What problem does it solve?
Legacy security and compliance frameworks (NIST 800-53, ISO 27001, SOC 2) were designed for on-prem and early-cloud environments, and fail to address mid-2026 threats including cloud control plane abuse, workload identity federation misconfigurations, AI workload egress risks, and shared responsibility ambiguity for managed AI services. This skill bridges that gap with threat-informed, cloud-native guidance aligned to current attack patterns.
Core Features & Use Cases
- Threat-informed TTP mapping: Maps cloud and AI workload attack techniques from MITRE ATT&CK and ATLAS to real-world mid-2026 incident patterns, including federation trust-policy abuse, IMDSv1 SSRF, and AI model registry tampering.
- Compliance gap analysis: Explicitly flags where legacy framework controls are insufficient for modern cloud and AI workloads, with cross-jurisdiction coverage for NIS2, DORA, NYDFS 500, and 30+ regional regulations.
- Layered defense guidance: Provides actionable steps for implementing CSPM drift detection, CIEM least-privilege IAM, eBPF runtime security, egress controls, and encryption tailored to ephemeral cloud-native and AI workloads.
- Use Case: A cloud security engineer can use this skill to audit AWS IRSA trust policies for confused-deputy risks, map findings to NIST 800-53 and CSA CCM gaps, and generate evidence for a SOC 2 audit.
Quick Start
Use the cloud-security skill to audit your cloud workload identity federation policies for confused-deputy risks and generate a compliance gap report for NIST 800-53 and CSA CCM v4.