By GRCEngClub
Conduct HITRUST CSF assessments (i1/r2/e1) for healthcare security compliance, mapping controls to HIPAA/NIST/ISO/PCI frameworks, generating evidence checklists with exports, performing gap analyses with risk prioritization, and selecting optimal scopes based on organization type.
HITRUST CSF readiness assessment by assessment type
Map HITRUST CSF controls to source frameworks
Generates comprehensive evidence collection checklists for HITRUST Common Security Framework (CSF) certification with focus on healthcare and HIPAA alignment (implementation levels 1-3).
Identify gaps between current state and HITRUST CSF requirements
Determine appropriate HITRUST assessment scope (i1 vs r2)
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin hitrustDeploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
FedRAMP Rev 5 Plugin - Traditional authorization path with SSP/SAP/SAR/POA&M documentation and NIST 800-53 Rev 5 control mapping
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
NIST 800-53 Plugin - Control families, baseline selection (Low/Moderate/High), and FedRAMP alignment
DORA Plugin - EU Digital Operational Resilience Act for financial entities with ICT risk management (effective January 2025)
GRC Auditor Plugin - Evidence review, control validation, and audit workpaper generation for external auditors and assessors
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor — gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.
Harness-native ECC plugin for engineering teams - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.