compliance-review

Assess systems for regulatory compliance and identify missing technical controls.

7|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/camilooscargbaptista/cto-toolkit --skill compliance-review-camilooscargbaptista
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-review
Source: https://github.com/camilooscargbaptista/cto-toolkit/tree/main/compliance-review
Command: npx skills add https://github.com/camilooscargbaptista/cto-toolkit --skill compliance-review-camilooscargbaptista

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Translates regulatory frameworks into concrete technical controls and audit-ready evidence so engineering teams can prove compliance and remediate gaps before an external audit.

Core Features & Use Cases

  • Framework mappings: Detailed checklists and control mappings for SOC2, GDPR/LGPD, PCI-DSS, and HIPAA to translate legal requirements into engineering tasks.
  • Technical controls review: Coverage of access control, audit logging, encryption, change management, and incident response with prioritized findings.
  • Evidence & templates: Prebuilt SOC2 evidence templates, LGPD implementation guidance, and artifact lists to accelerate audit preparation.
  • Use cases: pre-audit readiness assessments, vendor and third-party reviews, privacy impact assessments (DPIA), and compliance remediation planning.

Quick Start

Run a compliance assessment for SOC2 and GDPR focusing on access control, audit logging, encryption, and produce a prioritized remediation roadmap.

Frequently Asked Questions about compliance-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC2 audit and identify missing technical controls?

A pre-audit readiness assessment evaluates access control, audit logging, encryption, and change management against SOC2 and GDPR checklists to identify missing technical controls and produce a prioritized remediation roadmap with required documentation.

What technical controls are required for GDPR and LGPD compliance?

GDPR and LGPD compliance requires technical controls across access control, audit logging, encryption, and incident response. Assessing these areas against framework mappings translates privacy requirements into engineering tasks and yields implementation guidance for evidence.

Can I use one assessment for both HIPAA and PCI-DSS remediation planning?

Yes, a single compliance assessment can evaluate systems across both HIPAA and PCI-DSS, identifying missing technical controls and producing a unified, prioritized remediation roadmap with the required documentation and evidence artifacts for both frameworks.

What is the best way to conduct a vendor security and privacy impact assessment?

The best way to conduct a vendor assessment is to review the third party's access control, audit logging, and encryption controls against regulatory frameworks like SOC2 and GDPR, producing a prioritized findings report for compliance remediation.

Do I need prebuilt evidence templates for a compliance gap analysis?

Prebuilt evidence templates accelerate compliance gap analysis by providing standardized artifact lists and SOC2 documentation structures, ensuring engineering teams can quickly prove compliance and remediate gaps before an external audit occurs.