By GRCEngClub
Assess organizational readiness for NYDFS 23 NYCRR 500 cybersecurity compliance, prepare tailored annual certifications, generate evidence checklists by section, create penetration testing plans for cloud environments, and access expert guidance on CISO roles, incident response, and third-party risks in financial services.
NYDFS 23 NYCRR 500 compliance readiness assessment
Annual NYDFS 23 NYCRR 500 certification guidance
NYDFS CISO role, qualifications, and responsibilities
Generates comprehensive evidence collection checklists for New York Department of Financial Services (NYDFS) 23 NYCRR 500 cybersecurity requirements for covered entities.
NYDFS penetration testing and vulnerability assessment requirements
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Deploy a serverless trust center to publish your company's compliance posture. Supports AWS deployment with S3, CloudFront, Lambda, DynamoDB, Cognito, and WAF.
FedRAMP Rev 5 Plugin - Traditional authorization path with SSP/SAP/SAR/POA&M documentation and NIST 800-53 Rev 5 control mapping
SOC 2 Compliance Plugin - Trust Service Criteria expertise, Type I/II assessment support, and control mapping
NIST 800-53 Plugin - Control families, baseline selection (Low/Moderate/High), and FedRAMP alignment
DORA Plugin - EU Digital Operational Resilience Act for financial entities with ICT risk management (effective January 2025)
npx claudepluginhub grcengclub/claude-grc-engineering --plugin nydfsDORA Plugin - EU Digital Operational Resilience Act for financial entities with ICT risk management (effective January 2025)
GRC (Governance, Risk, and Compliance) domain knowledge — frameworks, controls, audits, evidence, ConMon, cross-framework mappings, document review, and operational workflows. Cloud-agnostic.
End-to-end FedRAMP authorization guidance — readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.
Comprehensive skill pack with 66 specialized skills for full-stack developers: 12 language experts (Python, TypeScript, Go, Rust, C++, Swift, Kotlin, C#, PHP, Java, SQL, JavaScript), 10 backend frameworks, 6 frontend/mobile, plus infrastructure, DevOps, security, and testing. Features progressive disclosure architecture for 50% faster loading.
v9.44.1 — Patch release for Gemini environment/version detection and qwen auth gating. Run /octo:setup.
Harness-native ECC plugin for engineering teams - 67 agents, 271 skills, 92 legacy command shims, reusable hooks, rules, MCP conventions, and operator workflows for Claude Code plus adjacent agent harnesses