You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+5-7Lines changed: 5 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
# Claude Skills for Governance, Risk & Compliance (GRC)
2
2
Expert-level compliance guidance for ISO 27001, SOC 2, FedRAMP, GDPR, HIPAA, NIST CSF, PCI DSS, TSA Cybersecurity, ISO 42001 AI Management System, ISO 27701 Privacy Information Management, DORA Digital Operational Resilience, and India's Digital Personal Data Protection Act (DPDPA) — powered by Claude Skills.
3
3
4
-
Benchmarked across 60 test cases (5 per framework) using the eval framework — each graded against 5 verifiable assertions by independent agents. Skills scored **92%** vs a baseline of **84%** across 300 total assertions.
4
+
Benchmarked across 60 test cases (5 per framework) using the eval framework — each graded against 5 verifiable assertions by independent agents. Skills scored **94%** vs a baseline of **83%** across 300 total assertions.
| ISO 27701 | 5 |**76%**|84% |-8% | Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence |
461
+
| ISO 27701 | 5 |**100%**|80% |+20% | Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence |
462
462
| DORA | 5 |**88%**| 72% | +16% | Five pillars; ICT incident reporting timelines; TLPT requirements; Third-party contracts; DORA vs EBA |
463
463
| DPDPA | 5 |**96%**| 80% | +16% | Applicability to foreign entities; Consent vs GDPR; Children's data (18-year threshold); Cross-border transfers; SDF obligations |
464
464
465
465
Skills add the most measurable value on highly framework-specific tasks: clause-level precision for ISO 27001, CC criteria mapping for SOC 2, exact FedRAMP POA&M timeframes and document names, GDPR article citations, HIPAA regulatory section references, CSF 2.0 subcategory IDs, PCI DSS v4.0.1 requirement numbers, TSA Security Directive citations, ISO 42001 AIMS clause references, DORA Article citations and exact incident reporting timelines (4h/72h/1 month), and DPDPA-specific terminology (Data Fiduciary, 8 legitimate uses, blacklist transfers).
466
466
467
-
The ISO 27701 skill shows a slight negative delta in keyword-matching grading because baseline Claude already has substantial GDPR/privacy knowledge; qualitative review of the outputs confirms the skill still provides more structured, citation-precise responses.
468
-
469
467
📊 **[View the full eval results →](grc-skills-eval-results.html)**
<tr><td>🤖 ISO 42001</td><td>5</td><td><strong>92%</strong></td><td>80%</td><td>+12%</td><td>AIMS applicability; Key requirements; AI-specific risks; Third-party LLM management; AI ethics controls</td></tr>
743
-
<tr><td>🔏 ISO 27701</td><td>5</td><td><strong>76%</strong></td><td>84%</td><td>-8%</td><td>Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence</td></tr>
743
+
<tr><td>🔏 ISO 27701</td><td>5</td><td><strong>100%</strong></td><td>80%</td><td>+20%</td><td>Extension to ISO 27001; GDPR mapping; Processor controls; PIA methodology; Certification as GDPR evidence</td></tr>
744
744
<tr><td>🏦 DORA</td><td>5</td><td><strong>88%</strong></td><td>72%</td><td>+16%</td><td>Five pillars; ICT incident reporting timelines; TLPT requirements; Third-party contracts; DORA vs EBA</td></tr>
745
745
<tr><td>🇮🇳 DPDPA</td><td>5</td><td><strong>96%</strong></td><td>80%</td><td>+16%</td><td>Applicability to foreign entities; Consent vs GDPR; Children's data (18-year threshold); Cross-border transfers; SDF obligations</td></tr>
746
746
</tbody>
@@ -749,8 +749,6 @@ <h3>Per-Skill Results</h3>
749
749
750
750
<p>Skills add the most measurable value on highly framework-specific tasks: clause-level precision for ISO 27001, CC criteria mapping for SOC 2, exact FedRAMP document names and POA&M timeframes, GDPR article citations, HIPAA regulatory section references, CSF 2.0 subcategory IDs, PCI DSS v4.0.1 requirement numbers, TSA Security Directive citations, ISO 42001 AIMS clause references, DORA Article numbers and exact incident reporting timelines (4h/72h/1 month), and DPDPA-specific terminology and section references.</p>
751
751
752
-
<p><em>Note: ISO 27701 shows a slight negative delta in keyword-matching grading because baseline Claude already has substantial GDPR/privacy knowledge. Qualitative review confirms the skill still produces more structured, citation-precise responses.</em></p>
753
-
754
752
<ahref="grc-skills-eval-results.html" class="eval-link-btn">📊 View the full eval results →</a>
<li><spanclass="release-badge badge-new">New</span> Interactive Customer Feedback tab with Formspree-powered contact form (Customer Name, Company, Feedback Title, Feedback Body) — submissions delivered to <ahref="mailto:hemant.naik@gmail.com">hemant.naik@gmail.com</a></li>
900
898
<li><spanclass="release-badge badge-new">New</span> Integrated Formspree Ajax library (<code>@formspree/ajax</code>) via CDN for inline field validation and no-reload submissions</li>
901
899
<li><spanclass="release-badge badge-new">New</span> Release Notes section (this section) added to the Resources tab</li>
902
-
<li><spanclass="release-badge badge-improve">Improved</span> Evaluation tab now shows stat cards (92% / 84% / +8pts) and per-skill results table for all 12 skills</li>
900
+
<li><spanclass="release-badge badge-improve">Improved</span> Evaluation tab now shows stat cards (94% / 83% / +11pts) and per-skill results table for all 12 skills</li>
903
901
</ul>
904
902
<h4>🐛 Bug Fixes — Skill Installability</h4>
905
903
<ul>
@@ -930,7 +928,7 @@ <h4>🆕 New Skills (4)</h4>
930
928
<h4>📊 Skill Evaluation</h4>
931
929
<ul>
932
930
<li><spanclass="release-badge badge-improve">Improved</span> Expanded eval suite to <strong>12 skills / 60 test cases</strong> (5 per framework), each graded against 5 verifiable assertions by independent grader agents — 300 total assertions</li>
933
-
<li><spanclass="release-badge badge-improve">Improved</span> Skills scored <strong>92%</strong> vs baseline of 84% (+8 point improvement, +24 additional assertions passed)</li>
931
+
<li><spanclass="release-badge badge-improve">Improved</span> Skills scored <strong>94%</strong> vs baseline of 83% (+11 point improvement, +32 additional assertions passed)</li>
934
932
<li><spanclass="release-badge badge-improve">Improved</span> Evaluation tab updated with full 60-case results for all 12 skills including DORA and DPDPA</li>
0 commit comments