By GRCEngClub
Assess organizational readiness for ACSC Essential Eight cybersecurity strategies at maturity levels 1-3, generate evidence checklists and prioritized improvement roadmaps, recommend target maturity levels by risk profile, and verify individual strategy implementations with checklists and validation steps.
Essential 8 maturity assessment by target level
Generates comprehensive evidence collection checklists for Australian Cyber Security Centre (ACSC) Essential Eight mitigation strategies with maturity level progression (ML1-ML3).
Determine appropriate Essential 8 maturity level target
Generate Essential 8 maturity improvement roadmap
Verify specific Essential 8 strategy implementation
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin essential8Deploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
FedRAMP Rev 5 Plugin - Traditional authorization path with SSP/SAP/SAR/POA&M documentation and NIST 800-53 Rev 5 control mapping
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
NIST 800-53 Plugin - Control families, baseline selection (Low/Moderate/High), and FedRAMP alignment
DORA Plugin - EU Digital Operational Resilience Act for financial entities with ICT risk management (effective January 2025)
Australian IRAP (ISM + Essential Eight) for government cloud
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor — gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.
Check infrastructure compliance (SOC2, HIPAA, PCI-DSS)
Harness-native ECC plugin for engineering teams - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.