research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
New mandatory requirements effective March 31, 2025
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/march-2025Context preview
What this command does when you run it.
New mandatory requirements effective March 31, 2025
description: New mandatory requirements effective March 31, 2025
Requirements that became mandatory on March 31, 2025 (previously "future-dated").
| Req | Description | |-----|-------------| | 3.3.3 | SAD stored prior to authorization is encrypted | | 3.4.2 | Technical controls prevent copy/relocation of PAN | | 3.5.1.1 | Keyed cryptographic hashes if used for PAN storage | | 3.5.1.2 | Disk-level encryption only for removable media |
| Req | Description | |-----|-------------| | 5.3.3 | Anti-malware for removable media | | 5.4.1 | Mechanisms detect phishing attacks |
| Req | Description | |-----|-------------| | 6.4.2 | WAF for public-facing web apps | | 6.4.3 | Payment page scripts inventoried and managed |
| Req | Description | |-----|-------------| | 7.2.5 | Application/system account access reviewed | | 7.2.5.1 | Access reviews include all access types | | 8.4.2 | MFA for all access into CDE | | 8.5.1 | MFA systems secured against replay | | 8.6.1 | Interactive login for app/system accounts managed | | 8.6.2 | Passwords/passphrases for interactive use not hardcoded | | 8.6.3 | Passwords for app/system accounts meet complexity |
| Req | Description | |-----|-------------| | 10.4.1.1 | Automated audit log review mechanisms | | 10.4.2.1 | Targeted risk analysis for log review frequency | | 10.7.2 | Failures of security controls detected and reported | | 10.7.3 | Failures responded to promptly |
| Req | Description | |-----|-------------| | 11.3.1.1 | Internal vulnerability scans via authenticated scanning | | 11.3.1.2 | Internal scans performed after significant changes | | 11.4.7 | Multi-tenant service providers support pen testing | | 11.5.1.1 | IDS/IPS detect covert malware channels | | 11.6.1 | Change/tamper detection on payment pages |
| Req | Description | |-----|-------------| | 12.3.1 | Targeted risk analysis for each flexible requirement | | 12.3.2 | Targeted risk analyses documented and reviewed |
1. **Payment page security** (6.4.3, 11.6.1) - Script inventory, change detection 2. **MFA everywhere** (8.4.2, 8.5.1) - CDE access requires MFA 3. **Automated log review** (10.4.1.1) - Manual review no longer sufficient 4. **Authenticated scanning** (11.3.1.1) - Better vulnerability detection
/pci-dss:march-2025 /pci-dss:march-2025 8 /pci-dss:march-2025 "payment page"
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.