You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+13-13Lines changed: 13 additions & 13 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -74,7 +74,7 @@ These skills are designed for professionals who work on information security, pr
74
74
75
75
## The Skills
76
76
77
-
### 🔐 ISO 27001
77
+
### 1. 🔐 ISO 27001
78
78
79
79
**File:**`ISO 27001 - Claude Skill/iso27001.skill`
80
80
@@ -92,7 +92,7 @@ The ISO 27001 skill turns Claude into an expert ISO 27001 Lead Auditor and ISMS
92
92
93
93
---
94
94
95
-
### ✅ SOC 2
95
+
### 2. ✅ SOC 2
96
96
97
97
**File:**`SOC 2 - Claude Skill/soc2.skill`
98
98
@@ -110,7 +110,7 @@ The SOC 2 skill turns Claude into an expert SOC 2 compliance advisor grounded in
110
110
111
111
---
112
112
113
-
### 🏛️ FedRAMP
113
+
### 3. 🏛️ FedRAMP
114
114
115
115
**File:**`FedRamp - Claude Skill/fedramp.skill`
116
116
@@ -128,7 +128,7 @@ The FedRAMP skill turns Claude into a knowledgeable FedRAMP advisor covering the
128
128
129
129
---
130
130
131
-
### 🇪🇺 GDPR
131
+
### 4. 🇪🇺 GDPR
132
132
133
133
**File:**`GDPR - Claude Skill/gdpr-compliance.skill`
134
134
@@ -145,7 +145,7 @@ The GDPR skill turns Claude into an expert GDPR compliance assistant that bridge
145
145
146
146
---
147
147
148
-
### 🏥 HIPAA
148
+
### 5. 🏥 HIPAA
149
149
150
150
**File:**`HIPAA - Claude Skill/hipaa-compliance.skill`
151
151
@@ -162,7 +162,7 @@ The HIPAA skill turns Claude into a knowledgeable HIPAA compliance advisor cover
162
162
163
163
---
164
164
165
-
### 🛡️ NIST CSF
165
+
### 6. 🛡️ NIST CSF
166
166
167
167
**File:**`NIST Cybersecurity framework - Claude Skill/NIST Cybersecurity.skill`
168
168
@@ -181,7 +181,7 @@ The NIST CSF skill turns Claude into an expert NIST Cybersecurity Framework advi
181
181
182
182
---
183
183
184
-
### 💳 PCI DSS
184
+
### 7. 💳 PCI DSS
185
185
186
186
**File:**`PCI Compliance - Claude Skill/PCI-Compliance.skill`
187
187
@@ -200,7 +200,7 @@ The PCI DSS skill turns Claude into an expert PCI DSS compliance advisor coverin
200
200
201
201
---
202
202
203
-
### 🚨 TSA Cybersecurity
203
+
### 8. 🚨 TSA Cybersecurity
204
204
205
205
**File:**`TSA Compliance - Claude Skill/TSA-Compliance.skill`
206
206
@@ -221,17 +221,17 @@ The TSA Cybersecurity skill turns Claude into an expert TSA cybersecurity direct
221
221
222
222
---
223
223
224
-
### 🤖 ISO 42001 AI Management System
224
+
### 9. 🤖 ISO 42001 AI Management System
225
225
226
226
**File:**`ISO 42001 - Claude Skill/ISO-42001.skill`
227
227
228
228
The ISO 42001 skill turns Claude into an expert **ISO/IEC 42001:2023** AI Management System (AIMS) advisor — the world's first international standard for AI governance. It serves both **AI providers** (organisations that develop or deploy AI) and **AI users** (organisations integrating third-party AI), covering the full certification lifecycle from gap assessment through Stage 2 audit readiness.
