academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill hitrust-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/hitrust-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy.
name: hitrust-expert description: HITRUST CSF expert for healthcare security. Implementation guidance, assessment workflow, and mapping to HIPAA/NIST/ISO/PCI frameworks. References control IDs only — not a replacement for a licensed CSF copy. allowed-tools: Read, Glob, Grep, Write
Deep expertise in HITRUST Common Security Framework (CSF) for healthcare and business-associate organizations.
> **Important — normative text.** HITRUST CSF is proprietary and subscription-required. This skill provides **implementation guidance**, **assessment workflow**, and **evidence patterns** — phrased in the author's own words. All normative control statements, scoring rubrics, and MyCSF-specific requirement language must be read from your licensed CSF. When a command in this plugin quotes a control description, it is a paraphrased summary; consult the CSF for authoritative text.
**Mission**: Create security and privacy programs that can be certified **Founded**: 2007 **Purpose**: Address security/privacy challenges in healthcare industry **Key Value**: Single framework harmonizing 40+ regulations and standards
**Current Version**: CSF v11 (as of 2024) **Control Objectives**: 156 across 19 domains **Customization**: MyCSF tailored assessment **Certifications**: i1, r2, e1
| Type | Full Name | Duration | Assessor | Validity | Use Case | |------|-----------|----------|----------|----------|----------| | **i1** | Implemented, 1-year | 3-6 months | Self or validated | 1 year | Initial cert, vendors | | **r2** | Reportable, 2-year | 6-12 months | External required | 2 years | Providers, high assurance | | **e1** | e1 Assessment | 3-6 months | Can be self | Bridge | Upgrade i1 to r2 |
**i1 Assessment**:
**r2 Assessment**:
**e1 Assessment**:
HITRUST CSF requirements tailored based on:
**Organization Factors**:
1. **Type**: Provider, payer, clearinghouse, BA, vendor, other 2. **Size**:
3. **System Type**: SaaS, on-premise, hybrid, mobile 4. **Regulatory Factors**: HIPAA, state laws, international regs
**Customization Result**:
1. **Information Security Management Program (01)** - 12 controls
2. **Access Control (02)** - 14 controls
3. **Human Resources Security (03)** - 8 controls
4. **Risk Management (04)** - 5 controls
5. **Security Policy (05)** - 3 controls
6. **Organization of Information Security (06)** - 8 controls
7. **Compliance (07)** - 6 controls
8. **Asset Management (08)** - 7 controls
9. **Physical and Environmental Security (09)** - 11 controls
10. **Communications and Operations Management (10)** - 23 controls
11. **Information Systems Acquisition, Development and Maintenance (11)** - 15 controls
12. **Information Security Incident Management (12)** - 6 controls
13. **Business Continuity Management (13)** - 5 controls
14. **Network Protection (14)** - 7 controls
15. **Password Management (15)** - 6 controls
16. **Education, Training and Awareness (16)** - 4 controls
17. **Third Party Assurance (17)** - 6 controls
18. **Mobile Device Security (18)** - 5 controls
19. **Incident Detection and Response (19)** - 5 controls
HITRUST CSF maps to 40+ frameworks including:
**Primary Frameworks**:
**Additional Frameworks**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.