What problem does it solve?
Manually creating consistent, compliant control catalogs for cloud services to meet FINOS Common Cloud Controls (CCC) standards is time-consuming, error-prone, and requires deep knowledge of regulatory frameworks and cloud service capabilities. This Skill automates the end-to-end process of generating valid, schema-compliant controls.yaml files for cloud services.
Core Features & Use Cases
- Core Control Reuse: Automatically imports applicable pre-defined CCC core controls to avoid duplication and ensure consistency across service catalogs.
- Service-Specific Control Generation: Creates granular, provider-neutral service-specific controls mapped directly to identified threats for the target cloud service, aligned to recognized regulatory frameworks.
- Schema Validation: Ensures all generated controls include testable assessment requirements, correct threat mappings, and valid guideline references that pass the official CCC controls schema.
- Use Case: A cloud security engineer onboarding a new cloud storage service to the CCC standard can use this Skill to generate a complete, validated controls.yaml file in minutes instead of building it manually from scratch.
Quick Start
Use the build-control-catalog skill to generate a valid controls.yaml file for your target cloud service by providing the path to its catalog directory.