What problem does it solve?
Legacy security and compliance frameworks including NIST 800-53, ISO 27001, PCI DSS, and NIS2 were written for network-centric on-prem or early-cloud environments, with controls that do not accommodate modern architectural realities like ephemeral serverless compute, AI pipelines, zero trust architecture, and no-reboot patching requirements. This gap forces organizations to either make false compliance claims or block valid, secure architectural upgrades entirely.
Core Features & Use Cases
- Defensible Exception Templates: Pre-built, auditor-ready exception templates for common framework control gaps, including ephemeral infrastructure asset inventory, externally managed LLM change management, zero trust network segmentation, and critical system no-reboot kernel patching.
- Threat-Aligned Compensating Controls: Maps residual risks to MITRE ATLAS and ATT&CK TTPs, and ties compensating control requirements to real-world exploit availability (RWEP) scoring to eliminate compliance theater.
- Multi-Framework Support: Templates and gap declarations aligned to NIST, ISO 27001, PCI DSS, NIS2, EU DORA, EU AI Act, UK NCSC CAF, AU ASD Essential 8, and other global regulatory regimes.
- Use Case: A team deploying immutable serverless functions can use this skill to produce a valid, defensible exception for NIST 800-53 CM-8 asset inventory controls that assume persistent, individually scannable assets.
Quick Start
Use the policy-exception-gen skill to create a defensible exception request for your serverless workload's NIST 800-53 CM-8 asset inventory control gap.