What problem does it solve? Achieving regulatory compliance across multiple frameworks like SOC 2, HIPAA, PCI-DSS, and GDPR typically requires duplicating security controls for each framework, manually collecting audit evidence, and reacting to findings after deployment. This Skill provides unified control mapping, policy-as-code enforcement, and automated evidence collection so one implementation satisfies multiple frameworks. ## Core Features & Use Cases - Unified Control Mapping: Implement 45 controls once and map them to SOC 2, HIPAA, PCI-DSS 4.0, GDPR, and ISO 27001 requirements, reducing effort by 60-80%. - Policy-as-Code Enforcement: Validate Terraform plans with OPA policies and Checkov scans in CI/CD pipelines before infrastructure is deployed. - Automated Evidence Collection: Continuously gather control evidence via AWS Config, EventBridge, and Lambda, and generate audit-ready compliance reports. - Use Case: A SaaS company preparing for SOC 2 Type II and HIPAA audits uses this Skill to deploy encrypted infrastructure with Terraform, enforce MFA via IAM policies, retain immutable audit logs for 7 years, and auto-generate evidence reports for auditors. ## Quick Start Ask the AI to implement unified SOC 2 and HIPAA compliance controls for your AWS infrastructure, including encryption, MFA enforcement, audit logging, and OPA policy checks in CI/CD.