research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Quarterly audit-committee or board-ready narrative from findings, incidents, and residual risk
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/board-briefContext preview
What this command does when you run it.
Quarterly audit-committee or board-ready narrative from findings, incidents, and residual risk
description: Quarterly audit-committee or board-ready narrative from findings, incidents, and residual risk allowed-tools: Read, Glob, Grep, Write, Bash
Draft a quarterly board or audit-committee brief. This is a real board brief, not a bulleted slide outline. It uses prose where narrative carries meaning and tables where structure carries meaning. Every section is concise. Length budget: 2 pages for audit committee, 1 page for full board. Business impact first, control text last.
Invoke `context-bootstrap`. For a meaningful quarterly brief, check:
Partial context is acceptable here if the user confirms. A quarterly brief with limited data is a real artifact - just name the gaps.
Apply `so-what-translation` + `exec-narrative-patterns` + `program-portfolio-composition` for cross-framework synthesis.
Concision rules:
Structure:
# <Audience> Brief - <Quarter> ## Headline <One sentence. The most important thing the committee needs to walk away with.> ## Program Posture <Short table: framework, coverage %, delta from last quarter, 1-line commentary.> ## Material Events <Prose. 1-3 short paragraphs. Incidents, audits, regulatory changes, with business impact. No blow-by-blow.> ## Residual Risk <Short table: top 5 risks, trend vs last quarter, treatment status, owner, expected close.> ## Program Initiatives <Prose. 2-4 short paragraphs. Automation programs, org changes, tooling. What the CISO wants the committee to know and why it matters.> ## Asks <Bulleted. Each ask: the decision, the context in one line, the deadline, the owner ready to execute.> ## Appendix <Findings run IDs, gap reports, incident postmortems. Linked, not inlined.>
Write to `./grc-reports/board-brief-<quarter>-<audience>.md`. Offer:
# Current quarter, audit committee /report:board-brief # Specific quarter, full board /report:board-brief 2026-Q1 board # Risk committee version /report:board-brief 2026-Q1 risk-committee
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.