research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Determine appropriate HITRUST assessment scope (i1 vs r2)
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/scope-selectContext preview
What this command does when you run it.
Determine appropriate HITRUST assessment scope (i1 vs r2)
description: Determine appropriate HITRUST assessment scope (i1 vs r2)
Helps determine whether to pursue i1, r2, or e1 HITRUST CSF assessment based on organizational needs and constraints.
**Choose i1 when**:
**i1 Validated vs Self-Assessment**:
**Choose r2 when**:
**r2 Requirements**:
**Choose e1 when**:
**Recommendation**: r2
**Recommendation**: r2
**Recommendation**: i1 validated or r2
**Recommendation**: i1 validated minimum, r2 preferred
**Recommendation**: i1 self-assessment or validated
| Assessment Type | Assessment Cost | Remediation Cost | Timeline | Validity | |-----------------|----------------|------------------|----------|----------| | **i1 Self** | $10K-$30K | $50K-$150K | 3-6 months | 1 year | | **i1 Validated** | $30K-$80K | $50K-$150K | 3-6 months | 1 year | | **r2** | $100K-$300K+ | $150K-$500K+ | 6-12 months | 2 years | | **e1** | $40K-$100K | Variable | 3-6 months | Extends to 2yr |
*Costs vary by scope, assessor, and readiness level*
1. **Recommended Assessment Type**: i1, r2, or e1 2. **Justification**: Why this type fits 3. **Timeline Projection**: Expected duration 4. **Budget Estimate**: Assessment + remediation 5. **Alternative Paths**: e.g., "Start with i1, plan for r2" 6. **Key Considerations**: Org-specific factors
# Vendor needing BAA compliance /hitrust:scope-select business-associate baa-requirement # Healthcare provider evaluating options /hitrust:scope-select provider hipaa # Determine best path for SaaS vendor /hitrust:scope-select vendor competitive
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.