229
229
230
230
**What it does:**
231
-
- Conducts structured **gap assessments** across all mandatory clauses (4–10) and all **38 Annex A controls** with 🔴/🟡/🟢 status, evidence requirements, and a phased remediation roadmap
231
+
- Conducts structured **gap assessments** across all mandatory clauses (4–10) and all **38 Annex A controls**(domains A.2–A.10) with 🔴/🟡/🟢 status, evidence requirements, and a phased remediation roadmap
232
232
- Guides the mandatory **AI System Impact Assessment (AISIA)** step by step — identifying affected populations, assessing impact dimensions (severity, reversibility, breadth, human oversight), classifying impact level (Low/Medium/High), and determining proportionate control requirements
233
233
- Performs **AI risk assessment** across all risk categories: model risks (bias, drift, hallucination, adversarial attacks), data risks (quality, poisoning, privacy in training data), operational risks (scope creep, human over-reliance), and supply chain risks (third-party model risk, API dependencies)
234
-
- Generates a complete **Statement of Applicability (SoA)**for all 38 Annex A controls with applicability decisions, justifications, and implementation status
234
+
- Generates a complete **Statement of Applicability (SoA)**covering all 38 Annex A controls (A.2.2–A.10.4) with applicability decisions, justifications, and implementation status
235
235
- Drafts all core **AIMS policies** — AI Policy, AI Risk Management Policy, AI Acceptable Use Policy, Data Governance for AI Policy, AI Incident Management Policy, AI System Lifecycle Policy, and AI Supplier Management Policy — each with document control blocks and clause citations
236
236
- Produces **Stage 1 and Stage 2 audit checklists** with RAG status, evidence requirements per clause, and common auditor focus areas
237
237
-**Maps ISO 42001 to the EU AI Act** — aligns AISIA to the Fundamental Rights Impact Assessment (FRIA) for high-risk AI systems; maps Annex A controls to EU AI Act technical requirements
@@ -283,13 +283,13 @@ The ISO 42001 skill turns Claude into an expert **ISO/IEC 42001:2023** AI Manage
283
283
| Aligning a TSA CRMP to NIST CSF 2.0 and CISA Cross-Sector CPGs | TSA Cybersecurity + NIST CSF |
284
284
| Running an ISO 42001 gap assessment for an AI provider with multiple ML models in production | ISO 42001 |
285
285
| Completing an AI System Impact Assessment (AISIA) for an automated hiring tool | ISO 42001 |
286
-
| Building a Statement of Applicability (SoA) for all 38 ISO 42001 Annex A controls | ISO 42001 |
286
+
| Building a Statement of Applicability (SoA) covering all 38 ISO 42001 Annex A controls (A.2–A.10)| ISO 42001 |
287
287
| Drafting an AI Policy and AI Acceptable Use Policy for a financial services firm | ISO 42001 |
288
288
| Assessing whether a customer-facing AI system requires high-impact controls under ISO 42001 | ISO 42001 |
289
289
| Preparing evidence packages for ISO 42001 Stage 1 and Stage 2 certification audits | ISO 42001 |
290
290
| Mapping ISO 42001 AISIA requirements to EU AI Act Fundamental Rights Impact Assessment (FRIA) | ISO 42001 |
291
291
| Integrating an ISO 42001 AIMS with an existing ISO 27001 ISMS | ISO 42001 + ISO 27001 |
292
-
| Governing staff use of public AI tools (ChatGPT, Copilot) under Annex A control A.9.7| ISO 42001 |
292
+
| Governing staff use of public AI tools (ChatGPT, Copilot) under Annex A control A.9.2 and A.9.4| ISO 42001 |
Copy file name to clipboardExpand all lines: index.html
+21-21Lines changed: 21 additions & 21 deletions
Original file line number
Diff line number
Diff line change
@@ -430,7 +430,7 @@ <h2>Who Is This For?</h2>
430
430
<h2>The Skills</h2>
431
431
432
432
<divclass="skill-card">
433
-
<h3>🔐 ISO 27001</h3>
433
+
<h3>1. 🔐 ISO 27001</h3>
434
434
<spanclass="file-badge">ISO 27001 - Claude Skill/iso27001.skill</span>
435
435
<p>Turns Claude into an expert ISO 27001 Lead Auditor and ISMS implementation consultant. Covers both <strong>ISO 27001:2013</strong> (114 controls, 14 domains) and <strong>ISO 27001:2022</strong> (93 controls, 4 themes), defaulting to 2022.</p>
436
436
<ul>
@@ -444,7 +444,7 @@ <h3>🔐 ISO 27001</h3>
444
444
</div>
445
445
446
446
<divclass="skill-card">
447
-
<h3>✅ SOC 2</h3>
447
+
<h3>2. ✅ SOC 2</h3>
448
448
<spanclass="file-badge">SOC 2 - Claude Skill/soc2.skill</span>
449
449
