Skip to content

Commit eb75de5

Browse files
committed
Add DORA skill.
1 parent b001218 commit eb75de5

File tree

15 files changed

+2028
-8
lines changed

15 files changed

+2028
-8
lines changed

.claude-plugin/marketplace.json

Lines changed: 25 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"$schema": "https://anthropic.com/claude-code/marketplace.schema.json",
33
"name": "grc-skills",
4-
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, and ISO 27701 Privacy Information Management.",
4+
"description": "Claude Code skills for Governance, Risk & Compliance \u2014 ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience.",
55
"owner": {
66
"name": "Hemant Naik",
77
"email": "hemant.naik@gmail.com"
@@ -222,6 +222,30 @@
222222
"aisia",
223223
"grc"
224224
]
225+
},
226+
{
227+
"name": "dora",
228+
"source": "./plugins/dora",
229+
"description": "DORA (Regulation (EU) 2022/2554) compliance advisor for EU financial entities \u2014 ICT risk management framework, incident classification and reporting, TLPT, ICT third-party risk, Register of Information, and all adopted RTS/ITS with article-level citations.",
230+
"version": "0.3.0",
231+
"author": {
232+
"name": "Hemant Naik",
233+
"email": "hemant.naik@gmail.com"
234+
},
235+
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
236+
"category": "compliance",
237+
"keywords": [
238+
"dora",
239+
"eu-2022-2554",
240+
"ict-risk",
241+
"digital-operational-resilience",
242+
"financial-entities",
243+
"third-party-risk",
244+
"tlpt",
245+
"rts",
246+
"its",
247+
"grc"
248+
]
225249
}
226250
]
227251
}

DORA - Claude Skill/dora.skill

32.8 KB
Binary file not shown.

README.md

Lines changed: 37 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
# Claude Skills for Governance, Risk & Compliance (GRC)
2-
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, and ISO 27701 Privacy Information Management — powered by Claude Skills.
2+
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, and DORA Digital Operational Resilience — powered by Claude Skills.
33

44
Benchmarked across 18 test cases (2 per framework) using the eval framework — each graded against 4–5 verifiable assertions by independent agents. Skills scored **94% ± 10%** vs a baseline of 72% ± 28%.
55

66
[![Release: v0.3.0](https://img.shields.io/badge/Release-v0.3.0-brightgreen.svg)](../../releases/tag/v0.3.0)
77
[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)
8-
[![Skills: 10](https://img.shields.io/badge/Skills-10-green.svg)](#the-skills)
8+
[![Skills: 11](https://img.shields.io/badge/Skills-11-green.svg)](#the-skills)
99
[![Built with Claude](https://img.shields.io/badge/Built%20with-Claude-orange.svg)](https://claude.ai)
1010

1111
---
@@ -25,6 +25,7 @@ Benchmarked across 18 test cases (2 per framework) using the eval framework —
2525
- [TSA Cybersecurity](#-tsa-cybersecurity)
2626
- [ISO 42001 AI Management System](#-iso-42001-ai-management-system)
2727
- [ISO 27701 Privacy Information Management](#-iso-27701-privacy-information-management)
28+
- [DORA Digital Operational Resilience](#-dora-digital-operational-resilience)
2829
- [Potential Use Cases](#potential-use-cases)
2930
- [How to Install a Skill](#how-to-install-a-skill)
3031
- [Install via Claude Code Marketplace](#install-via-claude-code-marketplace)
@@ -261,6 +262,28 @@ The ISO 27701 skill turns Claude into an expert **ISO/IEC 27701:2025** Privacy I
261262

