research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Evidence checklist for APRA CPS 234 assessments
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/evidence-checklistContext preview
What this command does when you run it.
Evidence checklist for APRA CPS 234 assessments
description: Evidence checklist for APRA CPS 234 assessments
Baseline evidence checklist for an APRA CPS 234 assessment. The SCF crosswalk maps 52 SCF controls to the 38 CPS 234 controls; this command enumerates what evidence tends to be expected for each SCF family in scope.
/au-apra-cps-234:evidence-checklist [--family=<SCF_family_code>]
such as `IAC`, `CRY`, `AST`, or `BCD`. Defaults to all families mapped for this framework.
Markdown checklist grouped by SCF family with:
Collect CPS 234 evidence around information assets and operating control effectiveness:
senior management reporting, risk appetite, risk acceptance records, and control ownership evidence.
ratings, data flows, business services supported, third-party dependencies, and hosting locations.
security standards, architecture controls, awareness, staffing, tooling, and capability reviews.
vulnerability management, change management, backup and recovery, endpoint and network controls, and secure configuration evidence.
plans, penetration tests, control self-assessments, independent assurance, failed-test remediation, and retest results.
control test results, service provider risk assessments, cloud evidence, and monitoring of outsourced control operation.
escalation records, APRA notification analysis, post-incident reviews, and corrective action tracking.
plans, risk acceptance, APRA notification analysis, and board reporting.
Prefer structured exports from identity, ticketing, cloud, vulnerability management, SIEM, GRC, and vendor-risk systems over screenshots. Where evidence is narrative, capture the owner, approval date, asset scope, materiality assessment, and link to the underlying operating record.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.