<p>Turns Claude into an expert SOC 2 compliance advisor grounded in the <strong>AICPA 2017 Trust Services Criteria (TSC) with 2022 Revised Points of Focus</strong>. Covers all five TSC: Security (CC1–CC9), Availability (A1), Confidentiality (C1), Processing Integrity (PI1), and Privacy (P1–P8).</p>
450
450
<ul>
@@ -457,7 +457,7 @@ <h3>✅ SOC 2</h3>
457
457
</div>
458
458
459
459
<divclass="skill-card">
460
-
<h3>🏛️ FedRAMP</h3>
460
+
<h3>3. 🏛️ FedRAMP</h3>
461
461
<spanclass="file-badge">FedRamp - Claude Skill/fedramp.skill</span>
462
462
<p>Turns Claude into a knowledgeable FedRAMP advisor covering the full authorization lifecycle for Cloud Service Providers under <strong>NIST SP 800-53 Rev 5</strong>. Current as of 2025–2026, incorporating the Rev 5 transition, September 2026 OSCAL mandate, and December 2024 template updates.</p>
463
463
<ul>
@@ -471,7 +471,7 @@ <h3>🏛️ FedRAMP</h3>
471
471
</div>
472
472
473
473
<divclass="skill-card">
474
-
<h3>🇪🇺 GDPR</h3>
474
+
<h3>4. 🇪🇺 GDPR</h3>
475
475
<spanclass="file-badge">GDPR - Claude Skill/gdpr-compliance.skill</span>
476
476
<p>Turns Claude into an expert GDPR compliance assistant bridging technical and legal perspectives. Covers full <strong>EU GDPR</strong> with notes on <strong>UK GDPR (DPA 2018)</strong> where rules differ.</p>
477
477
<ul>
@@ -484,7 +484,7 @@ <h3>🇪🇺 GDPR</h3>
484
484
</div>
485
485
486
486
<divclass="skill-card">
487
-
<h3>🏥 HIPAA</h3>
487
+
<h3>5. 🏥 HIPAA</h3>
488
488
<spanclass="file-badge">HIPAA - Claude Skill/hipaa-compliance.skill</span>
489
489
<p>Turns Claude into a knowledgeable HIPAA compliance advisor covering the <strong>Privacy Rule, Security Rule, and Breach Notification Rule</strong> (45 CFR Parts 160 and 164, as amended by HITECH).</p>
490
490
<ul>
@@ -497,7 +497,7 @@ <h3>🏥 HIPAA</h3>
497
497
</div>
498
498
499
499
<divclass="skill-card">
500
-
<h3>🛡️ NIST CSF</h3>
500
+
<h3>6. 🛡️ NIST CSF</h3>
501
501
<spanclass="file-badge">NIST Cybersecurity framework - Claude Skill/NIST Cybersecurity.skill</span>
502
502
<p>Turns Claude into an expert NIST Cybersecurity Framework advisor covering both <strong>CSF 2.0</strong> (February 2024) and <strong>CSF 1.1</strong> (April 2018), defaulting to CSF 2.0. Covers all six functions — <strong>Govern, Identify, Protect, Detect, Respond, Recover</strong> — including the new Govern function in CSF 2.0.</p>
503
503
<ul>
@@ -511,7 +511,7 @@ <h3>🛡️ NIST CSF</h3>
511
511
</div>
512
512
513
513
<divclass="skill-card">
514
-
<h3>💳 PCI DSS</h3>
514
+
<h3>7. 💳 PCI DSS</h3>
515
515
<spanclass="file-badge">PCI Compliance - Claude Skill/PCI-Compliance.skill</span>
516
516
<p>Turns Claude into an expert PCI DSS compliance advisor covering <strong>PCI DSS v4.0.1</strong> (June 2024 — current), including all requirements that became mandatory on March 31, 2025. Covers all 12 requirements, all 8 SAQ types, merchant and service provider levels, and v4.0 changes from v3.2.1.</p>
517
517
<ul>
@@ -524,7 +524,7 @@ <h3>💳 PCI DSS</h3>
524
524
</div>
525
525
526
526
<divclass="skill-card">
527
-
<h3>🚨 TSA Cybersecurity</h3>
527
+
<h3>8. 🚨 TSA Cybersecurity</h3>
528
528
<spanclass="file-badge">TSA Compliance - Claude Skill/TSA-Compliance.skill</span>
529
529
<p>Turns Claude into an expert TSA cybersecurity directive advisor for <strong>critical transportation infrastructure</strong>. Covers all current TSA Security Directive series — SD Pipeline-2021-01G, SD Pipeline-2021-02F, SD 1580-21-01E (freight rail), and SD 1582-21-01E (transit/passenger rail) — plus the <strong>November 2024 NPRM</strong>.</p>
530
530
<divclass="info-box"><strong>Note on SSI:</strong> TSA Security Directives are classified as Sensitive Security Information (SSI). This skill is built from publicly available summaries, Federal Register notices, and DHS/CISA publications — not the classified full directive text.</div>
<spanclass="file-badge">ISO 42001 - Claude Skill/ISO-42001.skill</span>
543
543
<p>Turns Claude into an expert <strong>ISO/IEC 42001:2023</strong> AI Management System (AIMS) advisor — the world's first international standard for AI governance. Serves both <strong>AI providers</strong> (organisations developing or deploying AI) and <strong>AI users</strong> (organisations integrating third-party AI).</p>
544
544
<ul>
545
-
<li>Conducts structured <strong>gap assessments</strong> across all mandatory clauses (4–10) and all <strong>38 Annex A controls</strong> with 🔴/🟡/🟢 status and phased remediation roadmap</li>
545
+
