How this command is triggered — by the user, by Claude, or both
Slash command
/ismap:assessThe summary Claude sees in its command listing — used to decide when to auto-load this command
# ISMAP Assessment Evaluates readiness for Information System Security Management and Assessment Program (ISMAP) compliance for Japanese government cloud services. ## Output file Write the complete assessment as a markdown report to the active workspace: For example, `/ismap:assess iso-mapping` → `grc-reports/ismap-assessment-iso-mapping.md`. Include today's date and assessment scope in the report header. Create the `grc-reports/` directory if it does not exist. ## Arguments - `$1` - Assessment scope (optional: full, iso-mapping, readiness) - defaults to "full" ## ISMAP Overview ...
Evaluates readiness for Information System Security Management and Assessment Program (ISMAP) compliance for Japanese government cloud services.
Write the complete assessment as a markdown report to the active workspace:
grc-reports/ismap-assessment[-{scope}].md
For example, /ismap:assess iso-mapping → grc-reports/ismap-assessment-iso-mapping.md.
Include today's date and assessment scope in the report header. Create the grc-reports/ directory if it does not exist.
$1 - Assessment scope (optional: full, iso-mapping, readiness) - defaults to "full"Authority: Japanese Government Digital Agency Base Standards: ISO/IEC 27001:2013, ISO/IEC 27017:2015, ISO/IEC 27018:2019 Scope: Cloud service providers for Japanese government agencies
| Standard | Focus | Controls |
|---|---|---|
| ISO 27001 | Information Security Management System | 114 controls (Annex A) |
| ISO 27017 | Cloud-specific security | Additional cloud controls (CLD prefix) |
| ISO 27018 | PII protection in cloud | Privacy controls for personal data |
Regions Required: ap-northeast-1 (Tokyo), ap-northeast-3 (Osaka)
/ismap:assess full
/ismap:assess iso-mapping
/assessCompares a local repository against a topic wiki's research body and the broader market, producing a gap analysis with opportunities and competitive landscape.
/assessAssesses DORA compliance readiness for EU financial entities and ICT providers. Requires scope (full, pillar-specific, entity-type); optional entity classification.
/assessAssesses GLBA compliance readiness for specified scope (full, safeguards, privacy, pretexting) and institution type, producing compliance score and detailed evaluation.
/assessAssesses compliance with NIST 800-53 controls for a specified control family (e.g., AC) or baseline (low, moderate, high), with optional revision (r4 or r5).
/assessAssesses SOC 2 Type I or II audit readiness for specified scope (security, availability, confidentiality, processing integrity, privacy), producing readiness scores, control gaps, evidence requirements, remediation recommendations, and timeline.
/assessAssesses ISMS compliance against ISO 27001:2022 clauses and Annex A controls, producing status reports, gap analysis, Statement of Applicability guidance, and certification readiness.
npx claudepluginhub hzmonama/cli-grc-engineering --plugin ismap