pbmm-expert

Analyze cloud deployments for PBMM compliance with ITSG-33 and CCCS requirements.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill pbmm-expert-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pbmm-expert
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/frameworks/pbmm/skills/pbmm-expert
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill pbmm-expert-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Helps organizations achieve PBMM compliance for Government of Canada cloud workloads by aligning with ITSG-33 and CCCS requirements.

Core Features & Use Cases

  • PBMM Data Residency: enforce Canadian regions across AWS, Azure, and GCP
  • Access control, MFA enforcement, and auditability aligned with ITSG-33 controls
  • Incident response planning, backup/recovery, and evidence-ready documentation for CCCS assessments

Quick Start

Map PBMM controls to your cloud resources and begin implementing the recommended Canadian residency, MFA, encryption, and incident response configurations.

Frequently Asked Questions about pbmm-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I achieve PBMM compliance for Government of Canada workloads in the cloud?

Achieve PBMM compliance by aligning your cloud deployments with ITSG-33 controls and CCCS requirements. This Skill maps Protected B controls to platform configurations across AWS, Azure, and GCP Canada, covering encryption, access, and incident response.

Does this tool support enforcing data residency in Canadian cloud regions across multiple providers?

Yes, it supports data residency by enforcing Canadian regions across AWS Canada, Azure Canada, and GCP Canada. It maps PBMM data residency requirements to platform-specific configurations to ensure Protected B data remains within Canada.

How do I map ITSG-33 controls to cloud platform configurations for a CCCS assessment?

Map ITSG-33 controls by using this Skill to translate security requirements into specific platform configurations for identity, access, encryption, and logging. It provides implementation guidance and generates evidence artifacts for CCCS cloud security assessments.

What is needed to configure MFA and access control for Protected B data in Canadian cloud environments?

Configuring MFA and access control for Protected B data requires aligning with ITSG-33 auditability requirements. This Skill guides MFA enforcement and access configurations across AWS, Azure, and GCP Canada to meet PBMM standards.

Can I generate evidence-ready documentation for incident response planning in a PBMM compliant deployment?

Yes, you can generate evidence-ready documentation for incident response planning. This Skill provides guidance on backup, recovery, and incident response configurations, producing artifacts needed to support CCCS cloud security assessments.

What is the best way to prepare for a CCCS cloud security assessment for Protected B workloads?

Prepare for a CCCS assessment by mapping PBMM controls to your cloud resources and implementing recommended Canadian residency, MFA, encryption, and incident response configurations. This generates the necessary evidence artifacts for review.