<li>Conducts structured <strong>gap assessments</strong> across all mandatory clauses (4–10) and all <strong>38 Annex A controls</strong>(domains A.2–A.10) with 🔴/🟡/🟢 status and phased remediation roadmap</li>
546
546
<li>Guides the mandatory <strong>AI System Impact Assessment (AISIA)</strong> — identifying affected populations, assessing impact dimensions, classifying impact level (Low/Medium/High)</li>
547
547
<li>Performs <strong>AI risk assessment</strong> across model risks, data risks, operational risks, and supply chain risks</li>
548
-
<li>Generates a complete <strong>Statement of Applicability (SoA)</strong>for all 38 Annex A controls</li>
548
+
<li>Generates a complete <strong>Statement of Applicability (SoA)</strong>covering all 38 Annex A controls (A.2.2–A.10.4)</li>
549
549
<li><strong>Maps ISO 42001 to the EU AI Act</strong> — aligns AISIA to the Fundamental Rights Impact Assessment (FRIA) for high-risk AI systems</li>
550
550
</ul>
551
551
<divclass="trigger-tags"><strong>Trigger phrases:</strong><code>ISO 42001</code><code>ISO/IEC 42001</code><code>AI Management System</code><code>AIMS</code><code>AISIA</code><code>AI governance standard</code><code>Annex A AI controls</code><code>AI certification</code><code>EU AI Act management system</code></div>
@@ -606,15 +606,15 @@ <h2>How to Install a Skill</h2>
<tr><td>🔐 ISO 27001</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027001%20-%20Claude%20Skill/iso27001.skill">iso27001.skill</a></td></tr>
<tr><td>🤖 ISO 42001 AI Management System</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill">ISO-42001.skill</a></td></tr>
609
+
<tr><td>1. 🔐 ISO 27001</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027001%20-%20Claude%20Skill/iso27001.skill">iso27001.skill</a></td></tr>
<tr><td>9. 🤖 ISO 42001 AI Management System</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill">ISO-42001.skill</a></td></tr>
618
618
</tbody>
619
619
</table>
620
620
</div>
@@ -850,7 +850,7 @@ <h4>🆕 New Skills (4)</h4>
850
850
<li><spanclass="release-badge badge-new">New</span><strong>NIST CSF</strong> — CSF 2.0 and CSF 1.1 advisor covering all six functions (Govern, Identify, Protect, Detect, Respond, Recover), gap assessments, organisational profiles, and implementation tiers</li>
<li><spanclass="release-badge badge-new">New</span><strong>TSA Cybersecurity</strong> — TSA Security Directive advisor for pipeline and rail critical infrastructure, CRMP drafting, OT/ICS implementation, and CISA 24-hour incident reporting</li>
853
-
<li><spanclass="release-badge badge-new">New</span><strong>ISO 42001 AI Management System</strong> — ISO/IEC 42001:2023 AIMS advisor covering all 38 Annex A controls, AISIA methodology, AI risk assessment, and EU AI Act mapping</li>
853
+
<li><spanclass="release-badge badge-new">New</span><strong>ISO 42001 AI Management System</strong> — ISO/IEC 42001:2023 AIMS advisor covering all 38 Annex A controls (A.2–A.10), AISIA methodology, AI risk assessment, and EU AI Act mapping</li>
-**OSCAL mandate**: RFC-0024 requires all CSPs to transition to machine-readable OSCAL packages by **September 2026**
39
39
-**Security Inbox**: As of January 5, 2026, all authorized CSPs must maintain a dedicated Security Inbox for urgent vulnerability directives (no CAPTCHAs or barriers)
40
40
-**FedRAMP 20x**: A modernization initiative in progress; introduces continuous authorization and modular/API-driven submissions. Traditional SSP/SAP/SAR templates remain required for non-20x paths.
@@ -46,7 +46,7 @@ Identify the user's goal and jump to the appropriate section:
46
46
47
47
### Approach
48
48
1.**Clarify scope** — Ask the user: What is the CSO (Cloud Service Offering)? IaaS/PaaS/SaaS? Target impact level?
49
-
2.**Identify authorization path** — Agency Authorization (sponsor needed) vs. JAB (Joint Authorization Board, now limited) vs. FedRAMP 20x pilot
49
+
2.**Identify authorization path** — Agency Authorization (sponsor needed) vs. JAB P-ATO (Joint Authorization Board — effectively suspended since 2024; verify current status with FedRAMP PMO) vs. FedRAMP 20x pilot
50
50
3.**Run through the readiness checklist** — See `references/readiness-checklist.md`
51
51
4.**Surface gaps** — Map current state to required controls; flag missing documentation, unimplemented controls, and architectural deficiencies
52
52
5.**Prioritize** — Group gaps by: (a) blockers for readiness review, (b) items addressable before 3PAO assessment, (c) POA&M candidates
0 commit comments