All authors
GRCEngClub avatar

Claude Skills by GRCEngClub

github.com/GRCEngClub
101 skillsA× 100C× 10 installs0 views
Aws Inspector ExpertA

Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.

securityrailsaws
0
391
Azure Inspector ExpertA

Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.

securitysqlazure
0
391
Crowdstrike Inspector ExpertA

Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.

developmentapi
0
391
Datadog Inspector ExpertA

Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.

developmentgoapi
0
391
Drata Inspector ExpertA

Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.

developmentgitapi
0
391
Gcp Inspector ExpertA

Expertise in evaluating GCP projects for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gcloud output.

securitygosql
0
391
Github Inspector ExpertA

Expertise in evaluating GitHub repositories for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret gh CLI output.

securitygoterraform
0
391
Okta Inspector ExpertA

Expertise in evaluating Okta configurations for compliance — policies, MFA, session management, admin accounts, lifecycle. Maps to FedRAMP/NIST/SOC2/PCI identity controls.

securitygoapi
0
391
Poam Automation ExpertA

Expertise in FedRAMP POA&M lifecycle management, FedRAMP 20x VDR generation, and vulnerability classification using CISA KEV, EPSS, N-ratings, LEV/IRV, and NIST 800-53 control mappings.

securitypythonapi
0
391
Slack Inspector ExpertA

Interpret slack-inspector findings, explain Slack API coverage limits, and turn Slack workspace posture results into control evidence or remediation.

developmentgoapi
0
391
Snowflake Inspector ExpertA

Interpret Snowflake account usage findings for MFA, network policies, masking/row access policies, session timeout, and retention.

security
0
391
Splunk Inspector ExpertA

Interpret splunk-inspector findings and translate Splunk retention, RBAC, audit, search ACL, and auth posture into compliance evidence and remediation.

securityapisecurity
0
391
Tenable Inspector ExpertA

Interpret Tenable vulnerability-management findings for scan coverage, credentialed scans, vulnerability age, and scan access visibility.

security
0
391
Testssl Inspector ExpertA

Interpret testssl-inspector normalized findings, recommend remediations, and tie evidence back to SCF anchor controls plus SOC 2 / NIST 800-53 r5 / PCI DSS 4.0.1 / ISO 27002:2022 equivalents derived from SCF crosswalks.

securityrustgo
0
391
Wiz Inspector ExpertA

Use `wiz-inspector` when Wiz CNAPP is the source of cloud posture, vulnerability, toxic-combination, or inventory evidence. Inputs: - `WIZ_CLIENT_ID` - `WIZ_CLIENT_SECRET` - `WIZ_API_URL`, for example `https://api.<region>.app.wiz.io/graphql` - optional `WIZ_AUTH_URL`, defaulting to `https://auth.app.wiz.io/oauth/token` - optional `WIZ_PROJECT_ID` to constrain collection to a Wiz project - required read-only scopes: `read:projects`, `read:issues`, `read:vulnerabilities`, `read:inventory` Run ...

securityapi
0
391
Fedramp Ssp ExpertA

Expertise on FedRAMP SSP authoring — what the DOCX templates contain, what OSCAL 1.2.0 SSP looks like for FedRAMP, how this plugin fits alongside Compliance Trestle and oscal-cli.

developmentgoaws
0
391
Au Apra Cps 234 ExpertA

APRA CPS 234 expert for Australian prudential information security. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance.

securitygotesting
0
391
Ch Fadp ExpertA

Swiss Federal Act on Data Protection (nFADP) expert. Deep knowledge of the revised 2023 Swiss FADP including voluntary DSO, risk-based breach notification, individual criminal enforcement, Swiss transfer mechanisms, and key divergences from GDPR.

securitygoaws
0
391
Cis ExpertA

CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.

securitypythonrust
0
391
Cmmc Assessment ObjectivesA

Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.

securitygoaws
0
391
Cmmc ExpertA

CMMC v2.0 expert for DoD contractors. Covers NIST 800-171 Rev 2 (14 families, 110 controls), SPRS scoring, POA&M rules, 32 CFR Part 170, DFARS clauses, scoping, ESP/CSP, C3PAO assessment lifecycle, and Rev 2 → Rev 3 transition.

securitygoaws
0
391
Ccm ExpertA

CSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST.

securityrustgo
0
391
Cyber Essentials Plus ExpertA

UK NCSC Cyber Essentials Plus (CE+) v3.3 Danzell expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Five core controls: Firewalls, Secure Configuration, User Access Control (MFA mandatory for all cloud services), Malware Protection, and Patch Management.

developmentgoaws
0
391
Dora ExpertA

DORA expert for EU financial entities. Deep knowledge of Digital Operational Resilience Act including 5 pillars, ICT risk management, incident reporting, resilience testing, third-party oversight, and information sharing for financial sector digital resilience.

securityrustgo
0
391
Essential8 ExpertA

Essential 8 expert for Australian cyber security. Deep knowledge of ACSC Essential Eight mitigation strategies including 8 strategies, 3 maturity levels, implementation guidance, and Australian government requirements.

securityjavascriptrust
0
391
Eu Nis2 ExpertA

EU NIS2 Directive (Directive (EU) 2022/2555) expert. Reference-depth knowledge of essential vs important entity classification, Article 20 governance, the Article 21 ten cybersecurity risk-management measures, the Article 23 24h/72h/1mo incident-reporting timeline, and supervision/enforcement under Articles 32-34. SCF-backed gap assessment via the crosswalk.

