research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Deep dive on specific PCI DSS requirement
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/requirementContext preview
What this command does when you run it.
Deep dive on specific PCI DSS requirement
description: Deep dive on specific PCI DSS requirement
Provides detailed guidance on specific PCI DSS v4.0.1 requirements.
| Req | Title | Key Focus | |-----|-------|-----------| | 1 | Network Security Controls | Firewalls, network segmentation | | 2 | Secure Configurations | Hardening, defaults, inventory | | 3 | Protect Stored Data | Encryption, retention, PAN masking | | 4 | Cryptography in Transit | TLS, secure transmission | | 5 | Malware Protection | Anti-malware, updates | | 6 | Secure Development | SDLC, vulnerabilities, patches | | 7 | Access Restriction | Need-to-know, least privilege | | 8 | User Authentication | Passwords, MFA, accounts | | 9 | Physical Security | Facility access, media | | 10 | Logging and Monitoring | Audit trails, log review | | 11 | Security Testing | Scans, pen tests, IDS | | 12 | Security Policies | Policies, awareness, incidents |
Requirements follow pattern: `X.Y.Z`
/pci-dss:requirement 3 /pci-dss:requirement 8.4.2 testing /pci-dss:requirement 6.4.3 evidence
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.