccm ExpertCSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST.Votes: 0GitHub stars: 391
- Cyber Essentials Plus ExpertUK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Five core controls: Firewalls, Secure Configuration, User Access Control (MFA mandatory for all cloud services), Malware Protection, and Patch Management.Votes: 0GitHub stars: 391
- Dora ExpertDORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.Votes: 0GitHub stars: 391
- Essential8 ExpertEssential 8 expert for Australian cyber security. Deep knowledge of ACSC Essential Eight mitigation strategies including 8 strategies, 3 maturity levels, implementation guidance, and Australian government requirements.Votes: 0GitHub stars: 391
- Eu Nis2 ExpertEU NIS2 Directive (Directive (EU) 2022/2555) expert. Reference-depth knowledge of essential vs important entity classification, Article 20 governance, the Article 21 ten cybersecurity risk-management measures, the Article 23 24h/72h/1mo incident-reporting timeline, and supervision/enforcement under Articles 32-34. SCF-backed gap assessment via the crosswalk.Votes: 0GitHub stars: 391
- Fedramp 20x ExpertFedRAMP 20X modernization expert. Provides guidance on Key Security Indicators (KSIs), continuous monitoring automation, machine-readable policies, and the new automated authorization approach. Auto-syncs with official FedRAMP docs.Votes: 0GitHub stars: 391
- Fedramp Rev5 ExpertFedRAMP Rev 5 authorization expert. Provides guidance on traditional authorization paths, SSP/SAP/SAR/POA&M documentation, NIST 800-53 Rev 5 control implementation, and 3PAO assessment preparation.Votes: 0GitHub stars: 391
- Gdpr ExpertGDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.Votes: 0GitHub stars: 391
- Glba ExpertGLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.Votes: 0GitHub stars: 391
- Hitrust ExpertHITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.Votes: 0GitHub stars: 391
- Ind Dpdpa ExpertIndia DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement.Votes: 0GitHub stars: 391
- Irap ExpertAustralian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.Votes: 0GitHub stars: 391
- Ismap ExpertJapanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.Votes: 0GitHub stars: 391
- Iso ExpertISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.Votes: 0GitHub stars: 391
- Jp Appi ExpertJapan APPI expert for the Act on the Protection of Personal Information. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Japanese personal data.Votes: 0GitHub stars: 391
- Nist ExpertNIST 800-53 control framework expert. Provides guidance on control families, baseline selection, tailoring, and federal compliance requirements including FedRAMP alignment.Votes: 0GitHub stars: 391
- Nist Csf 20 ExpertNIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF as a board-readable cybersecurity outcomes language. Backed by the SCF crosswalk for control-by-control mechanics.Votes: 0GitHub stars: 391
- Nydfs ExpertNYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management.Votes: 0GitHub stars: 391
- Pbmm ExpertCanadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements.Votes: 0GitHub stars: 391
- Pci Dss ExpertPCI DSS v4.0.1 compliance expert. Provides guidance on payment card industry security, ROC completion, SAQ selection, requirement interpretation, and the new March 2025 mandatory requirements.Votes: 0GitHub stars: 391
- Sg Mas Trm ExpertSingapore MAS Technology Risk Management Guidelines expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Singapore-regulated financial institutions.Votes: 0GitHub stars: 391
- Singapore Pdpa ExpertSingapore - Personal Data Protection Ac (PDPA) (2012) expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Level up to Full by adding framework-specific workflow commands.Votes: 0GitHub stars: 391
- Soc2 ExpertSOC 2 Trust Service Criteria expert. Provides guidance on Type I/II audits, control mapping, evidence requirements, and audit preparation for all Trust Service Categories.Votes: 0GitHub stars: 391
- Stateramp ExpertStateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.Votes: 0GitHub stars: 391
- Us Ccpa ExpertCalifornia Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider / Contractor / Third Party distinctions, the Universal Opt-Out Mechanism (Global Privacy Control), CPPA risk assessments and cybersecurity audits, and dual enforcement by the California Privacy Protection Agency and the Califo...Votes: 0GitHub stars: 391
- Us Export ExpertUS Export Controls expert covering ITAR and EAR. Provides comprehensive guidance on defense articles (USML), dual-use commercial items (CCL), jurisdiction determination, FIPS encryption, denied party screening, and cloud compliance strategies.Votes: 0GitHub stars: 391
- Us Finra ExpertFINRA Broker-Dealer Cybersecurity Guidance expert. Stub-depth framework plugin that routes to the SCF crosswalk. Level up by adding framework-specific context, assessment workflow, and evidence patterns.Votes: 0GitHub stars: 391
- Us Hipaa SecurityHIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.Votes: 0GitHub stars: 391
- Us Nerc Cip ExpertNERC Critical Infrastructure Protection expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for BES Cyber Systems.Votes: 0GitHub stars: 391