From pbmm
Assesses Protected B (PBMM) compliance readiness against ITSG-33 controls, evaluating data residency, access control, MFA, auditing, and encryption in AWS, Azure, GCP regions. Supports classification levels and assessment types.
How this command is triggered — by the user, by Claude, or both
Slash command
/pbmm:assessThe summary Claude sees in its command listing — used to decide when to auto-load this command
# PBMM Assessment Evaluates readiness for Canadian Protected B, Medium Integrity, Medium Availability (PBMM) compliance based on ITSG-33 and the CCCS Medium Cloud Security Profile. ## Arguments - `$1` - Classification level (optional: protected-a, protected-b, protected-c) - defaults to "protected-b" - `$2` - Assessment type (optional: readiness, gap-analysis, certification) - defaults to "readiness" ## Classification Levels | Level | Sensitivity | Injury if Compromised | Controls Required | |-------|-------------|----------------------|-------------------| | **Unclassified** | Public ...
Evaluates readiness for Canadian Protected B, Medium Integrity, Medium Availability (PBMM) compliance based on ITSG-33 and the CCCS Medium Cloud Security Profile.
$1 - Classification level (optional: protected-a, protected-b, protected-c) - defaults to "protected-b"$2 - Assessment type (optional: readiness, gap-analysis, certification) - defaults to "readiness"| Level | Sensitivity | Injury if Compromised | Controls Required |
|---|---|---|---|
| Unclassified | Public information | None | Basic hygiene |
| Protected A | Low sensitivity | Limited injury | Basic ITSG-33 |
| Protected B | Sensitive | Serious injury | Full PBMM profile (10 controls) |
| Protected C | Extremely sensitive | Grave injury | Enhanced beyond PBMM |
Requirement: All Protected B data must reside exclusively in Canadian geographic regions.
Approved Regions:
Assessment Questions:
Requirement: Establish and maintain access control policies aligned with ITSG-33.
NIST Mapping: AC-1, AC-2
Assessment Questions:
Requirement: Enforce MFA for all users accessing Protected B systems.
NIST Mapping: IA-2(1), IA-2(2)
Assessment Questions:
Requirement: Maintain comprehensive audit logs for at least 2 years.
NIST Mapping: AU-2, AU-3, AU-6, AU-9
Assessment Questions:
Requirement: Encrypt all Protected B data at rest using FIPS 140-2 validated encryption.
NIST Mapping: SC-28
Assessment Questions:
Requirement: Encrypt all data transmissions using TLS 1.2+ with FIPS-approved cipher suites.
NIST Mapping: SC-8
Assessment Questions:
Requirement: Implement network segmentation with security groups and firewalls.
NIST Mapping: SC-7
Assessment Questions:
Requirement: Scan for vulnerabilities and remediate within defined timeframes.
NIST Mapping: RA-5
Remediation Timeframes:
Assessment Questions:
Requirement: Establish incident response procedures and contact CCCS for incidents.
NIST Mapping: IR-1, IR-4, IR-6
Assessment Questions:
Requirement: Implement automated backups with Canadian region storage.
NIST Mapping: CP-9
Assessment Questions:
Organizations prepare for CCCS assessment by:
Process:
Timeline: 6-12 months Validity: 2 years (re-assessment required)
| Provider | PBMM Status | Canadian Regions | Notes |
|---|---|---|---|
| AWS | ✅ Certified | ca-central-1, ca-west-1 | ITSM.50.100 assessed |
| Azure | ✅ Certified | canadacentral, canadaeast | PBMM compliant |
| GCP | ⚠️ In Progress | northamerica-northeast1/2 | Check current status |
Assessment Report Includes:
# Protected B readiness assessment
/pbmm:assess protected-b readiness
# Gap analysis for certification
/pbmm:assess protected-b gap-analysis
# Protected A assessment
/pbmm:assess protected-a readiness
npx claudepluginhub grcengclub/claude-grc-engineering --plugin pbmm/assessEvaluates organizational readiness for CSA CCM v4.0 compliance using specified scope (full, domain-specific, service-model) and optional cloud service model (IaaS, PaaS, SaaS, hybrid).
/assessAssesses IRAP compliance readiness for Australian government cloud services based on ISM and Essential Eight, evaluating maturity levels for specified classification (official, protected, secret).
/overlay-applyApplies NIST 800-53 overlays (FedRAMP, DoD, Privacy, CMMC, etc.) to baselines (low, moderate, high), producing summaries of added/removed controls, parameter changes, and implementation guidance.
/assessEvaluates ISMAP compliance readiness for Japanese government cloud services based on ISO 27001/27017/27018 standards across 12 control areas. Supports full, iso-mapping, readiness scopes.
/evidence-checklistGenerates StateRAMP evidence checklists for NIST 800-53 control families, supporting moderate/high baselines and markdown/JSON/CSV export.
/assessAssesses CIS Controls v8 compliance for specified Implementation Group (IG1/IG2/IG3), with optional full, gap-analysis, or specific-control scope.