What problem does it solve?
This Skill helps you prepare data platform and infrastructure controls for SOC2 Type II, GDPR, PCI-DSS scope reduction, and CIS Benchmark assessments by turning compliance expectations into actionable mappings, checklists, and repeatable evidence collection steps.
Core Features & Use Cases
- Framework control mapping (SOC2 Type II): Provides control-to-implementation guidance across access control, threat protection, monitoring, and change management with concrete evidence examples.
- GDPR PII handling: Supports building a PII inventory, planning encryption/masking coverage, and implementing right-to-erasure workflows with auditable logging.
- Security and audit evidence completeness: Covers CIS Kubernetes benchmark automation, audit log completeness verification (Vault/Kubernetes/cloud trail), and encryption at rest/in transit evidence.
- Compliance as code: Includes example OPA/Rego policies to enforce retention and encryption annotations and reduce compliance drift.
- Vulnerability management guardrails: Provides CVE response SLA guidance and CI scanning criteria to block critical issues.
Quick Start
Use the infra-compliance-readiness skill to map your current Kubernetes/Vault/cloud configurations to SOC2 Type II control expectations and produce an audit-ready evidence plan.