audit-frameworks

Audit Cartography rules for TODOs, duplicates, and cross-provider clusters.

4.0k|550|Updated Feb 27, 2019
One-click install
npx skills add https://github.com/cartography-cncf/cartography --skill audit-frameworks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: audit-frameworks
Source: https://github.com/cartography-cncf/cartography/tree/main/.agents/skills/audit-frameworks
Command: npx skills add https://github.com/cartography-cncf/cartography --skill audit-frameworks

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audits and surfaces TODOs, cross-provider rule clusters, and duplicate detections across the Cartography rule set, helping teams improve consistency and compliance.

Core Features & Use Cases

  • TODO triage of rules, ontology collapse candidates, and duplicate detection, plus consolidation planning across CIS, NIST, ISO 27001, and SOC 2.
  • Cross-provider ontology alignment, identification of duplicate rules, and actionable recommendations for governance.
  • Use Case: When teams need to align multiple compliance frameworks with a single rule, speeding reporting and audits.

Quick Start

Run the audit framework to generate a consolidated report on the current Cartography rules and proposed frameworks.

Frequently Asked Questions about audit-frameworks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect duplicate rules across different cloud providers in Cartography?

Audit Cartography rules to identify cross-provider duplicate detections and ontology collapse candidates. The audit analyzes the complete rule base to surface overlapping rules and generate actionable consolidation guidance for governance.

What's the best way to align Cartography rules with CIS, NIST, ISO 27001, and SOC 2 frameworks?

Apply the audit framework to map Cartography rules across CIS, NIST, ISO 27001, and SOC 2 compliance frameworks. It identifies ontology opportunities and provider mappings to consolidate multiple frameworks with a single rule set.

How do I triage TODOs in Cartography compliance rules?

Run the audit tool against cartography/rules and the schema mapping to surface TODOs within the rule set. It generates a consolidated report highlighting triage candidates and proposed framework alignments.

Do I need access to the schema mapping to audit Cartography rules?

Yes, the audit tool requires access to both cartography/rules and the schema mapping to function. These inputs allow it to generate actionable consolidation guidance and identify ontology opportunities.

Can I consolidate multiple compliance frameworks into a single Cartography rule?

Yes, the audit identifies cross-provider ontology alignment and duplicate rules to help teams map multiple compliance frameworks to a single rule. This speeds up compliance reporting and audit processes.

Why does my Cartography rule audit show cross-provider rule clusters?

Cross-provider rule clusters appear when the audit surfaces overlapping rules across different cloud providers. Identifying these clusters helps improve consistency and provides actionable recommendations for governance consolidation.