security-compliance

Document security controls and compliance evidence for regulatory frameworks.

5|Updated Jul 6, 2025
One-click install
npx skills add https://github.com/GuicedEE/ai-rules --skill security-compliance-guicedee
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: security-compliance
Source: https://github.com/GuicedEE/ai-rules/tree/main/skills/.curated/security-compliance
Command: npx skills add https://github.com/GuicedEE/ai-rules --skill security-compliance-guicedee

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps security teams design defense-in-depth controls, perform threat modeling and risk assessments, and map mitigations to frameworks (SOC2/ISO27001/GDPR/HIPAA) to produce testable compliance evidence.

Core Features & Use Cases

  • Threat-model templates and lightweight risk assessment guidance for system design.
  • Pragmatic control checklists mapped to data flows and trust boundaries.
  • Evidence inventory and artifacts guidance for audits and certifications.
  • Use Case: When shipping sensitive features, run a quick threat-modeling session and assemble required artifacts.

Quick Start

Start by scaffolding a lightweight threat model for your system and populate the control checklist and evidence list.

Frequently Asked Questions about security-compliance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a lightweight threat model for system design?▼

A lightweight threat model for system design is created by identifying defense-in-depth controls and documenting data flows alongside trust boundaries. This process generates a pragmatic control checklist mapped directly to your architecture.

What is the best way to map security controls to SOC2 and ISO27001 frameworks?▼

Mapping security controls to SOC2 and ISO27001 frameworks involves linking your documented defense-in-depth mitigations to specific regulatory standards. This produces a testable evidence inventory required for audits and certifications.

How do I generate compliance evidence for GDPR and HIPAA audits?▼

Generating compliance evidence for GDPR and HIPAA audits requires assembling an evidence inventory that links your system design mitigations to regulatory frameworks. This provides testable artifacts for certification reviews.

Can I perform a risk assessment during a system design review?▼

Yes, you can perform a risk assessment during a system design review by applying threat-model templates to identify vulnerabilities. This yields a documented assessment of threats and a pragmatic control checklist.

What is defense-in-depth control documentation for sensitive features?▼

Defense-in-depth control documentation for sensitive features identifies multiple security layers across your services and data flows. It produces a pragmatic checklist mapping mitigations to frameworks like SOC2 and HIPAA.

When do I need a compliance evidence inventory for my data flows?▼

You need a compliance evidence inventory for your data flows when preparing for audits or shipping sensitive features. It links your documented security controls to specific regulatory frameworks to ensure testable compliance.