security-compliance-compliance-check
监管合规助手
此技能帮助开发者和安全团队评估GDPR、HIPAA、SOC2和PCI-DSS的合规准备状态,并提供可操作的实施指导和审计支持。
下载技能 ZIP
在 Claude 中上传
前往 设置 → 功能 → 技能 → 上传技能
开启并开始使用
测试它
正在使用“security-compliance-compliance-check”。 Help me understand the key requirements for GDPR compliance
预期结果:
GDPR compliance requires addressing several core areas:
1. Lawful Basis for Processing - Document your legal basis (consent, contract, legitimate interest)
2. Data Subject Rights - Implement processes for access, rectification, erasure, portability
3. Data Protection by Design - Include privacy from the start of any new system
4. Data Breach Procedures - 72-hour notification process to authorities
5. DPIA Requirements - Data Protection Impact Assessments for high-risk processing
Key evidence needed: Privacy policy, consent records, data processing agreements, breach log, DPIA documentation
正在使用“security-compliance-compliance-check”。 What are the SOC2 Trust Principles I need to implement?
预期结果:
SOC2 Trust Principles fall into two categories:
**Common Criteria (Mandatory)**:
- Security (CC1-CC9): Access controls, encryption, monitoring
- Availability (A1): Uptime guarantees, disaster recovery
**Optional Principles**:
- Processing Integrity: Accuracy of data processing
- Confidentiality: Handling of sensitive data
- Privacy: PII protection practices
Each principle has specific controls mapped to them. The Security principle is required for all audits.
安全审计
安全This skill is a legitimate regulatory compliance assistant. All static findings are false positives: code fence markers (```) were incorrectly flagged as command execution, SOC2 (compliance framework) was flagged as C2, strong TLS cipher configurations were flagged as weak crypto, and the word 'audit' triggered system reconnaissance alerts. No actual malicious behavior or prompt injection attempts detected.
质量评分
你能构建什么
初步合规评估
对照适用的监管要求评估当前系统架构和数据流,以识别差距并确定修复工作的优先级。
控制实施指南
获取可操作代码示例和配置指导,用于实施特定合规控制,如加密、访问日志和数据脱敏。
审计文档生成器
生成策略模板、审计跟踪配置和证据收集程序,用于即将进行的合规评估。
试试这些提示
帮助我了解{regulation}合规的关键要求。主要控制类别有哪些?我需要提供什么证据来通过审计?我需要为{regulation}合规实施{control_type}。请给我展示{specific_requirement}的代码示例,包括日志记录和监控。我将在{timeframe}进行{regulation}审计。我需要准备什么文档?应该准备什么证据?有哪些常见问题我应该优先处理?最佳实践
- 在开始合规工作前完全映射数据流,以了解哪些法规适用
- 从最关键的控制(访问控制、加密、日志记录)开始,然后再处理管理要求
- 记录所有合规决策及其理由,以随时间积累审计证据
避免
- 在没有正式评估的情况下声称合规——此技能有所帮助,但不能替代认证审计师
- 将合规视为一次性项目而非持续维护
- 仅关注技术控制而忽视管理和物理安全措施