security-compliance

Guide security professionals through compliance frameworks and threat modeling.

2|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/daeha76/RianFriends --skill security-compliance-daeha76
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-compliance
Source: https://github.com/daeha76/RianFriends/tree/main/.claude/commands/security-compliance
Command: npx skills add https://github.com/daeha76/RianFriends --skill security-compliance-daeha76

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and examples (resource) components.

What problem does it solve?

This Skill empowers security professionals to navigate complex security challenges, from implementing robust architectures and achieving compliance to managing incidents and embedding security throughout the development lifecycle.

Core Features & Use Cases

  • Security Architecture: Design and implement defense-in-depth and Zero Trust architectures.
  • Compliance Management: Achieve and maintain compliance with frameworks like SOC 2, ISO 27001, GDPR, and HIPAA.
  • Risk Assessment & Threat Modeling: Conduct thorough risk assessments and threat modeling using STRIDE, PASTA, and quantitative/qualitative analysis.
  • Incident Response: Develop and execute effective incident response plans and playbooks.
  • Application Security: Integrate security into the SDLC and secure APIs and containers.
  • Use Case: A company needs to prepare for a SOC 2 Type II audit. This Skill provides a detailed roadmap, control examples, and evidence collection strategies to guide them through the process.

Quick Start

Use the security-compliance skill to generate a SOC 2 Type II audit readiness roadmap.

Frequently Asked Questions about security-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for a SOC 2 Type II audit and collect the right evidence?

Preparing for a SOC 2 Type II audit requires a detailed roadmap of control examples and evidence collection strategies. This ensures your security operations align with trust service criteria and facilitates a successful compliance review.

What is the best way to conduct threat modeling using STRIDE or PASTA methodologies?

Conducting threat modeling with STRIDE or PASTA involves systematically identifying vulnerabilities across your architecture. These methodologies provide structured frameworks to analyze security risks, quantify potential impact, and integrate mitigations into the software development lifecycle.

How do I build an incident response playbook for security operations?

Building an incident response playbook requires defining structured procedures for detecting, containing, and eradicating security threats. Effective playbooks guide your security operations team through vulnerability management and ensure systematic recovery during a breach.

Can I design a Zero Trust architecture and still maintain ISO 27001 compliance?

Yes, designing a Zero Trust architecture directly supports maintaining ISO 27001 compliance. Zero Trust principles enforce strict access controls and defense-in-depth, directly supporting the risk management controls and security requirements mandated by the ISO framework.

How do I integrate security into the SDLC for securing APIs and containers?

Integrating security into the SDLC for APIs and containers requires embedding threat modeling and vulnerability management early in development. This approach ensures continuous risk assessment and automated security checks throughout the application security workflow.