research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
CCCS assessment process and certified cloud provider guidance
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/cccs-guidanceContext preview
What this command does when you run it.
CCCS assessment process and certified cloud provider guidance
description: CCCS assessment process and certified cloud provider guidance
Guidance on the Canadian Centre for Cyber Security (CCCS) cloud security assessment process and certified cloud service providers.
The CCCS assesses cloud service providers against the ITSP.50.103 Cloud Security Categorization framework.
**Assessment Tiers**:
**Organization Activities**:
**Required Documentation**:
**Submission to CCCS**:
**CCCS Review**:
**Assessment Activities**:
**Evidence Requirements**:
**For Identified Gaps**:
**POA&M**:
**CCCS Deliverables**:
**Validity Period**: 2 years (re-assessment required)
| Item | Estimated Cost (CAD) | Notes | |------|---------------------|-------| | **Pre-assessment consulting** | $50,000 - $150,000 | Gap analysis, SSP development | | **Third-party assessment** | $100,000 - $250,000 | CCCS Tier 2 assessment | | **Remediation** | $50,000 - $200,000 | Depends on gaps | | **CCCS assessment fee** | Varies | For Tier 3 assessments | | **Annual maintenance** | $25,000 - $75,000 | Continuous monitoring | | **Re-assessment (2 years)** | $75,000 - $150,000 | Reduced scope |
**Certification Status**: ✅ ITSM.50.100 Assessed
**Canadian Regions**:
**Services Assessed**:
**PBMM Features**:
**Contact**: AWS Canada Public Sector team
**Certification Status**: ✅ PBMM Assessed
**Canadian Regions**:
**Services Assessed**:
**PBMM Features**:
**Contact**: Microsoft Canada Public Sector
**Certification Status**: ⚠️ Assessment In Progress (verify current status)
**Canadian Regions**:
**Services**:
**PBMM Features**:
**Contact**: Google Cloud Canada team
**Note**: Verify current CCCS certification status before use
| Control ID | Control Name | CCCS Requirement | |-----------|-------------|-----------------| | **PBMM-DATA-1** | Canadian Data Residency | All data in CA regions only | | **PBMM-AC-1** | Access Control Policy | Documented, enforced | | **PBMM-AC-2** | Multi-Factor Authentication | Mandatory for all users | | **PBMM-AU-1** | Audit and Accountability | 2-year log retention | | **PBMM-SC-1** | Encryption at Rest | FIPS 140-2 Level 2+ | | **PBMM-SC-2** | Encryption in Transit | TLS 1.2+ with FIPS | | **PBMM-SC-3** | Network Segmentation | VPC/VNet isolation | | **PBMM-RA-1** | Vulnerability Management | 48-hour critical patching | | **PBMM-IR-1** | Incident Response | CCCS notification process | | **PBMM-CP-1** | Backup and Recovery | Canadian region backups |
**Monthly Reporting**:
**Quarterly Reviews**:
-
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.