security-compliance

Document security controls and compliance evidence for regulatory frameworks.

5|Updated Jul 6, 2025
One-click install
npx skills add https://github.com/GuicedEE/ai-rules --skill security-compliance-guicedee
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-compliance
Source: https://github.com/GuicedEE/ai-rules/tree/main/skills/.curated/security-compliance
Command: npx skills add https://github.com/GuicedEE/ai-rules --skill security-compliance-guicedee

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security teams design defense-in-depth controls, perform threat modeling and risk assessments, and map mitigations to frameworks (SOC2/ISO27001/GDPR/HIPAA) to produce testable compliance evidence.

Core Features & Use Cases

  • Threat-model templates and lightweight risk assessment guidance for system design.
  • Pragmatic control checklists mapped to data flows and trust boundaries.
  • Evidence inventory and artifacts guidance for audits and certifications.
  • Use Case: When shipping sensitive features, run a quick threat-modeling session and assemble required artifacts.

Quick Start

Start by scaffolding a lightweight threat model for your system and populate the control checklist and evidence list.

Frequently Asked Questions about security-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a lightweight threat model for system design?

A lightweight threat model for system design is created by identifying defense-in-depth controls and documenting data flows alongside trust boundaries. This process generates a pragmatic control checklist mapped directly to your architecture.

What is the best way to map security controls to SOC2 and ISO27001 frameworks?

Mapping security controls to SOC2 and ISO27001 frameworks involves linking your documented defense-in-depth mitigations to specific regulatory standards. This produces a testable evidence inventory required for audits and certifications.

How do I generate compliance evidence for GDPR and HIPAA audits?

Generating compliance evidence for GDPR and HIPAA audits requires assembling an evidence inventory that links your system design mitigations to regulatory frameworks. This provides testable artifacts for certification reviews.

Can I perform a risk assessment during a system design review?

Yes, you can perform a risk assessment during a system design review by applying threat-model templates to identify vulnerabilities. This yields a documented assessment of threats and a pragmatic control checklist.

What is defense-in-depth control documentation for sensitive features?

Defense-in-depth control documentation for sensitive features identifies multiple security layers across your services and data flows. It produces a pragmatic checklist mapping mitigations to frameworks like SOC2 and HIPAA.

When do I need a compliance evidence inventory for my data flows?

You need a compliance evidence inventory for your data flows when preparing for audits or shipping sensitive features. It links your documented security controls to specific regulatory frameworks to ensure testable compliance.