GRC & Compliance

Analyze governance, risk, and compliance requirements into scored risk registers and control mappings.

4|Updated Mar 10, 2026
One-click install
npx skills add https://github.com/GhostPWN/ghostpwn --skill grc-compliance-ghostpwn
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: GRC & Compliance
Source: https://github.com/GhostPWN/ghostpwn/tree/main/src/skills/19-grc-compliance
Command: npx skills add https://github.com/GhostPWN/ghostpwn --skill grc-compliance-ghostpwn

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires pyyaml, and includes scripts (resource) components.

What problem does it solve?

It helps teams turn scattered governance, risk, and compliance requirements into actionable analysis, reusable control mappings, and clear remediation plans.

Core Features & Use Cases

  • Risk assessment and scoring: Rank risks by likelihood, impact, control effectiveness, and treatment priority.
  • Cross-framework control mapping: Reuse one control across NIST CSF 2.0, ISO 27001:2022, SOC 2, CIS Controls v8, PCI DSS 4.0, and NIST SP 800-53.
  • Audit readiness and evidence work: Build gap analyses, statements of applicability, control narratives, and evidence indexes.
  • Policy drafting: Generate security policies and standards for access, incident response, vendor risk, and related program areas.
  • Use case: A security lead can assess a new web application, map existing controls to multiple frameworks, and produce a prioritized remediation roadmap for an upcoming audit.

Quick Start

Ask the GRC and Compliance skill to assess your current controls against a target framework and produce a risk register, gap analysis, and remediation plan.

Frequently Asked Questions about GRC & Compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map controls across NIST CSF 2.0, ISO 27001, and SOC 2 frameworks?

Cross-framework control mapping reuses a single control across NIST CSF 2.0, ISO 27001:2022, and SOC 2 using Python-based mapping utilities to generate unified control inventories and gap analyses.

What is the best way to build a risk register and score risks for audit readiness?

Building a risk register for audit readiness involves analyzing structured risk inputs to rank risks by likelihood, impact, and control effectiveness, producing a prioritized remediation roadmap.

Can I generate statements of applicability and control narratives for ISO 27001?

Yes, you can generate ISO 27001 statements of applicability and control narratives by analyzing control inventories and evidence references to identify gaps and document security program design.

Do I need structured inputs to perform a vendor risk review and policy drafting?

Yes, vendor risk reviews and policy drafting require structured risk inputs and control inventories to produce accurate security policies, standards, and prioritized treatment plans.

How does cross-framework control mapping handle PCI DSS 4.0 and NIST SP 800-53?

Cross-framework control mapping analyzes existing controls to align with PCI DSS 4.0 and NIST SP 800-53 requirements, generating reusable mappings and evidence indexes for compliance reporting.

What limitations exist when using Python scripts for compliance gap analysis?

Compliance gap analysis using Python scripts requires structured risk inputs and evidence references; unstructured documentation or missing control inventories will prevent accurate scoring and ranked outputs.