research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Deep dive guidance on CMMC v2.0 domains and practices
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/domain-guidanceContext preview
What this command does when you run it.
Deep dive guidance on CMMC v2.0 domains and practices
description: Deep dive guidance on CMMC v2.0 domains and practices
Provides detailed implementation guidance for CMMC v2.0 domains and their associated practices.
Controls who can access systems and data based on approved authorizations.
**Key practices**:
Manages organizational assets commensurate with their importance.
**Key practices**:
Maintains audit logs to detect and respond to cyber incidents.
**Key practices**:
Ensures personnel are trained in cybersecurity.
**Key practices**:
Establishes and maintains baseline configurations.
**Key practices**:
Verifies identities of users and devices.
**Key practices**:
Detects and responds to cybersecurity incidents.
**Key practices**:
Manages system maintenance and repair.
**Key practices**:
Protects digital and non-digital media.
**Key practices**:
Screens and monitors personnel.
**Key practices**:
Limits physical access to systems and facilities.
**Key practices**:
Executes recovery plans during disruptions.
**Key practices**:
Manages organizational risk to operations and assets.
**Key practices**:
Develops and implements activities to assess security effectiveness.
**Key practices**:
Detects and analyzes indicators of compromise.
**Key practices**:
Monitors and controls communications at system boundaries.
**Key practices**:
Identifies and manages information system flaws.
**Key practices**:
1. **Domain Overview**: Purpose and objectives 2. **Practice List**: All practices in domain by level 3. **Implementation Guidance**: How to satisfy each practice 4. **Common Gaps**: Typical deficiencies found 5. **Evidence Requirements**: What C3PAOs look for 6. **NIST Mapping**: Correlation to NIST 800-171
# Get guidance for Access Control domain /cmmc:domain-guidance AC # See Level 2 practices for Incident Response /cmmc:domain-guidance IR 2 # Review Audit and Accountability requirements /cmmc:domain-guidance AU
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.