research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Portfolio view across every framework in scope, sized for CISO 1:1s and program reviews
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/program-healthContext preview
What this command does when you run it.
Portfolio view across every framework in scope, sized for CISO 1:1s and program reviews
description: Portfolio view across every framework in scope, sized for CISO 1:1s and program reviews allowed-tools: Read, Glob, Grep, Write, Bash
Draft a portfolio snapshot of the whole GRC program. Built for CISO 1:1s and program reviews, not for audit evidence.
Invoke `context-bootstrap`. Program-health needs:
Without at least two frameworks, this command has no portfolio to report on. Suggest `/grc-engineer:frameworks` to discover what's available and install a second framework before proceeding.
Apply `program-portfolio-composition` for cross-framework synthesis. Apply `so-what-translation` for the commentary column.
Structure:
# Program Health - <as-of> ## Portfolio Snapshot | Framework | Coverage | 30-day trend | Top gap | Owner | |---|---|---|---|---| | <framework> | <%> | <+/- pp> | <1-line gap> | <name or team> | ## Cross-Framework Patterns <Controls that fail in multiple frameworks get called out here. SCF crosswalk shows the leverage points where one fix unblocks many.> ## Program Momentum <What got better this period. What got worse. What's static and shouldn't be.> ## Watch List <Frameworks or controls at risk of slipping without intervention.> ## Appendix Per-framework full reports: <paths> SCF crosswalk run: <run_id>
Write to `./grc-reports/program-health-<as-of>.md`. Offer:
# Today, all frameworks with runs /report:program-health # Specific date, specific frameworks /report:program-health 2026-04-18 soc2,fedramp-moderate,iso27001
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.