262263
---
263264

265+
### 11. 🏦 DORA Digital Operational Resilience
266+
267+
**File:** `DORA - Claude Skill/dora.skill`
268+
269+
The DORA skill turns Claude into an expert advisor on **Regulation (EU) 2022/2554** (the Digital Operational Resilience Act) — the anchoring ICT regulation for EU financial entities since 17 January 2025. It encodes all 64 DORA articles, all 12 adopted RTS/ITS, and provides precise article-level guidance for every compliance workflow. It explicitly separates DORA from NIS2, legacy EBA ICT guidelines, and ISO 27001 — a common source of conflation in general LLM responses.
270+
271+
**What it does:**
272+
- Conducts structured **DORA gap analyses** across all four pillars: ICT risk management framework (Chapter II, Art. 5–16), incident management (Chapter III, Art. 17–23), resilience testing / TLPT (Chapter IV, Art. 24–27), and ICT third-party risk (Chapter V, Art. 28–44)
273+
- Guides **ICT-related incident classification** against Art. 18 criteria and the materiality thresholds in CDR (EU) 2024/1772, with a full decision tree for major vs. non-major
274+
- Builds **three-stage incident reporting procedures** per Art. 19 and CDR (EU) 2025/301 — initial (4h), intermediate (72h), final (1 month) — including content requirements at each stage
275+
- Reviews and drafts **contractual provisions** per Art. 30(2)(a)–(i), flagging the common audit-rights gap with hyperscale cloud providers
276+
- Builds or validates the **Register of Information** with all mandatory fields per CIR (EU) 2024/2956
277+
- Assesses **ICT concentration risk** per Art. 28(6) and Art. 29 — including multi-function reliance on a single cloud provider
278+
- Scopes **TLPT programmes** per Art. 26 and CDR (EU) 2025/1190, covering threat intelligence phase, red team test, mutual recognition, and tester qualification requirements
279+
- Drafts **ICT risk management framework** documentation per Art. 6–14 and CDR (EU) 2024/1774
280+
- Precisely distinguishes **Chapter II** (proactive ICT risk governance) from **Chapter III** (reactive incident management) — a common compliance confusion point
281+
- References all **12 adopted RTS/ITS** by exact regulation number (CDR/CIR) with article-level mapping
282+
283+
**Trigger phrases:** `DORA`, `Regulation (EU) 2022/2554`, `digital operational resilience`, `ICT risk management framework`, `DORA gap analysis`, `Art. 6 DORA`, `Art. 17 ICT incident`, `Art. 18 classification`, `Art. 19 incident reporting`, `Art. 26 TLPT`, `Art. 28 third-party risk`, `Art. 30 contractual provisions`, `Register of Information`, `CIR 2024/2956`, `CDR 2024/1772`, `CDR 2024/1773`, `CDR 2024/1774`, `CDR 2025/301`, `CDR 2025/1190`, `TLPT financial entities`, `ICT concentration risk`, `critical ICT TPSP`, `DORA vs NIS2`, `EBA ICT guidelines DORA`, `DORA incident classification`, `DORA reporting timelines`, `Chapter II DORA`, `Chapter III DORA`
284+
285+
---
286+
264287
## Potential Use Cases
265288

266289
| Scenario | Relevant Skill(s) |
@@ -319,6 +342,16 @@ The ISO 27701 skill turns Claude into an expert **ISO/IEC 27701:2025** Privacy I
319342
| Mapping ISO 27701:2025 controls to GDPR articles for a compliance audit | ISO 27701 |
320343
| Assessing sub-processor management obligations for a cloud-native B2B SaaS | ISO 27701 |
321344
| Integrating a PIMS with an existing ISO 27001:2022 ISMS to avoid duplicating controls | ISO 27701 + ISO 27001 |
345+
| Running a DORA gap analysis for an EU credit institution ahead of a supervisory review | DORA |
346+
| Classifying an ICT incident against Art. 18 criteria and CDR (EU) 2024/1772 thresholds | DORA |
347+
| Building a three-stage incident reporting procedure (4h / 72h / 1 month) per Art. 19 | DORA |
348+
| Reviewing ICT vendor contracts against Art. 30(2) mandatory provisions | DORA |
349+
| Building or validating the Register of Information per CIR (EU) 2024/2956 | DORA |
350+
| Assessing ICT concentration risk for a bank reliant on a single hyperscaler | DORA |
351+
| Scoping a TLPT programme and evaluating whether the Art. 26 threshold applies | DORA |
352+
| Drafting an ICT Third-Party Risk Policy satisfying CDR (EU) 2024/1773 | DORA |
353+
| Advising on the interaction between DORA and NIS2 for a financial entity | DORA |
354+
| Mapping DORA obligations to legacy EBA ICT guidelines and identifying what changed | DORA |
322355

323356
---
324357

@@ -338,6 +371,7 @@ The ISO 27701 skill turns Claude into an expert **ISO/IEC 27701:2025** Privacy I
338371
| 🚨 TSA Cybersecurity | [TSA-Compliance.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/TSA%20Compliance%20-%20Claude%20Skill/TSA-Compliance.skill) |
339372
| 🤖 ISO 42001 AI Management System | [ISO-42001.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill) |
340373
| 🔒 ISO 27701 Privacy Information Management | [iso27701.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill) |
374+
| 🏦 DORA Digital Operational Resilience | [dora.skill](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill) |
341375

