research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Determine appropriate CIS Controls Implementation Group (IG1/IG2/IG3)
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/ig-selectContext preview
What this command does when you run it.
Determine appropriate CIS Controls Implementation Group (IG1/IG2/IG3)
description: Determine appropriate CIS Controls Implementation Group (IG1/IG2/IG3)
> _CIS Controls v8 content used under CC BY-SA 4.0 from the Center for Internet Security. This command's CIS-derived content is CC BY-SA 4.0. See [LICENSE-CIS.md](../LICENSE-CIS.md)._
Helps determine the appropriate Implementation Group (IG1, IG2, or IG3) for your organization based on size, resources, risk profile, and adversary sophistication.
**Recommended For**:
**Resource Requirements**:
**Threat Profile**:
**Example Organizations**:
**Recommended For**:
**Resource Requirements**:
**Threat Profile**:
**Example Organizations**:
**Recommended For**:
**Resource Requirements**:
**Threat Profile**:
**Example Organizations**:
| Factor | IG1 | IG2 | IG3 | |--------|-----|-----|-----| | **Employees** | <100 | 100-1,000 | 1,000+ | | **IT Staff** | 1-2 generalists | 3-10 with security focus | 10+ dedicated security | | **Annual Revenue** | <$10M | $10M-$1B | $1B+ | | **Data Sensitivity** | Basic business data | Customer PII, PHI | Trade secrets, critical infrastructure | | **Regulatory** | Minimal | Moderate (HIPAA, SOX) | High (CMMC, NERC CIP) | | **Threat Level** | Opportunistic | Targeted | Advanced/persistent | | **Security Budget** | <$50K | $100K-$500K | $1M+ | | **Downtime Tolerance** | Hours-days | Hours | Minutes |
Organizations should consider a phased approach:
**Phase 1**: Implement IG1 (Foundation)
**Phase 2**: Advance to IG2 (If needed)
**Phase 3**: Advance to IG3 (If needed)
**High-Risk Factors** (may warrant higher IG):
**Offsetting Factors** (may allow lower IG):
**Healthcare**:
**Financial Services**:
**Manufacturing**:
**Technology**:
1. **Recommended IG Level**: IG1, IG2, or IG3 2. **Justification**: Factors driving the recommendation 3. **Resource Requirements**: Estimated staff, budget, tools needed 4. **Safeguard Count**: How many controls to implement (56, 128, or 153) 5. **Implementation Timeline**: Realistic timeframe to reach target IG 6. **Cost-Benefit Analysis**: Security value vs implementation cost 7. **Progressive Path**: If starting lower, roadmap to advance IG levels
# Determine IG for small healthcare practice /cis:ig-select small moderate # Assess IG needs for large financial institution /cis:ig-select large
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.