From fedramp-rev5
Assesses FedRAMP Rev 5 authorization readiness for low/moderate/high impact levels and agency/JAB paths, producing readiness score, control gaps, documentation requirements, and 3PAO checklist.
How this command is triggered — by the user, by Claude, or both
Slash command
/fedramp-rev5:assessThe summary Claude sees in its command listing — used to decide when to auto-load this command
# FedRAMP Rev 5 Assessment Evaluates readiness for traditional FedRAMP authorization under Rev 5. ## Arguments - `$1` - Impact level (required: low, moderate, high) - `$2` - Authorization path (optional: agency, jab) ## Impact Levels ### FedRAMP Low (~125 controls) - Low-impact data (public information) - Minimal security requirements ### FedRAMP Moderate (~325 controls) - Controlled unclassified information (CUI) - Most common authorization level ### FedRAMP High (~425 controls) - Highly sensitive data - Law enforcement, emergency services ## Authorization Paths - **Agency**: Spons...
Evaluates readiness for traditional FedRAMP authorization under Rev 5.
$1 - Impact level (required: low, moderate, high)$2 - Authorization path (optional: agency, jab)/fedramp-rev5:assess moderate agency
npx claudepluginhub grcengclub/claude-grc-engineering --plugin fedramp-rev5/assessEvaluates organizational readiness for StateRAMP authorization to provide cloud services to state/local governments at low/moderate impact level with optional target state.
/overlay-applyApplies NIST 800-53 overlays (FedRAMP, DoD, Privacy, CMMC, etc.) to baselines (low, moderate, high), producing summaries of added/removed controls, parameter changes, and implementation guidance.
/ksi-checkEvaluates FedRAMP 20X Key Security Indicators (KSI) compliance by category or all, using optional evidence path. Outputs status, automation readiness, gap analysis, and recommendations.
/gap-analysisPerforms structured gap analysis against compliance frameworks like FedRAMP or SOC2 for a given scope, generating assessment templates, interactive worksheets, gap summaries, heat maps, and remediation roadmaps.
/assessAssesses CMMC v2.0 readiness for target level (1-3) with optional scope, producing compliance score, domain gaps, practice status, C3PAO preparation, and remediation roadmap.
/assessAssesses HITRUST CSF readiness for specified type (i1, r2, e1) and optional scope, producing readiness score, domain breakdowns, gap analysis, and remediation roadmap.