build-control-catalog

Generate schema-valid FINOS CCC controls.yaml files for cloud services.

85|80|Updated Jul 26, 2023
One-click install
npx skills add https://github.com/finos/common-cloud-controls --skill build-control-catalog
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: build-control-catalog
Source: https://github.com/finos/common-cloud-controls/tree/main/skills/build-control-catalog
Command: npx skills add https://github.com/finos/common-cloud-controls --skill build-control-catalog

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Manually creating consistent, compliant control catalogs for cloud services to meet FINOS Common Cloud Controls (CCC) standards is time-consuming, error-prone, and requires deep knowledge of regulatory frameworks and cloud service capabilities. This Skill automates the end-to-end process of generating valid, schema-compliant controls.yaml files for cloud services.

Core Features & Use Cases

  • Core Control Reuse: Automatically imports applicable pre-defined CCC core controls to avoid duplication and ensure consistency across service catalogs.
  • Service-Specific Control Generation: Creates granular, provider-neutral service-specific controls mapped directly to identified threats for the target cloud service, aligned to recognized regulatory frameworks.
  • Schema Validation: Ensures all generated controls include testable assessment requirements, correct threat mappings, and valid guideline references that pass the official CCC controls schema.
  • Use Case: A cloud security engineer onboarding a new cloud storage service to the CCC standard can use this Skill to generate a complete, validated controls.yaml file in minutes instead of building it manually from scratch.

Quick Start

Use the build-control-catalog skill to generate a valid controls.yaml file for your target cloud service by providing the path to its catalog directory.

Frequently Asked Questions about build-control-catalog

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a FINOS CCC compliant controls.yaml file for a new cloud service?

To generate a FINOS CCC compliant controls.yaml file, map service-specific controls to identified threats and import reusable core controls. This process ensures all outputs validate against the official CCC controls schema, eliminating manual control definition work for cloud services.

What prerequisite files are needed to build a cloud control catalog mapped to regulatory frameworks?

Building a cloud control catalog requires prerequisite metadata, capabilities, and threats files for the target service. These input files enable the generation of service-specific controls mapped to regulatory frameworks like NIST 800-53, DORA, and CRI.

How does control mapping to recognized regulatory frameworks work for FINOS CCC compliance?

Control mapping for FINOS CCC compliance works by generating provider-neutral service-specific controls mapped directly to identified threats. These controls are aligned to recognized regulatory frameworks including NIST 800-53, DORA, and CRI, producing testable assessment requirements.

Can I reuse pre-defined CCC core controls when onboarding multiple cloud services?

Yes, you can reuse pre-defined CCC core controls when onboarding multiple cloud services. The catalog generation process automatically imports applicable core controls to avoid duplication and ensure consistency across service catalogs while maintaining schema validation.

What is the best way to validate cloud controls against the official CCC controls schema?

The best way to validate cloud controls against the official CCC controls schema is to generate controls that include testable assessment requirements, correct threat mappings, and valid guideline references. This ensures all outputs pass official schema validation for FINOS CCC compliance.

Does the FINOS CCC control catalog generation support TLP applicability levels for assessment requirements?

Yes, FINOS CCC control catalog generation supports TLP applicability levels. It produces testable assessment requirements with TLP applicability levels specified, ensuring the generated controls.yaml file meets the full compliance catalog schema validation requirements.