342376
2. Open Claude and navigate to **Customize → Skills**.
343377
3. Click **Upload Skill** and select the `.skill` file.
@@ -357,7 +391,7 @@ Add the marketplace and install the skills you need directly from the terminal:
357391

358392
```shell
359393
/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
360-
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills iso27701@grc-skills
394+
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills iso27701@grc-skills dora@grc-skills
361395
```
362396

363397
Teams can pre-wire the marketplace in `.claude/settings.json` so every developer gets the skills automatically when they open the project — no manual install required.

index.html

Lines changed: 26 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -375,7 +375,7 @@ <h1>Claude Skills for Governance, Risk &amp; Compliance</h1>
375375
<div class="badges">
376376
<img src="https://img.shields.io/badge/Release-v0.3.0-brightgreen.svg" alt="Release v0.3.0" />
377377
<img src="https://img.shields.io/badge/License-MIT-blue.svg" alt="MIT License" />
378-
<img src="https://img.shields.io/badge/Skills-10-green.svg" alt="10 Skills" />
378+
<img src="https://img.shields.io/badge/Skills-11-green.svg" alt="11 Skills" />
379379
<img src="https://img.shields.io/badge/Built%20with-Claude-orange.svg" alt="Built with Claude" />
380380
</div>
381381
</header>
@@ -566,6 +566,21 @@ <h3>10. 🔒 ISO 27701 Privacy Information Management</h3>
566566
<div class="trigger-tags"><strong>Trigger phrases:</strong> <code>ISO 27701</code> <code>PIMS</code> <code>privacy information management</code> <code>PII controller</code> <code>PII processor</code> <code>DPIA</code> <code>RoPA</code> <code>data subject rights</code> <code>privacy by design</code> <code>data processing agreement</code> <code>GDPR alignment ISO 27701</code></div>
567567
</div>
568568

569+
<div class="skill-card">
570+
<h3>11. 🏦 DORA Digital Operational Resilience</h3>
571+
<span class="file-badge">DORA - Claude Skill/dora.skill</span>
572+
<p>Turns Claude into an expert advisor on <strong>Regulation (EU) 2022/2554</strong> (DORA) — the anchoring ICT regulation for EU financial entities since 17 January 2025. Encodes all 64 DORA articles, all 12 adopted RTS/ITS, and provides precise article-level guidance. Explicitly separates DORA from NIS2, legacy EBA ICT guidelines, and ISO 27001.</p>
573+
<ul>
574+
<li>Conducts structured <strong>DORA gap analyses</strong> across ICT risk management (Chapter II, Art. 5–16), incident management (Chapter III, Art. 17–23), TLPT (Chapter IV, Art. 24–27), and third-party risk (Chapter V, Art. 28–44)</li>
575+
<li>Guides <strong>ICT incident classification</strong> against Art. 18 criteria and CDR (EU) 2024/1772 materiality thresholds, with a full decision tree for major vs. non-major</li>
576+
<li>Builds <strong>three-stage reporting procedures</strong> per Art. 19: initial (4h), intermediate (72h), final (1 month), including content requirements per CDR (EU) 2025/301</li>
577+
<li>Reviews contracts against <strong>Art. 30(2)(a)–(i)</strong> mandatory provisions and flags the audit-rights gap common with hyperscale cloud providers</li>
578+
<li>Builds and validates the <strong>Register of Information</strong> with all mandatory fields per CIR (EU) 2024/2956</li>
579+
<li>Scopes <strong>TLPT programmes</strong> per Art. 26 and CDR (EU) 2025/1190, covering threat intelligence, red team, mutual recognition, and tester qualifications</li>
580+
</ul>
581+
<div class="trigger-tags"><strong>Trigger phrases:</strong> <code>DORA</code> <code>Regulation (EU) 2022/2554</code> <code>digital operational resilience</code> <code>ICT risk management framework</code> <code>Art. 18 classification</code> <code>Art. 19 incident reporting</code> <code>Art. 26 TLPT</code> <code>Art. 30 contractual provisions</code> <code>Register of Information</code> <code>ICT concentration risk</code> <code>DORA vs NIS2</code> <code>Chapter II DORA</code> <code>Chapter III DORA</code></div>
582+
</div>
583+
569584
<hr />
570585

