security-compliance

Codify security policies, risk assessments, threat modeling, and incident response for compliance programs.

1|Updated Apr 9, 2026
One-click install
npx skills add https://github.com/hbvg234/jnmt.vn --skill security-compliance-hbvg234
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-compliance
Source: https://github.com/hbvg234/jnmt.vn/tree/main/.claude/skills/security-compliance
Command: npx skills add https://github.com/hbvg234/jnmt.vn --skill security-compliance-hbvg234

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security and compliance programs are complex and siloed, making risk assessments, threat modeling, and audits slow and error-prone.

Core Features & Use Cases

  • Defense-in-Depth planning: Guide multi-layer security architectures.
  • Threat modeling & risk assessments: Provide templates and checklists for STRIDE/PASTA analyses.
  • Compliance mapping & governance: Align to SOC2, ISO27001, GDPR, HIPAA, and incident response lifecycle.
  • Audit-ready artifacts: Deliver runbooks, risk registers, control matrices, and policy docs.
  • Use Case: For a mid-size SaaS, apply the lifecycle to reach audit readiness and continuous security improvement.

Quick Start

Provide a complete security and compliance plan for your organization aligned with SOC2, ISO27001, GDPR, and HIPAA.

Frequently Asked Questions about security-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a SOC2 or ISO27001 compliance program from scratch?

SOC2 and ISO27001 compliance programs are built by codifying policies, generating risk registers, mapping security control matrices, and defining incident response lifecycles to achieve audit readiness.

What is the best way to perform STRIDE or PASTA threat modeling for my application?

STRIDE and PASTA threat modeling is performed by generating structured threat models, data flow diagrams, and attack trees to identify risks across defense-in-depth architectures throughout the SDLC.

Can I use this for GDPR and HIPAA compliance mapping in a SaaS environment?

GDPR and HIPAA compliance mapping is supported for SaaS environments by aligning security governance policies, encryption designs, and IAM models to regulatory requirements and audit deliverables.

How do I create audit-ready risk registers and security control matrices?

Audit-ready risk registers and security control matrices are created by codifying risk assessments, governance policies, and incident response runbooks into structured documentation for SOC2 or ISO27001 audits.

Does this help with encryption, key management, and IAM design?

Encryption, key management, and IAM models are supported by providing structured designs and templates that align with defense-in-depth architectures and multi-layer security governance requirements.