securityrustgo
0
391
Fedramp 20x ExpertA

FedRAMP 20X modernization expert. Provides guidance on Key Security Indicators (KSIs), continuous monitoring automation, machine-readable policies, and the new automated authorization approach. Auto-syncs with official FedRAMP docs.

securitygobash
0
391
Fedramp Rev5 ExpertA

FedRAMP Rev 5 authorization expert. Provides guidance on traditional authorization paths, SSP/SAP/SAR/POA&M documentation, NIST 800-53 Rev 5 control implementation, and 3PAO assessment preparation.

developmentgosecurity
0
391
Gdpr ExpertA

GDPR expert for EU privacy compliance. Deep knowledge of General Data Protection Regulation including 99 articles, 7 principles, 6 lawful bases, data subject rights, DPO requirements, DPIA, breach notification, cross-border transfers, and enforcement.

securitygoreact
0
391
Glba ExpertA

GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.

securitygoaws
0
391
Hitrust ExpertA

HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.

securityrustgo
0
391
Ind Dpdpa ExpertA

India DPDPA expert for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Covers Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary regime, Consent Manager, breach notification (72-hour), cross-border transfer regime, children's data, sectoral overlap with RBI / SEBI / IRDAI / TRAI / CERT-In / ABDM, and Data Protection Board enforcement.

securitygorails
0
391
Irap ExpertA

Australian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.

securitygojava
0
391
Ismap ExpertA

Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.

developmentgogit
0
391
Iso ExpertA

ISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.

securitysecurityperformance
0
391
Jp Appi ExpertA

Japan APPI expert for the Act on the Protection of Personal Information. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Japanese personal data.

developmentrustgo
0
391
Nist ExpertA

NIST 800-53 control framework expert. Provides guidance on control families, baseline selection, tailoring, and federal compliance requirements including FedRAMP alignment.

securitysecurity
0
391
Nist Csf 20 ExpertA

NIST Cybersecurity Framework v2.0 expert. Reference-depth knowledge of the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Profiles (Current vs Target), Tiers, Implementation Examples, and the practitioner workflow of using CSF as a board-readable cybersecurity outcomes language. Backed by the SCF crosswalk for control-by-control mechanics.

securitygoreact
0
391
Nydfs ExpertA

NYDFS 23 NYCRR 500 expert for financial services. Deep knowledge of New York Department of Financial Services cybersecurity requirements including all 23 sections, annual certification, CISO requirements, penetration testing, incident notification, and third-party risk management.

securityrustgo
0
391
Pbmm ExpertA

Canadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements.

securitygosql
0
391
Pci Dss ExpertA

PCI DSS v4.0.1 compliance expert. Provides guidance on payment card industry security, ROC completion, SAQ selection, requirement interpretation, and the new March 2025 mandatory requirements.

securityrailstesting
0
391
Sg Mas Trm ExpertA

Singapore MAS Technology Risk Management Guidelines expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for Singapore-regulated financial institutions.

securitygotesting
0
391
Singapore Pdpa ExpertA

Singapore - Personal Data Protection Ac (PDPA) (2012) expert. Reference-depth framework plugin with assessment, scope determination, and evidence checklist — backed by the SCF crosswalk. Level up to Full by adding framework-specific workflow commands.

developmentrustgit
0
391
Soc2 ExpertA

SOC 2 Trust Service Criteria expert. Provides guidance on Type I/II audits, control mapping, evidence requirements, and audit preparation for all Trust Service Categories.

securityrustgo
0
391
Stateramp ExpertA

StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.

securityrustgo
0
391
Us Ccpa ExpertA

California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) expert. Deep knowledge of California Civil Code §1798.100 et seq., CPRA-amended applicability thresholds, the seven consumer rights, Sensitive Personal Information handling, Service Provider / Contractor / Third Party distinctions, the Universal Opt-Out Mechanism (Global Privacy Control), CPPA risk assessments and cybersecurity audits, and dual enforcement by the California Privacy Protection Agency and the Califo...

developmentjavascriptgo
0
391
Us Export ExpertA

US Export Controls expert covering ITAR and EAR. Provides comprehensive guidance on defense articles (USML), dual-use commercial items (CCL), jurisdiction determination, FIPS encryption, denied party screening, and cloud compliance strategies.

developmentpythongo
0
391
Us Finra ExpertA

FINRA Broker-Dealer Cybersecurity Guidance expert. Stub-depth framework plugin that routes to the SCF crosswalk. Level up by adding framework-specific context, assessment workflow, and evidence patterns.

securitysecurity
0
391
Us Hipaa SecurityA

HIPAA Security Rule expert for US healthcare compliance. Deep knowledge of 45 CFR Part 164 Subpart C, Administrative/Physical/Technical Safeguards, Required vs Addressable specifications, Risk Analysis, Business Associate Agreements, and HHS OCR enforcement.

securitygoaws
0
391
Us Nerc Cip ExpertA

NERC Critical Infrastructure Protection expert. Reference-depth framework plugin with scope determination, evidence checklist, and SCF-backed assessment guidance for BES Cyber Systems.

securitygotesting
0
391