academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
CSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ccm-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/ccm-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
CSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST.
name: ccm-expert description: CSA CCM expert for cloud security. Deep knowledge of Cloud Security Alliance Cloud Controls Matrix including 197 controls, 17 domains, CAIQ questionnaire, cloud service models (IaaS/PaaS/SaaS), shared responsibility, and framework mappings to ISO 27001, SOC 2, PCI-DSS, NIST. allowed-tools: Read, Glob, Grep, Write
Deep expertise in Cloud Security Alliance Cloud Controls Matrix (CCM) for cloud service providers, cloud consumers, and cloud security professionals.
**Mission**: Promote best practices for secure cloud computing **Founded**: 2008 **Membership**: 500+ corporate members, 100,000+ individual members globally **Key Programs**:
**Current Version**: CCM v4.0 (released 2021) **Control Objectives**: 197 controls across 17 domains **Purpose**: Provide cloud-specific security controls framework **Scope**: Applies to all cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, multi-cloud)
**Key Features**:
Independent verification and compliance validation.
**Key Controls**:
**Implementation Priorities**:
Secure software development and API protection.
**Key Controls**:
**Cloud-Specific Considerations**:
**OWASP Top 10 Cloud Risks**:
1. Broken authentication and session management 2. Sensitive data exposure 3. Broken access control 4. Security misconfiguration 5. Cross-site scripting (XSS) 6. Insecure deserialization 7. Using components with known vulnerabilities 8. Insufficient logging and monitoring 9. SQL injection 10. Server-side request forgery (SSRF)
High availability and disaster recovery.
**Key Controls**:
**Cloud Resilience Patterns**:
**SLA Tiers**:
Managing changes and maintaining secure configurations.
**Key Controls**:
**Cloud Configuration Management**:
**CIS Benchmarks for Cloud**:
Data protection through cryptographic controls.
**Key Controls**:
**Cloud Key Management Services**:
**Encryption Standards**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.