You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, and ISO 27701 Privacy Information Management.",
4
+
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience.",
5
5
"owner": {
6
6
"name": "Hemant Naik",
7
7
"email": "hemant.naik@gmail.com"
@@ -222,6 +222,30 @@
222
222
"aisia",
223
223
"grc"
224
224
]
225
+
},
226
+
{
227
+
"name": "dora",
228
+
"source": "./plugins/dora",
229
+
"description": "DORA (Regulation (EU) 2022/2554) compliance advisor for EU financial entities \u2014 ICT risk management framework, incident classification and reporting, TLPT, ICT third-party risk, Register of Information, and all adopted RTS/ITS with article-level citations.",
Copy file name to clipboardExpand all lines: README.md
+37-3Lines changed: 37 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,11 @@
1
1
# Claude Skills for Governance, Risk & Compliance (GRC)
2
-
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, and ISO 27701 Privacy Information Management — powered by Claude Skills.
2
+
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience — powered by Claude Skills.
3
3
4
4
Benchmarked across 18 test cases (2 per framework) using the eval framework — each graded against 4–5 verifiable assertions by independent agents. Skills scored **94% ± 10%** vs a baseline of 72% ± 28%.
[](https://claude.ai)
10
10
11
11
---
@@ -25,6 +25,7 @@ Benchmarked across 18 test cases (2 per framework) using the eval framework —
25
25
-[TSA Cybersecurity](#-tsa-cybersecurity)
26
26
-[ISO 42001 AI Management System](#-iso-42001-ai-management-system)
27
27
-[ISO 27701 Privacy Information Management](#-iso-27701-privacy-information-management)
28
+
-[DORA Digital Operational Resilience](#-dora-digital-operational-resilience)
28
29
-[Potential Use Cases](#potential-use-cases)
29
30
-[How to Install a Skill](#how-to-install-a-skill)
30
31
-[Install via Claude Code Marketplace](#install-via-claude-code-marketplace)
@@ -261,6 +262,28 @@ The ISO 27701 skill turns Claude into an expert **ISO/IEC 27701:2025** Privacy I
261
262
262
263
---
263
264
265
+
### 11. 🏦 DORA Digital Operational Resilience
266
+
267
+
**File:**`DORA - Claude Skill/dora.skill`
268
+
269
+
The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/2554** (the Digital Operational Resilience Act) — the anchoring ICT regulation for EU financial entities since 17 January 2025. It encodes all 64 DORA articles, all 12 adopted RTS/ITS, and provides precise article-level guidance for every compliance workflow. It explicitly separates DORA from NIS2, legacy EBA ICT guidelines, and ISO 27001 — a common source of conflation in general LLM responses.
270
+
271
+
**What it does:**
272
+
- Conducts structured **DORA gap analyses** across all four pillars: ICT risk management framework (Chapter II, Art. 5–16), incident management (Chapter III, Art. 17–23), resilience testing / TLPT (Chapter IV, Art. 24–27), and ICT third-party risk (Chapter V, Art. 28–44)
273
+
- Guides **ICT-related incident classification** against Art. 18 criteria and the materiality thresholds in CDR (EU) 2024/1772, with a full decision tree for major vs. non-major
274
+
- Builds **three-stage incident reporting procedures** per Art. 19 and CDR (EU) 2025/301 — initial (4h), intermediate (72h), final (1 month) — including content requirements at each stage
275
+
- Reviews and drafts **contractual provisions** per Art. 30(2)(a)–(i), flagging the common audit-rights gap with hyperscale cloud providers
276
+
- Builds or validates the **Register of Information** with all mandatory fields per CIR (EU) 2024/2956
277
+
- Assesses **ICT concentration risk** per Art. 28(6) and Art. 29 — including multi-function reliance on a single cloud provider
278
+
- Scopes **TLPT programmes** per Art. 26 and CDR (EU) 2025/1190, covering threat intelligence phase, red team test, mutual recognition, and tester qualification requirements
279
+
- Drafts **ICT risk management framework** documentation per Art. 6–14 and CDR (EU) 2024/1774
280
+
- Precisely distinguishes **Chapter II** (proactive ICT risk governance) from **Chapter III** (reactive incident management) — a common compliance confusion point
281
+
- References all **12 adopted RTS/ITS** by exact regulation number (CDR/CIR) with article-level mapping
| 🤖 ISO 42001 AI Management System |[ISO-42001.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill)|
340
373
| 🔒 ISO 27701 Privacy Information Management |[iso27701.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill)|
374
+
| 🏦 DORA Digital Operational Resilience |[dora.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill)|
341
375
342
376
2. Open Claude and navigate to **Customize → Skills**.
343
377
3. Click **Upload Skill** and select the `.skill` file.
@@ -357,7 +391,7 @@ Add the marketplace and install the skills you need directly from the terminal:
Teams can pre-wire the marketplace in `.claude/settings.json` so every developer gets the skills automatically when they open the project — no manual install required.
