Skip to content
Security
Command

/evidence-checklist

Evidence checklist for APRA CPS 234 assessments

From plugin
trust-center
367139 skills139 commands1 MCP
Install
$ npx -y skills add GRCEngClub/claude-grc-engineering --agent claude-code

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/evidence-checklist

Context preview

What this command does when you run it.

Evidence checklist for APRA CPS 234 assessments

Command definition

evidence-checklist.md
description: Evidence checklist for APRA CPS 234 assessments

APRA CPS 234 Evidence Checklist

Baseline evidence checklist for an APRA CPS 234 assessment. The SCF crosswalk maps 52 SCF controls to the 38 CPS 234 controls; this command enumerates what evidence tends to be expected for each SCF family in scope.

Usage

/au-apra-cps-234:evidence-checklist [--family=<SCF_family_code>]

Arguments

  • `--family=<SCF_family_code>` (optional) - restrict to a single SCF family

such as `IAC`, `CRY`, `AST`, or `BCD`. Defaults to all families mapped for this framework.

Output

Markdown checklist grouped by SCF family with:

  • SCF control ID to framework-native control ID(s) from the crosswalk.
  • Evidence types typically expected.
  • Which connector plugins can collect each type automatically.
  • Which items require manual upload or narrative.

Framework-specific evidence

Collect CPS 234 evidence around information assets and operating control effectiveness:

  • **Governance and accountability**: information security policy, board and

senior management reporting, risk appetite, risk acceptance records, and control ownership evidence.

  • **Information asset inventory**: asset owners, sensitivity and criticality

ratings, data flows, business services supported, third-party dependencies, and hosting locations.

  • **Information security capability**: threat and vulnerability monitoring,

security standards, architecture controls, awareness, staffing, tooling, and capability reviews.

  • **Control implementation**: access controls, logging, encryption,

vulnerability management, change management, backup and recovery, endpoint and network controls, and secure configuration evidence.

  • **Control testing**: testing strategy, testing frequency rationale, test

plans, penetration tests, control self-assessments, independent assurance, failed-test remediation, and retest results.

  • **Third-party and related-party reliance**: contracts, assurance reports,

control test results, service provider risk assessments, cloud evidence, and monitoring of outsourced control operation.

  • **Incident management**: incident response plan, materiality criteria,

escalation records, APRA notification analysis, post-incident reviews, and corrective action tracking.

  • **Weakness management**: material control weakness register, remediation

plans, risk acceptance, APRA notification analysis, and board reporting.

Prefer structured exports from identity, ticketing, cloud, vulnerability management, SIEM, GRC, and vendor-risk systems over screenshots. Where evidence is narrative, capture the owner, approval date, asset scope, materiality assessment, and link to the underlying operating record.

Read more
Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked
Stats
367
Stars
0
Views
82
Forks
Active
Maintenance
JavaScript
Language
1d ago
Last commit
7mo ago
Created

Repo: GRCEngClub/claude-grc-engineering