research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Verify specific CMMC practice implementation
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/practice-checkContext preview
What this command does when you run it.
Verify specific CMMC practice implementation
description: Verify specific CMMC practice implementation
Validates implementation of specific CMMC v2.0 practices and provides evidence guidance.
**Structure**: `[DOMAIN].[LEVEL]-[NIST-ID]`
**Examples**:
Validates that the practice is properly implemented:
Reviews evidence artifacts for C3PAO assessment:
Identifies deficiencies in current state:
1. **Practice Definition**: What the practice requires 2. **Implementation Guidance**: How to satisfy the practice 3. **Evidence Examples**: What artifacts to provide
4. **Common Deficiencies**: What C3PAOs flag 5. **Pass/Fail Criteria**: Assessment thresholds 6. **Remediation Steps**: If gaps identified
# Check MFA implementation for Level 2 /cmmc:practice-check IA.L2-3.5.7 implementation # Review evidence for access control /cmmc:practice-check AC.L1-3.1.1 evidence # Gap analysis for incident response /cmmc:practice-check IR.L2-3.6.1 gaps # Verify audit logging implementation /cmmc:practice-check AU.L2-3.3.1
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.