/stateramp-expert
StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill stateramp-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/stateramp-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.
SKILL.md
stateramp-expert.SKILL.mdname: stateramp-expert
description: StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies.
allowed-tools: Read, Glob, Grep, Write
StateRAMP Expert
Deep expertise in StateRAMP (State Risk and Authorization Management Program) for cloud service providers serving state and local government agencies.
Expertise Areas
StateRAMP Program Overview
**Purpose**: Standardized, reusable security authorization framework for state and local government cloud services **Authority**: State-level (not federal) **Based On**: FedRAMP framework, adapted for state/local needs **Launch**: 2015 (evolved from state reciprocity initiatives) **Current Status**: 15+ participating states, growing adoption
**Program Goals**:
- Reduce duplicative state-by-state assessments
- Lower costs for CSPs and states
- Standardize security baselines
- Enable reciprocity across states
- Accelerate secure cloud adoption
StateRAMP vs FedRAMP Comparison
| Aspect | StateRAMP | FedRAMP | |--------|-----------|---------| | **Authority** | State/local government | Federal government | | **Governance** | StateRAMP Impact Council | GSA, DHS, DOD (JAB) | | **Market** | 50 states, territories, localities | Federal agencies | | **Cost** | 20-30% lower typically | $200K-$1M+ | | **Timeline** | 6-18 months | 12-24+ months | | **Reciprocity** | Across participating states | Across federal agencies | | **Controls** | NIST 800-53 (state-tailored) | NIST 800-53 Rev 5 | | **Impact Levels** | Low, Moderate | Low, Moderate, High | | **Assessment** | StateRAMP-recognized 3PAO | FedRAMP-authorized 3PAO |
**Similarities**:
- NIST 800-53 control framework
- Third-party assessment required
- Continuous monitoring mandatory
- Similar documentation (SSP, SAP, SAR, POA&M)
- Annual assessments
- Significant change notifications
**Key Differences**:
- **Scope**: States vs. federal agencies
- **Data Types**: State data vs. federal CUI/FCI
- **Cost**: StateRAMP generally less expensive (smaller scope, faster timelines)
- **Flexibility**: States may add requirements, less rigid than FedRAMP
- **Market Size**: 50 states + locals vs. federal enterprise
- **Leverage**: FedRAMP authorization helps StateRAMP but not reciprocal
StateRAMP Impact Levels
StateRAMP uses FIPS 199 categorization:
**Low Impact (~125 controls)**:
- **Data**: Public information, non-sensitive
- **Systems**: Public-facing services, informational systems
- **Impact**: Limited adverse effect if compromised
- **Examples**:
- Event calendars
- Public document repositories
- General constituent communication
- Non-sensitive form submissions
- **Cost**: $50K-$150K assessment + remediation
- **Timeline**: 6-12 months
**Moderate Impact (~325 controls)**:
- **Data**: CUI, PII, PHI, financial, law enforcement sensitive
- **Systems**: Mission-critical, sensitive data processing
- **Impact**: Serious adverse effect if compromised
- **Examples**:
- Tax systems
- Benefits administration (SNAP, Medicaid)
- HR/Payroll systems
- Law enforcement case management
- Licensing with PII
- Healthcare portals
- Financial management
- **Cost**: $150K-$400K assessment + remediation
- **Timeline**: 12-18 months
**High Impact**:
- Not currently defined in StateRAMP
- States with high-impact needs typically use FedRAMP High or custom authorizations
- May emerge in future StateRAMP versions
NIST 800-53 Control Families
StateRAMP uses NIST SP 800-53 control framework:
**18 Control Families**:
1. **Access Control (AC)** - 25 controls at Moderate
- Account management (AC-2)
- Least privilege (AC-6)
- Remote access (AC-17)
- Wireless access (AC-18)
- Access control for mobile devices (AC-19)
