infra-compliance-readiness

Map Kubernetes and cloud data platform controls to SOC2 Type II and GDPR compliance evidence.

14|1|Updated May 5, 2026
One-click install
npx skills add https://github.com/ivanshamaev/de-agent-skills --skill infra-compliance-readiness
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: infra-compliance-readiness
Source: https://github.com/ivanshamaev/de-agent-skills/tree/main/group_skills/infra_dataops_group_skills/infra_compliance_readiness
Command: npx skills add https://github.com/ivanshamaev/de-agent-skills --skill infra-compliance-readiness

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you prepare data platform and infrastructure controls for SOC2 Type II, GDPR, PCI-DSS scope reduction, and CIS Benchmark assessments by turning compliance expectations into actionable mappings, checklists, and repeatable evidence collection steps.

Core Features & Use Cases

  • Framework control mapping (SOC2 Type II): Provides control-to-implementation guidance across access control, threat protection, monitoring, and change management with concrete evidence examples.
  • GDPR PII handling: Supports building a PII inventory, planning encryption/masking coverage, and implementing right-to-erasure workflows with auditable logging.
  • Security and audit evidence completeness: Covers CIS Kubernetes benchmark automation, audit log completeness verification (Vault/Kubernetes/cloud trail), and encryption at rest/in transit evidence.
  • Compliance as code: Includes example OPA/Rego policies to enforce retention and encryption annotations and reduce compliance drift.
  • Vulnerability management guardrails: Provides CVE response SLA guidance and CI scanning criteria to block critical issues.

Quick Start

Use the infra-compliance-readiness skill to map your current Kubernetes/Vault/cloud configurations to SOC2 Type II control expectations and produce an audit-ready evidence plan.

Frequently Asked Questions about infra-compliance-readiness

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate audit-ready evidence for SOC2 Type II compliance in Kubernetes?

Generate audit-ready evidence for SOC2 Type II by mapping Kubernetes security controls to access management, monitoring, and change management requirements, producing concrete checklists and repeatable evidence collection steps for your data platform.

What is the best way to build a GDPR PII inventory and right-to-erasure workflow?

Building a GDPR PII inventory involves mapping data platform assets to PII requirements, planning encryption or masking coverage, and defining right-to-erasure workflows with auditable logging to ensure compliance readiness.

How do I enforce compliance-as-code using OPA and Rego policies?

Enforce compliance-as-code by implementing OPA and Rego guardrail policies to verify retention and encryption annotations, reducing compliance drift across Kubernetes and cloud-based data systems automatically.

Can I use CIS Kubernetes benchmarks to automate infrastructure hardening checks?

Yes, CIS Kubernetes benchmark automation checks infrastructure configurations against established security standards, verifying audit log completeness for Vault and cloud trails while validating encryption at rest and in transit.

How do I set vulnerability management guardrails and CVE response SLAs for CI scanning?

Set vulnerability management guardrails by defining CVE response SLA guidance and establishing CI scanning criteria to block critical issues, ensuring infrastructure hardening and continuous compliance for data platforms.