pbmm-expert

Map cloud deployments to Government of Canada PBMM controls across AWS, Azure, and GCP.

Updated Apr 25, 2026
One-click install
npx skills add https://github.com/abnejsolutions-alt/GRC --skill pbmm-expert
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pbmm-expert
Source: https://github.com/abnejsolutions-alt/GRC/tree/main/plugins/frameworks/pbmm/skills/pbmm-expert
Command: npx skills add https://github.com/abnejsolutions-alt/GRC --skill pbmm-expert

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

PBMM Expert helps security teams align cloud deployments with Government of Canada PBMM controls.

Core Features & Use Cases

  • Framework mapping and governance for Protected B workloads
  • Cross-cloud residency, MFA enforcement, and encryption controls
  • Use Case: Plan and implement PBMM controls across AWS Canada, Azure Canada, and GCP Canada to meet ITSG-33 and CCCS baselines.

Quick Start

Run a PBMM readiness assessment to map controls to Canadian cloud deployments and generate a residency, encryption, and MFA plan.

Frequently Asked Questions about pbmm-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map ITSG-33 controls to cloud deployments for PBMM compliance?

To achieve PBMM compliance, run a readiness assessment mapping ITSG-33 controls to your AWS, Azure, and GCP deployments. This generates a tailored plan for Canadian data residency, encryption, and MFA enforcement for Protected B workloads.

What are the data residency requirements for Protected B workloads in Canadian clouds?

Protected B workloads require strict Canadian data residency and cross-region residency enforcement. You must configure AWS, Azure, or GCP Canada regions to meet PBMM controls and keep data within sovereign boundaries.

Does PBMM compliance require 2-year log retention and MFA enforcement?

Yes, PBMM compliance requires MFA enforcement and 2-year log retention. You must configure cloud auditing and access controls across your environments to satisfy these specific CCCS baseline and ITSG-33 mapping requirements.

Can I use AWS, Azure, and GCP for Protected B government workloads in Canada?

Yes, you can use AWS Canada, Azure Canada, and GCP Canada for Protected B workloads. You must apply cross-cloud residency, access control, and encryption controls to align deployments with Government of Canada PBMM standards.

What is the best way to plan incident response and backup controls for PBMM?

The best way to plan PBMM incident response and backup controls is to map governance frameworks directly to your cloud architecture. This ensures auditing and backup strategies align with ITSG-33 and CCCS baselines for Protected B workloads.