2. **Awareness and Training (AT)** - 5 controls
- Security awareness (AT-2)
- Role-based training (AT-3)
- Security training records (AT-4)
3. **Audit and Accountability (AU)** - 12 controls
- Audit events (AU-2)
- Content of audit records (AU-3)
- Audit storage capacity (AU-4)
- Response to audit failures (AU-5)
- Audit review, analysis, reporting (AU-6)
- Audit reduction and report generation (AU-7)
- Time stamps (AU-8)
- Protection of audit information (AU-9)
- Audit record retention (AU-11)
4. **Security Assessment and Authorization (CA)** - 9 controls
- Security assessments (CA-2)
- System interconnections (CA-3)
- Plan of action and milestones (CA-5)
- Security authorization (CA-6)
- Continuous monitoring (CA-7)
- Penetration testing (CA-8)
5. **Configuration Management (CM)** - 11 controls
- Baseline configuration (CM-2)
- Configuration change control (CM-3)
- Security impact analysis (CM-4)
- Access restrictions for change (CM-5)
- Configuration settings (CM-6)
- Least functionality (CM-7)
- Information system component inventory (CM-8)
6. **Contingency Planning (CP)** - 10 controls
- Contingency plan (CP-2)
- Contingency training (CP-3)
- Contingency plan testing (CP-4)
- Information system backup (CP-9)
- Information system recovery and reconstitution (CP-10)
7. **Identification and Authentication (IA)** - 11 controls
- Identification and authentication (organizational users) (IA-2)
- Device identification and authentication (IA-3)
- Identifier management (IA-4)
- Authenticator management (IA-5)
- Authenticator feedback (IA-6)
- Cryptographic module authentication (IA-7)
8. **Incident Response (IR)** - 10 controls
- Incident response training (IR-2)
- Incident response testing (IR-3)
- Incident handling (IR-4)
- Incident monitoring (IR-5)
- Incident reporting (IR-6)
- Incident response assistance (IR-7)
- Incident response plan (IR-8)
9. **Maintenance (MA)** - 6 controls
- System mainte
Read more
name: stateramp-expert description: StateRAMP expert for state and local government cloud services. Deep knowledge of State Risk and Authorization Management Program including Low/Moderate impact levels, NIST 800-53 controls, state-specific requirements, FedRAMP alignment, and multi-state authorization strategies. allowed-tools: Read, Glob, Grep, Write
StateRAMP Expert
Deep expertise in StateRAMP (State Risk and Authorization Management Program) for cloud service providers serving state and local government agencies.
Expertise Areas
StateRAMP Program Overview
**Purpose**: Standardized, reusable security authorization framework for state and local government cloud services **Authority**: State-level (not federal) **Based On**: FedRAMP framework, adapted for state/local needs **Launch**: 2015 (evolved from state reciprocity initiatives) **Current Status**: 15+ participating states, growing adoption
**Program Goals**:
- Reduce duplicative state-by-state assessments
- Lower costs for CSPs and states
- Standardize security baselines
- Enable reciprocity across states
- Accelerate secure cloud adoption
StateRAMP vs FedRAMP Comparison
| Aspect | StateRAMP | FedRAMP | |--------|-----------|---------| | **Authority** | State/local government | Federal government | | **Governance** | StateRAMP Impact Council | GSA, DHS, DOD (JAB) | | **Market** | 50 states, territories, localities | Federal agencies | | **Cost** | 20-30% lower typically | $200K-$1M+ | | **Timeline** | 6-18 months | 12-24+ months | | **Reciprocity** | Across participating states | Across federal agencies | | **Controls** | NIST 800-53 (state-tailored) | NIST 800-53 Rev 5 | | **Impact Levels** | Low, Moderate | Low, Moderate, High | | **Assessment** | StateRAMP-recognized 3PAO | FedRAMP-authorized 3PAO |
**Similarities**:
- NIST 800-53 control framework
- Third-party assessment required
- Continuous monitoring mandatory
- Similar documentation (SSP, SAP, SAR, POA&M)
