academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Canadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill pbmm-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/pbmm-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
Canadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements.
name: pbmm-expert description: Canadian PBMM (Protected B, Medium Integrity, Medium Availability) expert. Provides comprehensive guidance on ITSG-33 controls, CCCS assessment, Canadian data residency, and Government of Canada cloud security requirements. allowed-tools: Read, Glob, Grep, Write
Deep expertise in Canadian Protected B, Medium Integrity, Medium Availability (PBMM) compliance based on ITSG-33 and CCCS Medium Cloud Security Profile.
**PBMM (Protected B, Medium Integrity, Medium Availability)**:
**Purpose**: Standardize cloud security for Protected B data across Government of Canada
| Level | Full Name | Injury if Compromised | Use Cases | |-------|-----------|----------------------|-----------| | **U** | Unclassified | None | Public websites, published documents | | **PA** | Protected A | Limited injury | Internal emails, drafts | | **PB** | Protected B | Serious injury | Personal info, health records, financial data | | **PC** | Protected C | Grave injury | Law enforcement, sensitive intelligence | | **SECRET** | Secret | Exceptionally grave injury | National security | | **TOP SECRET** | Top Secret | Catastrophic injury | Highest classification |
**PBMM Applicability**: Protected B data only
**Requirement**: All Protected B data must be stored, processed, and backed up exclusively in Canadian geographic regions
**Approved Canadian Regions**:
| Provider | Regions | Location | |----------|---------|----------| | **AWS** | ca-central-1 | Montreal, QC | | **AWS** | ca-west-1 | Calgary, AB | | **Azure** | canadacentral | Toronto, ON | | **Azure** | canadaeast | Quebec City, QC | | **GCP** | northamerica-northeast1 | Montreal, QC | | **GCP** | northamerica-northeast2 | Toronto, ON |
**Prohibited**:
**NIST Mapping**: SA-9(5), SC-8
**Implementation**:
**Requirement**: Establish and maintain formal access control policies aligned with ITSG-33
**Key Elements**:
**NIST Mapping**: AC-1, AC-2
**Cloud Implementation**:
**Requirement**: Enforce MFA for all users accessing Protected B systems
**Acceptable MFA Methods**:
**Implementation**:
**Enforcement**: No MFA = No access
**NIST Mapping**: IA-2(1), IA-2(2)
**Requirement**: Maintain comprehensive audit logs for at least 2 years
**Logging Scope**:
**Log Retention**: Minimum 2 years
**Log Protection**:
**Implementation**:
**NIST Mapping**: AU-2, AU-3, AU-6, AU-9
**Requirement**: Encrypt all Protected B data at rest using FIPS 140-2 validated encryption
**Encryption Standard**: FIPS 140-2 Level 2 or higher
**Coverage**:
**Cloud KMS Solutions**:
**Key Management**:
**NIST Mapping**: SC-28
**Requirement**: Encrypt all data transmissions using TLS 1.2+ with FIPS-approved cipher suites
**Minimum TLS**: TLS 1.2 (TLS 1.3 preferred)
**FIPS Cipher Suites**:
**Prohibited**: SSL, TLS 1.0, TLS 1.1
**Implementation**:
**NIST Mapping**: SC-8
**Requirement**: Implement network segmentation with security groups, firewalls, and network
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.