compliance-drift

Detect drift between declared compliance posture and observed practice across governance frameworks.

Updated Apr 21, 2026
One-click install
npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill compliance-drift
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-drift
Source: https://github.com/brucebanner010198-commits/DevSecOps-Agency/tree/main/skills/compliance-drift
Command: npx skills add https://github.com/brucebanner010198-commits/DevSecOps-Agency --skill compliance-drift

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Detect drift between declared compliance posture (SOC 2, GDPR, HIPAA, state privacy) and observed practice. Runs monthly + on-demand when CLO flags an incoming audit. Drift = early warning; breach = finding. Both get reported. Owned by compliance-drift specialist on the Legal Council.

Core Features & Use Cases

  • Monthly cadence across all active compliance frameworks.
  • On-demand when CLO hears of an incoming audit.
  • After any incident that may have exposed a control, such as a secrets leak, or during portfolio audits.
  • Quarterly paired with CAO's portfolio audit.

Quick Start

Run a drift check for a chosen framework to surface deviations and trigger remediation tasks.

Frequently Asked Questions about compliance-drift

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is compliance drift detection and how does it help with audit readiness?

Compliance drift detection identifies gaps between your declared compliance posture for frameworks like SOC 2 and GDPR and actual observed practices. It serves as an early warning system before audits by surfacing deviations, pinning rubrics, gathering evidence, and creating remediation tasks.

How do I detect compliance posture deviations before an incoming audit?

You can detect compliance posture deviations on-demand by running a drift check when a CLO flags an incoming audit. This initiates a targeted scan across your active frameworks to identify breaches, pin required rubrics, gather evidence, and generate remediation tasks.

When should I run compliance drift checks across governance frameworks?

You should run compliance drift checks monthly across all active frameworks, on-demand when the CLO flags an incoming audit, after incidents like secrets leaks, and quarterly when paired with portfolio audits to ensure continuous governance posture alignment.

Can I use compliance drift detection for state privacy frameworks like SOC 2 and GDPR?

Yes, compliance drift detection actively supports SOC 2, GDPR, HIPAA, and state privacy frameworks. It evaluates declared compliance postures against observed practices across these active governance frameworks to identify drift and generate remediation tasks.

What is the difference between compliance drift and a compliance breach?

Compliance drift represents an early warning deviation between declared posture and observed practice, whereas a breach constitutes an actual finding. Both drift and breach results are reported, and both trigger the creation of remediation tasks to resolve the gap.

How do I remediate compliance drift after a security incident?

To remediate compliance drift after an incident like a secrets leak, run an on-demand drift check to evaluate exposed controls. The system will pin rubrics, gather evidence, and automatically create remediation tasks for any detected drift or breach.