원클릭으로
control-ops
Control lookup, cross-framework mapping, search, and coverage analysis across 15 compliance frameworks.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Control lookup, cross-framework mapping, search, and coverage analysis across 15 compliance frameworks.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | control-ops |
| description | Control lookup, cross-framework mapping, search, and coverage analysis across 15 compliance frameworks. |
Search, look up, map, and analyze controls across NIST 800-53, FedRAMP, SOC 2, ISO 27001, PCI DSS, HIPAA, CIS Controls, CMMC, COBIT, CSA CCM, and GDPR.
| Command | Description |
|---|---|
/grc:control-lookup | Look up controls by framework and ID or keyword |
/grc:map-controls | Cross-framework control mapping (NIST as hub) |
/grc:list-controls | List NIST controls from FRMR documents |
/grc:control-coverage | Analyze control coverage across baselines |
/grc:control-requirements | Get detailed control requirement info |
/grc:get-requirement | Retrieve a specific requirement by ID |
/grc:filter-impact | Filter controls by impact level |
/grc:list-ksi | List FedRAMP Key Security Indicators |
/grc:theme-summary | Summarize controls by framework theme |
/grc:search | Search FedRAMP documentation |
/grc:search-definitions | Search control definitions |
/grc:list-documents | List compliance documents |
Use this skill when the user needs to:
grc-pro/knowledge/frameworks/*.md — Framework reference filesgrc-pro/knowledge/mappings/*.md — Cross-framework mapping tablesgrc-pro/knowledge/oscal/nist-800-53-rev5/*.json — NIST 800-53 OSCAL datagrc-pro/knowledge/oscal/fedramp-moderate-rev5/*.json — FedRAMP OSCAL datagrc-pro/config/control-families.json — Control family metadataWhen the grc-mcp-server is available, prefer these MCP tools over direct file reading:
| MCP Tool | Use For |
|---|---|
grc_get_oscal_control | NIST/FedRAMP control lookups (statement, params, assessment objectives/methods) |
grc_lookup_control | Control catalog lookups by ID (GOV-01, CTRL-AC-001) |
grc_search_controls | Full-text search across control catalog |
grc_map_control | Cross-framework mapping with IR 8477 set-theory relationships |
grc_strm_analyze | Detailed IR 8477 STRM analysis (relation type, rationale, strength score) |
grc_transitive_map | Derive indirect mappings through an intermediary framework |
grc_strm_summary | Distribution of STRM relationship types across all mappings |
grc_reverse_map | Find all source mappings for a target control |
grc_search_oscal | Keyword search across OSCAL control prose |
Fallback: If MCP tools are unavailable, read the OSCAL JSON files directly from grc-pro/knowledge/oscal/ using offset/limit for large files.
Audit preparation, evidence checklists, assessment simulation, gap analysis, and maturity scoring.
Draft SSP sections, SAR responses, boundary definitions, inheritance models, OSCAL guidance, and multi-framework coverage analyses.
Operational compliance workflows: continuous monitoring, calendaring, POA&M management, change management, and framework transitions.
Maps controls across cybersecurity frameworks using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Use when helping with control implementation, compliance mapping, cross-framework alignment, or understanding control relationships.
Review SSPs, narratives, POA&Ms, policies, and CRMs for structural completeness and quality.
Generate tabletop exercise scenarios for incident response and contingency planning.