571586
<h2>Potential Use Cases</h2>
@@ -601,6 +616,14 @@ <h2>Potential Use Cases</h2>
601616
<tr><td>Completing a DPIA for a new AI feature that profiles users for targeted advertising</td><td>ISO 27701</td></tr>
602617
<tr><td>Mapping ISO 27701:2025 controls to GDPR articles for a compliance audit</td><td>ISO 27701</td></tr>
603618
<tr><td>Integrating a PIMS with an existing ISO 27001:2022 ISMS to avoid duplicating controls</td><td>ISO 27701 + ISO 27001</td></tr>
619+
<tr><td>Running a DORA gap analysis for an EU credit institution ahead of a supervisory review</td><td>DORA</td></tr>
620+
<tr><td>Classifying an ICT incident against Art. 18 criteria and CDR (EU) 2024/1772 thresholds</td><td>DORA</td></tr>
621+
<tr><td>Building a three-stage incident reporting procedure (4h / 72h / 1 month) per Art. 19</td><td>DORA</td></tr>
622+
<tr><td>Reviewing ICT vendor contracts against Art. 30(2) mandatory provisions</td><td>DORA</td></tr>
623+
<tr><td>Building or validating the Register of Information per CIR (EU) 2024/2956</td><td>DORA</td></tr>
624+
<tr><td>Assessing ICT concentration risk for a bank reliant on a single hyperscaler</td><td>DORA</td></tr>
625+
<tr><td>Scoping a TLPT programme and evaluating whether Art. 26 applies</td><td>DORA</td></tr>
626+
<tr><td>Advising on the interaction between DORA and NIS2 for a financial entity</td><td>DORA</td></tr>
604627
</tbody>
605628
</table>
606629
</div>
@@ -637,6 +660,7 @@ <h2>How to Install a Skill</h2>
637660
<tr><td>8. 🚨 TSA Cybersecurity</td><td><a href="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/TSA%20Compliance%20-%20Claude%20Skill/TSA-Compliance.skill">TSA-Compliance.skill</a></td></tr>
638661
<tr><td>9. 🤖 ISO 42001 AI Management System</td><td><a href="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2042001%20-%20Claude%20Skill/ISO-42001.skill">ISO-42001.skill</a></td></tr>
639662
<tr><td>10. 🔒 ISO 27701 Privacy Information Management</td><td><a href="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/ISO%2027701%20-%20Claude%20Skill/iso27701.skill">iso27701.skill</a></td></tr>
663+
<tr><td>11. 🏦 DORA Digital Operational Resilience</td><td><a href="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/raw/main/DORA%20-%20Claude%20Skill/dora.skill">dora.skill</a></td></tr>
640664
</tbody>
641665
</table>
642666
</div>
@@ -650,7 +674,7 @@ <h2>Install via Claude Code Marketplace</h2>
650674
<p>Add the marketplace and install the skills you need directly from the terminal:</p>
651675

652676
<pre><code>/plugin marketplace add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
653-
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills</code></pre>
677+
/plugin install iso27001@grc-skills soc2@grc-skills fedramp@grc-skills gdpr-compliance@grc-skills hipaa-compliance@grc-skills nist-csf@grc-skills pci-compliance@grc-skills tsa-compliance@grc-skills iso42001@grc-skills iso27701@grc-skills dora@grc-skills</code></pre>
654678

655679
<p>Teams can pre-wire the marketplace in <code>.claude/settings.json</code> so every developer gets the skills automatically when they open the project — no manual install required.</p>
656680
<p>📖 <a href="https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/blob/main/INSTALLATION.md"><strong>Full installation instructions, team setup, and update guide → INSTALLATION.md</strong></a></p>
Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,24 @@
1+
{
2+
"name": "dora",
3+
"description": "DORA (Regulation (EU) 2022/2554) compliance advisor for EU financial entities — ICT risk management framework, incident classification and reporting, TLPT, ICT third-party risk, Register of Information, and all adopted RTS/ITS with article-level citations.",
4+
"version": "0.3.0",
5+
"author": {
6+
"name": "Hemant Naik",
7+
"email": "hemant.naik@gmail.com"
8+
},
9+
"homepage": "https://sushegaad.github.io/Claude-Skills-Governance-Risk-and-Compliance/",
10+
"repository": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance",
11+
"license": "MIT",
12+
"keywords": [
13+
"dora",
14+
"eu-2022-2554",
15+
"ict-risk",
16+
"digital-operational-resilience",
17+
"financial-entities",
18+
"third-party-risk",
19+
"tlpt",
20+
"rts",
21+
"its",
22+
"grc"
23+
]
24+
}

plugins/dora/dora.skill

32.5 KB
Binary file not shown.

0 commit comments

Comments
 (0)