From grc
Develop or review security governance documents — policies, standards, procedures, and guidelines — aligned to a framework and the organization's risk, with a clear hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security policy set.
How this skill is triggered — by the user, by Claude, or both
Slash command
/grc:policy-managementThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A coherent, usable governance document set: the right policies/standards/procedures,
A coherent, usable governance document set: the right policies/standards/procedures, aligned to frameworks and risk, written to be followed, with ownership, approval, and review built in.
compliance-assessment) and risks (risk-assessment) require; find gaps,
overlaps, and stale/contradictory documents.A policy set or review: document · type (policy/standard/procedure) · owner · status ·
gaps/changes, plus drafts/revisions and an exception process. Use security-reporting.
Match the document to the level — putting how-to detail in a policy makes it churn;
putting mandatory specifics only in a guideline makes them optional. Policy without an
implementing control and an exception process is shelfware. Reuse framework control
language so policies map cleanly to compliance-assessment.
npx claudepluginhub jassics/awesome-claude-security --plugin grcProvides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.