compliance-control-foundation

Create a framework-agnostic control catalog for ISO 27001, ISO 42001, and SOC 2.

2|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill compliance-control-foundation
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: compliance-control-foundation
Source: https://github.com/nguyenpv1980-wq/Project-Aegis/tree/main/.claude/skills/compliance-control-foundation
Command: npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill compliance-control-foundation

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill prevents compliance teams from maintaining separate, drifting control lists for ISO 27001, ISO 42001, and SOC 2 by creating one framework-agnostic baseline that can be projected into each standard without duplication.

Core Features & Use Cases

  • Unified control catalog: Defines a single catalog across access control, cryptography, change management, logging and monitoring, incident response, vendor management, risk assessment, and AI governance when needed.
  • Map-don't-rebuild workflow: Reuses shipped mechanisms such as authorization matrices, RLS audits, audit logs, incident runbooks, and supply-chain reviews instead of rewriting them as new controls.
  • Honest compliance status: Records each control with an objective, owner, mechanism, evidence hook, and status such as implemented, partial, or missing so gaps remain visible.
  • Framework-neutral output: Keeps clause and criteria references out of the catalog so projections and crosswalks can evolve independently.
  • Use case: A company preparing for SOC 2 now and ISO 27001 later can use this Skill to produce one baseline control set that both programs consume.

Quick Start

Ask for a framework-neutral common control set for your organization, naming the target frameworks, the catalog owner, and the existing security artifacts you want mapped.

Frequently Asked Questions about compliance-control-foundation

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a unified control baseline for ISO 27001 and SOC 2?▼

A unified control baseline maps your existing security mechanisms across access control, cryptography, and incident response to a single framework-agnostic catalog. This prevents maintaining separate, drifting control lists for ISO 27001, ISO 42001, and SOC 2.

What is the best way to map shipped security mechanisms to compliance controls?▼

The map-don't-rebuild workflow reuses shipped mechanisms like authorization matrices, audit logs, and incident runbooks instead of rewriting them. Each mechanism is mapped to a control with a stable ID, owner, evidence hook, and an implemented, partial, or missing status.

Can I track compliance gaps across multiple frameworks without duplicating controls?▼

Yes, a framework-neutral control catalog keeps clause and criteria references out of the baseline. This allows projections and crosswalks for ISO 27001, ISO 42001, and SOC 2 to evolve independently while maintaining one honest compliance status record.

Do I need separate control sets for AI governance and standard security compliance?▼

No, a single framework-agnostic catalog can span access control, vendor management, risk assessment, and AI governance. This ensures organizations preparing for SOC 2 and ISO 27001 can consume one baseline control set that also covers ISO 42001.

How do I maintain honest compliance status across access control and logging controls?▼

Record each control with its objective, owner, mechanism, evidence hook, and a status of implemented, partial, or missing. Keeping gaps visible across access control, logging, and change management ensures compliance programs reflect actual security posture.

When should I not use a framework-agnostic compliance control catalog?▼

A framework-agnostic catalog may not suit organizations needing only a single framework's specific clause structure embedded directly. It is designed for programs spanning ISO 27001, ISO 42001, and SOC 2 where independent crosswalks are required.