pbmm-expert

Map cloud deployments to Government of Canada PBMM controls across AWS, Azure, and GCP.

Updated Apr 25, 2026
One-click install
npx skills add https://github.com/abnejsolutions-alt/GRC --skill pbmm-expert
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: pbmm-expert
Source: https://github.com/abnejsolutions-alt/GRC/tree/main/plugins/frameworks/pbmm/skills/pbmm-expert
Command: npx skills add https://github.com/abnejsolutions-alt/GRC --skill pbmm-expert

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

PBMM Expert helps security teams align cloud deployments with Government of Canada PBMM controls.

Core Features & Use Cases

  • Framework mapping and governance for Protected B workloads
  • Cross-cloud residency, MFA enforcement, and encryption controls
  • Use Case: Plan and implement PBMM controls across AWS Canada, Azure Canada, and GCP Canada to meet ITSG-33 and CCCS baselines.

Quick Start

Run a PBMM readiness assessment to map controls to Canadian cloud deployments and generate a residency, encryption, and MFA plan.

Frequently Asked Questions about pbmm-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map ITSG-33 controls to cloud deployments for PBMM compliance?▼

To achieve PBMM compliance, run a readiness assessment mapping ITSG-33 controls to your AWS, Azure, and GCP deployments. This generates a tailored plan for Canadian data residency, encryption, and MFA enforcement for Protected B workloads.

What are the data residency requirements for Protected B workloads in Canadian clouds?▼

Protected B workloads require strict Canadian data residency and cross-region residency enforcement. You must configure AWS, Azure, or GCP Canada regions to meet PBMM controls and keep data within sovereign boundaries.

Does PBMM compliance require 2-year log retention and MFA enforcement?▼

Yes, PBMM compliance requires MFA enforcement and 2-year log retention. You must configure cloud auditing and access controls across your environments to satisfy these specific CCCS baseline and ITSG-33 mapping requirements.

Can I use AWS, Azure, and GCP for Protected B government workloads in Canada?▼

Yes, you can use AWS Canada, Azure Canada, and GCP Canada for Protected B workloads. You must apply cross-cloud residency, access control, and encryption controls to align deployments with Government of Canada PBMM standards.

What is the best way to plan incident response and backup controls for PBMM?▼

The best way to plan PBMM incident response and backup controls is to map governance frameworks directly to your cloud architecture. This ensures auditing and backup strategies align with ITSG-33 and CCCS baselines for Protected B workloads.