How this command is triggered — by the user, by Claude, or both
Slash command
/pbmm:cccs-guidanceFiles this command reads when invoked
The summary Claude sees in its command listing — used to decide when to auto-load this command
# CCCS Assessment Guidance Guidance on the Canadian Centre for Cyber Security (CCCS) cloud security assessment process and certified cloud service providers. ## Arguments - `$1` - Topic (optional: process, providers, requirements) - defaults to "process" ## CCCS Assessment Process ### ITSM.50.100 Cloud Security Assessment The CCCS assesses cloud service providers against the ITSP.50.103 Cloud Security Categorization framework. **Assessment Tiers**: - **Tier 1**: Self-assessment by CSP - **Tier 2**: Independent third-party assessment - **Tier 3**: CCCS assessment (for Protected B and...
Guidance on the Canadian Centre for Cyber Security (CCCS) cloud security assessment process and certified cloud service providers.
$1 - Topic (optional: process, providers, requirements) - defaults to "process"The CCCS assesses cloud service providers against the ITSP.50.103 Cloud Security Categorization framework.
Assessment Tiers:
Organization Activities:
Required Documentation:
Submission to CCCS:
CCCS Review:
Assessment Activities:
Evidence Requirements:
For Identified Gaps:
POA&M:
CCCS Deliverables:
Validity Period: 2 years (re-assessment required)
| Item | Estimated Cost (CAD) | Notes |
|---|---|---|
| Pre-assessment consulting | $50,000 - $150,000 | Gap analysis, SSP development |
| Third-party assessment | $100,000 - $250,000 | CCCS Tier 2 assessment |
| Remediation | $50,000 - $200,000 | Depends on gaps |
| CCCS assessment fee | Varies | For Tier 3 assessments |
| Annual maintenance | $25,000 - $75,000 | Continuous monitoring |
| Re-assessment (2 years) | $75,000 - $150,000 | Reduced scope |
Certification Status: ✅ ITSM.50.100 Assessed
Canadian Regions:
Services Assessed:
PBMM Features:
Contact: AWS Canada Public Sector team
Certification Status: ✅ PBMM Assessed
Canadian Regions:
Services Assessed:
PBMM Features:
Contact: Microsoft Canada Public Sector
Certification Status: ⚠️ Assessment In Progress (verify current status)
Canadian Regions:
Services:
PBMM Features:
Contact: Google Cloud Canada team
Note: Verify current CCCS certification status before use
| Control ID | Control Name | CCCS Requirement |
|---|---|---|
| PBMM-DATA-1 | Canadian Data Residency | All data in CA regions only |
| PBMM-AC-1 | Access Control Policy | Documented, enforced |
| PBMM-AC-2 | Multi-Factor Authentication | Mandatory for all users |
| PBMM-AU-1 | Audit and Accountability | 2-year log retention |
| PBMM-SC-1 | Encryption at Rest | FIPS 140-2 Level 2+ |
| PBMM-SC-2 | Encryption in Transit | TLS 1.2+ with FIPS |
| PBMM-SC-3 | Network Segmentation | VPC/VNet isolation |
| PBMM-RA-1 | Vulnerability Management | 48-hour critical patching |
| PBMM-IR-1 | Incident Response | CCCS notification process |
| PBMM-CP-1 | Backup and Recovery | Canadian region backups |
Monthly Reporting:
Quarterly Reviews:
Annual Activities:
Incident Reporting:
ITSG-33: IT Security Risk Management - A Lifecycle Approach
ITSP.50.103: Cloud Security Categorization
ITSM.50.100: Cloud Security Assessment
Medium Cloud Security Profile:
Canadian Centre for Cyber Security (CCCS):
Cloud Assessment Inquiries:
Incident Reporting:
# View assessment process
/pbmm:cccs-guidance process
# Check certified providers
/pbmm:cccs-guidance providers
# Review certification requirements
/pbmm:cccs-guidance requirements
Q: How long does CCCS assessment take? A: 6-12 months total (pre-assessment through certification)
Q: Can I use US cloud regions for Protected B? A: No, Canadian regions mandatory for Protected B
Q: Is CCCS assessment required for all Protected B systems? A: Strongly recommended, may be required by contract or regulation
Q: How often is re-assessment required? A: Every 2 years for Protected B
Q: What if my cloud provider is not CCCS-certified? A: You can pursue your own CCCS assessment or use certified providers
Q: Are there alternatives to CCCS assessment? A: For non-government, use CCCS-assessed CSPs or conduct independent third-party assessment aligned with ITSG-33
npx claudepluginhub hzmonama/cli-grc-engineering --plugin pbmm/cccs-guidanceProvides CCCS guidance on cloud security assessment process, including tiers, steps for Protected B, documentation, remediation, costs. Optional topic: process, providers, requirements.