research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
List applicable CIS Controls v8 safeguards by Implementation Group
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/safeguard-listContext preview
What this command does when you run it.
List applicable CIS Controls v8 safeguards by Implementation Group
description: List applicable CIS Controls v8 safeguards by Implementation Group
> _CIS Controls v8 content used under CC BY-SA 4.0 from the Center for Internet Security. This command's CIS-derived content is CC BY-SA 4.0. See [LICENSE-CIS.md](../LICENSE-CIS.md)._
Provides comprehensive listing of CIS Controls v8 safeguards organized by Implementation Group (IG1, IG2, IG3).
| Implementation Group | Total Safeguards | Incremental | Cumulative | |---------------------|------------------|-------------|------------| | **IG1** | 56 | 56 new | 56 total | | **IG2** | 72 additional | 72 new | 128 total | | **IG3** | 25 additional | 25 new | 153 total |
These 56 safeguards represent the minimum baseline for cybersecurity. All organizations should implement IG1 regardless of size or industry.
**Controls Introduced at IG1**:
**Key IG1 Safeguards** (High Priority):
**1.1** - Establish and Maintain Detailed Enterprise Asset Inventory
**2.1** - Establish and Maintain Software Inventory
**3.1** - Establish and Maintain Data Management Process
**4.1** - Establish and Maintain Secure Configuration Process
**5.1** - Establish and Maintain Inventory of Accounts
**5.3** - Disable Dormant Accounts
**5.4** - Restrict Administrator Privileges to Dedicated Accounts
**6.1** - Establish Access Granting Process
**6.2** - Establish Access Revoking Process
**7.1** - Establish and Maintain Vulnerability Management Process
**7.3** - Perform Automated Operating System Patch Management
**8.2** - Collect Audit Logs
**9.2** - Use DNS Filtering Services
**10.1** - Deploy and Maintain Anti-Malware Software
**11.2** - Perform Automated Backups
**11.3** - Protect Recovery Data
**14.1** - Establish and Maintain Security Awareness Program
**17.1** - Designate Personnel to Manage Incident Handling
IG2 adds 72 safeguards for organizations with dedicated IT staff and moderate risk profiles.
**New Controls at IG2**:
**Expanded Controls at IG2**:
**Key IG2 Safeguards** (High Value):
**3.6** - Encrypt Data on End-User Devices
**3.10** - Encrypt Sensitive Data in Transit
**3.11** - Encrypt Sensitive Data at Rest
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.