What problem does it solve? Auditors and security teams struggle to connect firewall configurations to SOC 2 Trust Services Criteria, often overclaiming compliance or missing Type II operating-effectiveness evidence. This Skill provides a structured control-to-evidence mapping so firewall estates can be assessed accurately for SOC 2 examinations. ## Core Features & Use Cases - Control Mapping: Maps NGFW features and rules to Trust Services Criteria such as CC6.1, CC6.6, CC7.2, and CC8.1, plus Availability, Confidentiality, and Privacy categories. - Assessment Workflow: Guides a five-step process from establishing scope and control matrix through validating Type II operating effectiveness with sampled evidence. - Evidence Markers: Provides safe description/tag patterns for firewall configs that point auditors to control IDs without exposing sensitive data. - Use Case: A SaaS company preparing for a SOC 2 Type II audit uses this Skill to review its Palo Alto rulebase, map each rule to control IDs, identify gaps in change-management evidence, and produce an auditor-ready findings report. ## Quick Start Use the soc2-ngfw-compliance skill to assess this firewall configuration export against SOC 2 Trust Services Criteria and list the evidence gaps.