- Annual assessments
- Significant change notifications
**Key Differences**:
- **Scope**: States vs. federal agencies
- **Data Types**: State data vs. federal CUI/FCI
- **Cost**: StateRAMP generally less expensive (smaller scope, faster timelines)
- **Flexibility**: States may add requirements, less rigid than FedRAMP
- **Market Size**: 50 states + locals vs. federal enterprise
- **Leverage**: FedRAMP authorization helps StateRAMP but not reciprocal
StateRAMP Impact Levels
StateRAMP uses FIPS 199 categorization:
**Low Impact (~125 controls)**:
- **Data**: Public information, non-sensitive
- **Systems**: Public-facing services, informational systems
- **Impact**: Limited adverse effect if compromised
- **Examples**:
- Event calendars
- Public document repositories
- General constituent communication
- Non-sensitive form submissions
- **Cost**: $50K-$150K assessment + remediation
- **Timeline**: 6-12 months
**Moderate Impact (~325 controls)**:
- **Data**: CUI, PII, PHI, financial, law enforcement sensitive
- **Systems**: Mission-critical, sensitive data processing
- **Impact**: Serious adverse effect if compromised
- **Examples**:
- Tax systems
- Benefits administration (SNAP, Medicaid)
- HR/Payroll systems
- Law enforcement case management
- Licensing with PII
- Healthcare portals
- Financial management
- **Cost**: $150K-$400K assessment + remediation
- **Timeline**: 12-18 months
**High Impact**:
- Not currently defined in StateRAMP
- States with high-impact needs typically use FedRAMP High or custom authorizations
- May emerge in future StateRAMP versions
NIST 800-53 Control Families
StateRAMP uses NIST SP 800-53 control framework:
**18 Control Families**:
1. **Access Control (AC)** - 25 controls at Moderate
- Account management (AC-2)
- Least privilege (AC-6)
- Remote access (AC-17)
- Wireless access (AC-18)
- Access control for mobile devices (AC-19)
2. **Awareness and Training (AT)** - 5 controls
- Security awareness (AT-2)
- Role-based training (AT-3)
- Security training records (AT-4)
3. **Audit and Accountability (AU)** - 12 controls
- Audit events (AU-2)
- Content of audit records (AU-3)
- Audit storage capacity (AU-4)
- Response to audit failures (AU-5)
- Audit review, analysis, reporting (AU-6)
- Audit reduction and report generation (AU-7)
- Time stamps (AU-8)
- Protection of audit information (AU-9)
- Audit record retention (AU-11)
4. **Security Assessment and Authorization (CA)** - 9 controls
- Security assessments (CA-2)
- System interconnections (CA-3)
- Plan of action and milestones (CA-5)
- Security authorization (CA-6)
- Continuous monitoring (CA-7)
- Penetration testing (CA-8)
5. **Configuration Management (CM)** - 11 controls
- Baseline configuration (CM-2)
- Configuration change control (CM-3)
- Security impact analysis (CM-4)
- Access restrictions for change (CM-5)
- Configuration settings (CM-6)
- Least functionality (CM-7)
- Information system component inventory (CM-8)
6. **Contingency Planning (CP)** - 10 controls
- Contingency plan (CP-2)
- Contingency training (CP-3)
- Contingency plan testing (CP-4)
- Information system backup (CP-9)
- Information system recovery and reconstitution (CP-10)
7. **Identification and Authentication (IA)** - 11 controls
- Identification and authentication (organizational users) (IA-2)
- Device identification and authentication (IA-3)
- Identifier management (IA-4)
- Authenticator management (IA-5)
- Authenticator feedback (IA-6)
- Cryptographic module authentication (IA-7)
8. **Incident Response (IR)** - 10 controls
- Incident response training (IR-2)
- Incident response testing (IR-3)
- Incident handling (IR-4)
- Incident monitoring (IR-5)
- Incident reporting (IR-6)
- Incident response assistance (IR-7)
- Incident response plan (IR-8)
9. **Maintenance (MA)** - 6 controls
- System mainte
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

