research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
GLBA risk assessment methodology and guidance
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/risk-assessmentContext preview
What this command does when you run it.
GLBA risk assessment methodology and guidance
description: GLBA risk assessment methodology and guidance
Provides methodology and guidance for conducting risk assessments required under the GLBA Safeguards Rule.
**Authority**: 16 CFR Part 314.4(b) - Safeguards Rule Element #2 **Requirement**: "Identify and assess reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information"
**Purpose**:
**Frequency**:
**Objectives**:
**Scope Definition**:
1. **Information Assets**:
2. **Physical Locations**:
3. **Processes**:
4. **People**:
**Team Composition**:
**Step 1: Asset Identification**
**Information Assets**:
**Inventory Details**:
**Step 2: Threat Identification**
**External Threats**:
1. **Cyberattacks**:
2. **Environmental**:
3. **Third-Party**:
**Internal Threats**:
1. **Insider Threats**:
2. **Operational**:
3. **Technology**:
**Step 3: Vulnerability Analysis**
**Technical Vulnerabilities**:
**Administrative Vulnerabilities**:
**Physical Vulnerabilities**:
**Assessment Methods**:
**Step 4: Likelihood Assessment**
**Factors to Consider**:
**Likelihood Ratings**:
**Evidence Sources**:
**Step 5: Impact Analysis**
**Impact Categories**:
1. **Financial Impact**:
2. **Operational Impact**:
3. **Reputational Impact**:
4. **Compliance Impact**:
**Impact Ratings**:
**Step 6: Control Evaluation**
**Existing Controls Inventory**:
**Preventive Controls**:
**Detective Controls**:
**Corrective Controls**:
**Control Effectiveness**:
**Step 7: Risk Calculation**
**Risk Formula**: Risk = Likelihood × Impact
**
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.