research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Deep dive guidance on DORA's 5 pillars and implementation requirements
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/pillar-guidanceContext preview
What this command does when you run it.
Deep dive guidance on DORA's 5 pillars and implementation requirements
description: Deep dive guidance on DORA's 5 pillars and implementation requirements
Provides detailed implementation guidance for each of DORA's 5 pillars.
Establishes comprehensive framework for managing ICT risks across financial entities.
**Legal Basis**: Articles 5-16 of DORA **Applicability**: All financial entities **Key Principle**: Proportionality to size, risk profile, and complexity
**Must Include**:
**Implementation**:
**Board Responsibilities**:
**Management Body**:
**Requirements**:
**Deliverables**:
**Requirements**:
**Key Controls**:
**Requirements**:
**Capabilities**:
**Business Continuity**:
**Incident Response**:
**Requirements**:
**Requirements**:
**Requirements**:
---
Comprehensive framework for detecting, managing, classifying, and reporting ICT-related incidents.
**Legal Basis**: Articles 17-23 **Key Innovation**: Mandatory reporting of major incidents to authorities **Timeline**: Strict reporting deadlines
**Requirements**:
**Process Steps**:
1. Detection and logging 2. Initial assessment and classification 3. Containment 4. Investigation and analysis 5. Remediation and recovery 6. Post-incident review 7. Reporting (if major incident)
**Major Incident Criteria**:
**Classification Factors**:
**Major Incident Reporting Timeline**:
| Timeline | Report Type | Content | |----------|-------------|---------| | **4 hours** | Initial notification | Incident awareness, preliminary assessment | | **72 hours** | Intermediate report | Classification, impact assessment, mitigation actions | | **1 month** | Final report | Root cause, remediation, lessons learned |
**Additional Reports**:
**R
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.