research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Verify specific Essential 8 strategy implementation
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/strategy-checkContext preview
What this command does when you run it.
Verify specific Essential 8 strategy implementation
description: Verify specific Essential 8 strategy implementation
Provides detailed implementation guidance and verification for a specific Essential 8 mitigation strategy.
Prevent execution of unapproved/malicious programs
Remediate security vulnerabilities in applications
Prevent malicious macros from executing
Reduce attack surface of internet-facing applications
Prevent privilege escalation and lateral movement
Remediate security vulnerabilities in operating systems
Prevent unauthorized access using stolen credentials
Recover data and system availability after incidents
---
**Requirements**:
**Implementation Steps**:
1. Choose application control solution (AppLocker, Windows Defender Application Control) 2. Create baseline of approved applications 3. Configure publisher certificate rules 4. Implement path rules for authorized locations 5. Block execution from user-writable directories 6. Deploy to all workstations 7. Enable audit mode first, then enforcement 8. Log all blocked execution attempts
**Validation**:
**Additional Requirements**:
**Implementation Steps**:
1. Extend controls to all servers 2. Implement driver signature requirements 3. Configure PowerShell Constrained Language Mode 4. Block scripting languages (unless required) 5. Central log collection (SIEM) 6. Regular rule review and updates
**Validation**:
**Additional Requirements**:
**Implementation Steps**:
1. Independent validation of implementation 2. Implement automated rule compliance checking 3. Continuous monitoring and alerting 4. Threat hunting using control events 5. Penetration testing of bypass techniques 6. Annual recertification
**Validation**:
---
**Requirements**:
**Implementation Steps**:
1. Maintain inventory of all applications 2. Subscribe to vendor security advisories 3. Assess vulnerability severity (use CVSS) 4. Prioritize internet-facing and critical apps 5. Test patches in non-production environment 6. Deploy patches according to timeline 7. Verify successful installation 8. Document patching activities
**Extreme Risk Definition**:
**Validation**:
**Additional Requirements**:
**Implementation Steps**:
1. Implement automated patching tools 2. Accelerate testing procedures 3. Staged deployment approach 4. Enhanced monitoring for patch failures 5. Metrics tracking and reporting
**Additional Requirements**:
**Implementation Steps**:
1. Fully automated patch testing 2. Rapid deployment capabilities 3. Rollback procedures tested 4. Continuous vulnerability scanning 5. Real-time patch compliance dashboards
---
**Requirements**:
**Implementation Steps**:
1. Configure Group Policy for Office macro settings 2. Enable "Block macros from the internet" 3. Define Trusted Locations (limited, IT-controlled) 4. Enable AMSI (Antimalware Scan Interface) 5. Block embedded OLE packages 6. Educate users on macro risks 7. Monitor macro execution events
**Validation**:
**Additional Requirements**:
**Additional Requirements**:
---
**Requirements**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.