academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill cmmc-assessment-objectives --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cmmc-assessment-objectivesContext preview
The summary Claude sees to decide when to auto-load this skill.
Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert.
name: cmmc-assessment-objectives description: "Verbatim reference for all 320 NIST 800-171A Rev 2 assessment objectives, plus the Rev 2 → Rev 3 control crosswalk. Use for AO-level lookups (e.g., 3.1.1[c]), evidence planning, and forward-mapping to Rev 3. Pairs with cmmc-expert." allowed-tools: Read, Glob, Grep, Write
The scoreable layer underneath every CMMC Level 2 assessment. Where `cmmc-expert` describes the CMMC program, this skill captures the **320 specific objectives** an assessor is actually scoring against, plus the structural Rev 2 → Rev 3 mapping.
| Question | Skill | |---|---| | What does CMMC require, who needs L1 vs L2, how does SPRS scoring work, what's POA&M-eligible? | `cmmc-expert` | | What does an assessor look for at the objective level for 3.1.1? What does 3.13.11[a] actually say? | **this skill** | | Where does Rev 2 3.5.7 land in Rev 3? Which Rev 2 controls were withdrawn? | **this skill** | | What FedRAMP level does a CSP need for CUI? | `cmmc-expert` | | What does FIPS-validated cryptography mean in Rev 3 vs. Rev 2? | **this skill** (note in 3.13.11 crosswalk row) |
**Lookup patterns:**
**Layer 1 — Assessment objectives (Rev 2):**
**Layer 2 — Rev 2 → Rev 3 crosswalk:**
**Critical constants for Rev 2:**
---
| Family | Rev 2 Controls | Rev 2 Assessment Objectives | |---|---|---| | 3.1 Access Control (AC) | 22 | **70** | | 3.2 Awareness & Training (AT) | 3 | 9 | | 3.3 Audit & Accountability (AU) | 9 | 29 | | 3.4 Configuration Management (CM) | 9 | **44** | | 3.5 Identification & Authentication (IA) | 11 | 25 | | 3.6 Incident Response (IR) | 3 | 14 | | 3.7 Maintenance (MA) | 6 | 10 | | 3.8 Media Protection (MP) | 9 | 15 | | 3.9 Personnel Security (PS) | 2 | 4 | | 3.10 Physical Protection (PE) | 6 | 16 | | 3.11 Risk Assessment (RA) | 3 | 9 | | 3.12 Security Assessment (CA) | 4 | 14 | | 3.13 System & Comms Protection (SC) | 16 | **41** | | 3.14 System & Info Integrity (SI) | 7 | 20 | | **TOTAL** | **110** | **320** |
---
Three methods — **not four.** "Determine" is the verb each objective opens with, not a separate method.
| Method | What it means | Depth attributes | |---|---|---| | **EXAMINE** | Reviewing, inspecting, observing, studying, or analyzing assessment objects (specifications, mechanisms, activities). | Basic / Focused / Comprehensive | | **INTERVIEW** | Discussions with individuals or groups to facilitate understanding, achieve clarification, or obtain evidence. | Basic / Focused / Comprehensive | | **TEST** | Exercising assessment objects under specified conditions to compare actual with expected behavior. | Basic (black box) / Focused (gray box) / Comprehensive (white box) |
Each lettered sub-item (`[a]`, `[b]`, ...) is **one scoreable assessment objective**. For each, the assessor will (per NIST 800-171A):
1. **Determine** if the objective is satisfied. 2. Support that determination with **E/I/T** evidence — typically all three for any non-trivial control. 3. Mark it **Satisfied** or **Other Than Satisfied** for SPRS / CMMC purposes.
**Practice-level rollup:** all AOs within a practice must be Satisfied for the practice to be **MET** in a C3PAO assessment.
---
> Text below is verbatim from NIST SP 800-171A. Each lettered sub-item is one scoreable assessment objective.
**3.1.1** — Limit system access to authorized users, processes acting on behalf of authorized users, and devices.
**3.1.2** — Limit system access to the types of transactions and functions that authorized users are permitted to execute.
**3.1.3** — Control the flow of CUI in accordance with approved
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.