fedramp
01Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
End-to-end FedRAMP authorization guidance — readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
End-to-end FedRAMP authorization guidance — readiness assessments, SSP narratives, POA&M management, NIST 800-53 Rev 5 control mapping, and ConMon support.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert guidance for FedRAMP certification and compliance. Use this skill whenever a user asks about FedRAMP authorization, ATO (Authority to Operate), cloud security for federal government, NIST SP 800-53 controls, CSP compliance, or any of the core FedRAMP document types: SSP, SAP, SAR, POA&M, CIS/CRM workbooks. Also…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
GDPR compliance assistant — code and system audits, privacy notice drafting, DPAs, DPIAs, data flow reviews, and authoritative article-cited Q&A.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing Agreements (DPAs), and consent notices, (3) answering GDPR compliance questions with authoritative article citations, and…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
HIPAA compliance advisor covering Privacy Rule, Security Rule, and Breach Notification — document generation, technical safeguards for cloud, and breach response.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert HIPAA compliance assistant for healthcare and software contexts. Use this skill whenever the user mentions HIPAA, PHI (Protected Health Information), ePHI, covered entities, business associates, healthcare data privacy, medical records, health information security, BAA (Business Associate Agreements), or any…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
Expert ISO 27001 gap analysis, policy writing, Annex A control guidance, SoA generation, and risk register creation for both 2013 and 2022 versions.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
ISO 42001 AI Management System (AIMS) advisor — gap analysis, AI risk assessment, AI system impact assessment (AISIA), Annex A control guidance, SoA generation, policy writing, and certification readiness for ISO/IEC 42001:2023.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert ISO 42001 AI Management System (AIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 42001:2023, AI governance, AI management systems, AI risk assessment, AI system impact assessment, Annex A controls for AI, Statement of Applicability for AI systems, AI policy, responsible AI, AI…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
NIST Cybersecurity Framework (CSF 2.0 and 1.1) advisor — gap assessments, organisational profiles, implementation tiers, roadmaps, cross-framework mapping, and cybersecurity policy generation.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert NIST Cybersecurity Framework (CSF) advisor covering CSF 2.0 and CSF 1.1. Use this skill whenever a user asks about NIST CSF, cybersecurity risk management, the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), CSF profiles, implementation tiers, gap assessments, organizational profiles…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
PCI DSS v4.0.1 compliance advisor — CDE scoping, SAQ selection, gap assessments, control implementation guidance, QSA audit preparation, and remediation planning.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert PCI DSS compliance advisor covering PCI DSS v4.0.1 (current) and v4.0. Use this skill whenever a user asks about PCI DSS, payment card security, cardholder data protection, CDE scoping, SAQ types (A, A-EP, B, B-IP, C, C-VT, P2PE, D), ROC, AOC, QSA assessments, ASV scans, merchant levels, service provider…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
Expert SOC 2 compliance advisor covering all Trust Services Criteria — gap analysis, policy drafting, control documentation, audit evidence, and vendor risk.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P). Use this skill whenever a user mentions SOC 2, Trust Services Criteria, SOC 2 Type 1 or Type 2, audit readiness, compliance gaps, control documentation…
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Plugin Claude Code
TSA cybersecurity compliance advisor for critical infrastructure — pipeline, freight rail, and transit Security Directive requirements including CIP/COIP, IRP, ADR, CAP, incident reporting, and OT/ICS security.
Jandyoverseas977/Claude-Skills-Governance-Risk-and-Compliance
Skill Claude CodeCodex
Expert TSA cybersecurity compliance advisor for critical infrastructure owners and operators. Use this skill whenever a user asks about TSA Security Directives for pipelines, freight railroads, passenger rail, public transit, or bus operators; the TSA Cyber Risk Management Program (CRMP); Cybersecurity Implementation…