What problem does it solve? Security auditors and GRC analysts often lack a structured methodology when planning audits, testing controls, or choosing between compliance frameworks like SOC 2, ISO 27001, PCI DSS, and HIPAA. This Skill provides a complete audit lifecycle reference so findings are evidence-based, risk-prioritized, and aligned with the right standard. ## Core Features & Use Cases - Audit Lifecycle Guidance: Covers planning, scoping, fieldwork, control testing, reporting, remediation tracking, and follow-up audits with concrete techniques like walkthroughs, re-performance, and CAATs. - Framework Comparison & Mapping: Compares SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, SOX, and HITRUST with control overlap tables and a decision tree for selecting the right framework. - Certification & Career Path: Details CISA, CISSP, ISO 27001 Lead Auditor, CRISC, and CISM with costs, prerequisites, and career progression. - Use Case: A GRC analyst preparing a SOC 2 Type II audit can use this Skill to scope control objectives, design sampling strategies, structure workpapers, and map findings to Trust Services Criteria. ## Quick Start Ask the agent to help plan a SOC 2 Type II audit for a B2B SaaS company, including scope, control testing approach, and evidence collection strategy.