academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cis-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cis-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes.
name: cis-expert description: CIS Controls v8 expert for baseline security. Deep knowledge of 18 controls, 153 safeguards, Implementation Groups (IG1/IG2/IG3), and practical implementation guidance for organizations of all sizes. allowed-tools: Read, Glob, Grep, Write
Deep expertise in CIS Controls v8, the baseline cybersecurity framework developed by the Center for Internet Security.
> **License notice.** This skill incorporates content derived from **CIS Controls v8**, © Center for Internet Security, Inc., used under the [Creative Commons Attribution-ShareAlike 4.0 International](https://creativecommons.org/licenses/by-sa/4.0/) license. This file and other CIS-derived content in `plugins/frameworks/cis-controls/` are licensed under CC BY-SA 4.0 (the rest of the repository is MIT). See [LICENSE-CIS.md](../../LICENSE-CIS.md).
**Purpose**: Prioritized set of actions to defend against the most pervasive cyber threats **Authority**: Center for Internet Security (CIS) - global non-profit **Current Version**: CIS Controls v8 (May 2021) **Adoption**: Cross-industry standard, used globally by organizations of all sizes
**Key Principles**:
**Evolution from v7 to v8**:
The core innovation of CIS Controls: tailored security based on organizational maturity and risk.
**Target Audience**:
**Characteristics**:
**Attack Profile IG1 Defends Against**:
**Example Organizations**:
**Critical IG1 Safeguards**:
1. Asset and software inventory (1.1, 2.1) 2. Secure configurations (4.1, 4.2) 3. Account management (5.1, 5.3, 5.4) 4. Automated patching (7.3, 7.4) 5. Anti-malware (10.1, 10.2) 6. Backups (11.2, 11.3) 7. Security awareness (14.1)
**Target Audience**:
**Characteristics**:
**Attack Profile IG2 Defends Against**:
**Example Organizations**:
**Critical IG2 Safeguards** (beyond IG1):
1. Multi-factor authentication (5.5) 2. Encryption (3.6, 3.10, 3.11) 3. Centralized logging and SIEM (8.9, 8.11) 4. Vulnerability scanning (7.5, 7.6) 5. Network segmentation (12.2) 6. IDS/IPS (13.2, 13.3) 7. Secure SDLC (16.1, 16.2) 8. Penetration testing (18.1, 18.2)
**Target Audience**:
**Characteristics**:
**Attack Profile IG3 Defends Against**:
**Example Organizations**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.