research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Determine appropriate Essential 8 maturity level target
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/maturity-levelContext preview
What this command does when you run it.
Determine appropriate Essential 8 maturity level target
description: Determine appropriate Essential 8 maturity level target
Helps determine the appropriate Essential 8 maturity level target based on organizational risk profile and requirements.
**Target Organizations**:
**Threat Protection**:
**Characteristics**:
**Implementation Time**: 3-6 months typically
---
**Target Organizations**:
**Threat Protection**:
**Characteristics**:
**Implementation Time**: 6-12 months typically
---
**Target Organizations**:
**Threat Protection**:
**Characteristics**:
**Implementation Time**: 12-24 months typically
---
**Non-corporate Commonwealth Entities (NCEs)**:
**Corporate Commonwealth Entities (CCEs)**:
**State/Territory Government**:
**Critical Infrastructure**:
---
---
*Costs vary significantly by organization size and current maturity*
---
**Recommended Path**: ML1 → ML2 → ML3
1. **Phase 1: Achieve ML1** (Months 1-6)
2. **Phase 2: Progress to ML2** (Months 7-12)
3. **Phase 3: Advance to ML3** (Months 13-24)
**Benefits**:
---
Do you handle classified information or operate critical infrastructure? ├─ YES → Target ML3 └─ NO → Continue Are you a Commonwealth government entity? ├─ YES → ML3 (NCE) or ML2+ (CCE) └─ NO → Continue Are you a high-profile target or handle sensitive data at scale? ├─ YES → Target ML3 └─ NO → Continue Do you have regulatory compliance requirements or business-critical systems? ├─ YES → Target ML2 └─ NO → Continue Are you a small business or just starting cyber security journey? ├─ YES → Start with ML1, plan progression └─ NO → Target ML2 as baseline
---
# Determine level for government agency /essential8:maturity-level government high # Assess appropriate level for small business /essential8:maturity-level small-business low # Critical infrastructure guidance /essential8:maturity-level critical-infrastructure high # General business assessment /essential8:maturity-level business medium
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.