How this command is triggered — by the user, by Claude, or both
Slash command
/hitrust:assessThe summary Claude sees in its command listing — used to decide when to auto-load this command
# HITRUST Assessment Evaluates organizational readiness for HITRUST Common Security Framework (CSF) certification. ## Arguments - `$1` - Assessment type (required: i1, r2, e1) - `$2` - Scope (optional: full, self-assessment, validated) ## HITRUST Assessment Types | Type | Name | Duration | Assessor | Recertification | |------|------|----------|----------|----------------| | **i1** | Implemented, 1-year | Faster | Self or 3rd party | Annual | | **r2** | Reportable, 2-year | Comprehensive | External assessor required | Biennial | | **e1** | e1 Assessment | Bridges i1 to r2 | Can be self ...
Evaluates organizational readiness for HITRUST Common Security Framework (CSF) certification.
$1 - Assessment type (required: i1, r2, e1)$2 - Scope (optional: full, self-assessment, validated)| Type | Name | Duration | Assessor | Recertification |
|---|---|---|---|---|
| i1 | Implemented, 1-year | Faster | Self or 3rd party | Annual |
| r2 | Reportable, 2-year | Comprehensive | External assessor required | Biennial |
| e1 | e1 Assessment | Bridges i1 to r2 | Can be self | N/A - transition |
156 Control Objectives across 19 domains:
HITRUST MyCSF tailors requirements based on:
Customization Result:
HITRUST CSF harmonizes multiple frameworks:
# Full r2 assessment for healthcare provider
/hitrust:assess r2 full
# i1 self-assessment readiness check
/hitrust:assess i1 self-assessment
# Validated i1 assessment scope
/hitrust:assess i1 validated
npx claudepluginhub fianulabs/claude-grc-engineering --plugin hitrust/assessCompares a local repository against a topic wiki's research body and the broader market, producing a gap analysis with opportunities and competitive landscape.
/assessAssesses DORA compliance readiness for EU financial entities and ICT providers. Requires scope (full, pillar-specific, entity-type); optional entity classification.
/assessAssesses GLBA compliance readiness for specified scope (full, safeguards, privacy, pretexting) and institution type, producing compliance score and detailed evaluation.
/assessAssesses compliance with NIST 800-53 controls for a specified control family (e.g., AC) or baseline (low, moderate, high), with optional revision (r4 or r5).
/assessAssesses SOC 2 Type I or II audit readiness for specified scope (security, availability, confidentiality, processing integrity, privacy), producing readiness scores, control gaps, evidence requirements, remediation recommendations, and timeline.
/assessAssesses ISMS compliance against ISO 27001:2022 clauses and Annex A controls, producing status reports, gap analysis, Statement of Applicability guidance, and certification readiness.