跳转到主要内容
此内容尚未提供您的语言版本,正在以英文显示。

SOC 2 Compliance

技能 已验证 活跃

Use when the user asks to prepare for SOC 2 audits, map Trust Service Criteria, build control matrices, collect audit evidence, perform gap analysis, or assess SOC 2 Type I vs Type II readiness.

目的

To streamline and professionalize the preparation for SOC 2 audits, ensuring organizations can effectively map controls, identify compliance gaps, and gather necessary evidence.

功能

  • SOC 2 Type I vs Type II comparison
  • Trust Service Criteria mapping and documentation
  • Control matrix generation (SEC, AVL, CON, PRI, PRV)
  • Gap analysis for design and operating effectiveness
  • Evidence collection guidance and automation strategies
  • Audit readiness checklist and common findings

使用场景

  • Use when preparing for a SOC 2 Type I or Type II audit.
  • Use when mapping your organization's controls to SOC 2 Trust Service Criteria.
  • Use for conducting internal gap analyses against SOC 2 requirements.
  • Use to understand evidence collection requirements for SOC 2.

非目标

  • Performing the actual SOC 2 audit or issuing the report.
  • Providing legal advice on compliance matters.
  • Automating the remediation of identified gaps (focus is on analysis and preparation).

实践

  • Compliance Management
  • Information Security
  • Audit Preparation
  • Risk Management

安装

请先添加 Marketplace

/plugin marketplace add alirezarezvani/claude-skills
/plugin install ra-qm-team@claude-code-skills

质量评分

已验证
98 /100
about 20 hours ago 分析

信任信号

最近提交1 day ago
星标14.6k
许可证MIT
状态
查看源代码

类似扩展

TradeMemory Protocol

100

Evolution Engine 的领域知识 — 支持 LLM 从原始 OHLCV 数据中自主发现策略。涵盖生成-回测-选择-进化循环、向量化回测、样本外验证和策略梯度。在发现交易模式、运行回测、进化策略或审查进化日志时使用。由“evolve”、“discover patterns”、“backtest”、“evolution”、“strategy generation”、“candidate strategy”触发。

技能
mnemox-ai

Gdpr Dsgvo Expert

100

GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GDPR compliance assessments, privacy audits, data protection planning, DPIA generation, and data subject rights management.

技能
alirezarezvani

Ship Gate

100

Pre-production audit that scans a codebase for security, database, deployment, code quality, AI/LLM, dependency, frontend, and observability issues. Intercepts deploy commands and blocks until critical items pass. Stack-agnostic. Use for "run ship gate", "am I ready to ship", "pre-launch audit", "can I deploy", "push to production", "go live checklist", "preflight check". Not for CI/CD setup or infra provisioning.

技能
alirezarezvani

Context Mode Ops

100

使用并行子代理军队管理 context-mode GitHub 问题、PR、发布和营销。为每个任务编排 10-20 个动态代理。在分类问题、审查 PR、发布版本、撰写 LinkedIn 帖子、宣布发布、修复错误、合并贡献、验证 ENV 变量、测试适配器或同步分支时使用。

技能
mksglu

Refactor Plan

100

Prioritized redesign action plan covering quick wins, medium effort, major rework

技能
Aboudjem

Type Audit

100

Typography-only audit covering font selection, type scale, readability, hierarchy, performance

技能
Aboudjem