research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
StateRAMP ATO package documentation guidance (SSP, SAP, SAR, POA&M)
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/documentationContext preview
What this command does when you run it.
StateRAMP ATO package documentation guidance (SSP, SAP, SAR, POA&M)
description: StateRAMP ATO package documentation guidance (SSP, SAP, SAR, POA&M)
Provides comprehensive guidance on creating StateRAMP Authorization to Operate (ATO) package documentation.
StateRAMP requires four core documents for authorization:
1. **SSP** - System Security Plan 2. **SAP** - Security Assessment Plan 3. **SAR** - Security Assessment Report 4. **POA&M** - Plan of Action & Milestones
**Plus supporting documents**:
Comprehensive description of the system, security controls, and implementation details.
**1. Information System Name/Title**
**2. System Categorization**
**3. Information System Owner**
**4. Authorizing Official**
**5. System Description**
**6. System Environment**
**7. Security Control Implementation**
**8. Attachments**
**Be Specific**:
**Show Evidence**:
**Use Control Inheritance**:
**Common SSP Mistakes**:
1. Generic copy/paste from templates 2. No evidence of actual implementation 3. Vague statements without technical details 4. Missing diagrams or outdated diagrams 5. Inconsistent control numbering 6. Not addressing all control enhancements
Defines how the 3PAO will assess security controls during the authorization process.
**1. Assessment Methodology**
**2. Scope**
**3. Assessment Procedures**
**4. Rules of Engagement**
**5. Penetration Testing**
**6. Deliverables**
Documents 3PAO findings from the security assessment.
**1. Executive Summary**
**2. Assessment Results by Control**
**3. Risk Exposure**
**4. Penetration Test Results**
**5. Vulnerability Scan Results**
**6. Attachments**
**Satisfied (Pass)**:
**Other Than Satisfied (Fail)**:
**Not Applicable (N/A)**:
**Low Risk**:
**Moderate Risk**:
**High Risk**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.