<imgsrc="https://img.shields.io/badge/Built%20with-Claude-orange.svg" alt="Built with Claude" />
380
380
</div>
381
381
</header>
@@ -566,6 +566,21 @@ <h3>10. 🔒 ISO 27701 Privacy Information Management</h3>
566
566
<divclass="trigger-tags"><strong>Trigger phrases:</strong><code>ISO 27701</code><code>PIMS</code><code>privacy information management</code><code>PII controller</code><code>PII processor</code><code>DPIA</code><code>RoPA</code><code>data subject rights</code><code>privacy by design</code><code>data processing agreement</code><code>GDPR alignment ISO 27701</code></div>
567
567
</div>
568
568
569
+
<divclass="skill-card">
570
+
<h3>11. 🏦 DORA Digital Operational Resilience</h3>
571
+
<spanclass="file-badge">DORA - Claude Skill/dora.skill</span>
572
+
<p>Turns Claude into an expert advisor on <strong>Regulation (EU) 2022/2554</strong> (DORA) — the anchoring ICT regulation for EU financial entities since 17 January 2025. Encodes all 64 DORA articles, all 12 adopted RTS/ITS, and provides precise article-level guidance. Explicitly separates DORA from NIS2, legacy EBA ICT guidelines, and ISO 27001.</p>
573
+
<ul>
574
+
<li>Conducts structured <strong>DORA gap analyses</strong> across ICT risk management (Chapter II, Art. 5–16), incident management (Chapter III, Art. 17–23), TLPT (Chapter IV, Art. 24–27), and third-party risk (Chapter V, Art. 28–44)</li>
575
+
<li>Guides <strong>ICT incident classification</strong> against Art. 18 criteria and CDR (EU) 2024/1772 materiality thresholds, with a full decision tree for major vs. non-major</li>
576
+
<li>Builds <strong>three-stage reporting procedures</strong> per Art. 19: initial (4h), intermediate (72h), final (1 month), including content requirements per CDR (EU) 2025/301</li>
577
+
<li>Reviews contracts against <strong>Art. 30(2)(a)–(i)</strong> mandatory provisions and flags the audit-rights gap common with hyperscale cloud providers</li>
578
+
<li>Builds and validates the <strong>Register of Information</strong> with all mandatory fields per CIR (EU) 2024/2956</li>
579
+
<li>Scopes <strong>TLPT programmes</strong> per Art. 26 and CDR (EU) 2025/1190, covering threat intelligence, red team, mutual recognition, and tester qualifications</li>
580
+
</ul>
581
+
<divclass="trigger-tags"><strong>Trigger phrases:</strong><code>DORA</code><code>Regulation (EU) 2022/2554</code><code>digital operational resilience</code><code>ICT risk management framework</code><code>Art. 18 classification</code><code>Art. 19 incident reporting</code><code>Art. 26 TLPT</code><code>Art. 30 contractual provisions</code><code>Register of Information</code><code>ICT concentration risk</code><code>DORA vs NIS2</code><code>Chapter II DORA</code><code>Chapter III DORA</code></div>
582
+
</div>
583
+
569
584
<hr/>
570
585
571
586
<h2>Potential Use Cases</h2>
@@ -601,6 +616,14 @@ <h2>Potential Use Cases</h2>
601
616
<tr><td>Completing a DPIA for a new AI feature that profiles users for targeted advertising</td><td>ISO 27701</td></tr>
602
617
<tr><td>Mapping ISO 27701:2025 controls to GDPR articles for a compliance audit</td><td>ISO 27701</td></tr>
603
618
<tr><td>Integrating a PIMS with an existing ISO 27001:2022 ISMS to avoid duplicating controls</td><td>ISO 27701 + ISO 27001</td></tr>
619
+
<tr><td>Running a DORA gap analysis for an EU credit institution ahead of a supervisory review</td><td>DORA</td></tr>
620
+
<tr><td>Classifying an ICT incident against Art. 18 criteria and CDR (EU) 2024/1772 thresholds</td><td>DORA</td></tr>
621
+
<tr><td>Building a three-stage incident reporting procedure (4h / 72h / 1 month) per Art. 19</td><td>DORA</td></tr>
622
+
<tr><td>Reviewing ICT vendor contracts against Art. 30(2) mandatory provisions</td><td>DORA</td></tr>
623
+
<tr><td>Building or validating the Register of Information per CIR (EU) 2024/2956</td><td>DORA</td></tr>
624
+
<tr><td>Assessing ICT concentration risk for a bank reliant on a single hyperscaler</td><td>DORA</td></tr>
625
+
<tr><td>Scoping a TLPT programme and evaluating whether Art. 26 applies</td><td>DORA</td></tr>
626
+
<tr><td>Advising on the interaction between DORA and NIS2 for a financial entity</td><td>DORA</td></tr>
604
627
</tbody>
605
628
</table>
606
629
</div>
@@ -637,6 +660,7 @@ <h2>How to Install a Skill</h2>
<tr><td>9. 🤖 ISO 42001 AI Management System</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill">ISO-42001.skill</a></td></tr>
639
662
<tr><td>10. 🔒 ISO 27701 Privacy Information Management</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill">iso27701.skill</a></td></tr>
663
+
<tr><td>11. 🏦 DORA Digital Operational Resilience</td><td><ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill">dora.skill</a></td></tr>
640
664
</tbody>
641
665
</table>
642
666
</div>
@@ -650,7 +674,7 @@ <h2>Install via Claude Code Marketplace</h2>
650
674
<p>Add the marketplace and install the skills you need directly from the terminal:</p>
<p>Teams can pre-wire the marketplace in <code>.claude/settings.json</code> so every developer gets the skills automatically when they open the project — no manual install required.</p>
656
680
<p>📖 <ahref="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/blob/main/INSTALLATION.md"><strong>Full installation instructions, team setup, and update guide → INSTALLATION.md</strong></a></p>
"description": "DORA (Regulation (EU) 2022/2554) compliance advisor for EU financial entities — ICT risk management framework, incident classification and reporting, TLPT, ICT third-party risk, Register of Information, and all adopted RTS/ITS with article-level citations.",
0 commit comments