From grc
Gap-assess an organization or system against a compliance framework (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF/800-53), mapping controls to evidence, identifying gaps, and producing a prioritized remediation and audit-readiness plan. Use for compliance gap analysis, certification prep, or audit readiness.
How this skill is triggered — by the user, by Claude, or both
Slash command
/grc:compliance-assessmentThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A clear picture of where the org stands against the chosen framework: which controls
A clear picture of where the org stands against the chosen framework: which controls are met, partial, or missing; the evidence for each; and a prioritized path to compliant + audit-ready.
reference.md for a per-framework map.cloud-security, sast-sca, detection-engineering).risk-assessment), and the effort to close.A compliance gap analysis: control · requirement · status · evidence · gap · owner ·
priority · target date, plus a remediation roadmap and an evidence index. Use
security-reporting; visualize control coverage with security-diagramming.
Compliance ≠ security, but done well it raises the floor — map controls to real evidence, not aspirational policy. Many frameworks overlap heavily (ISO 27001, SOC 2, NIST); assess once and map to several to avoid duplicate work. Verify the current version of each framework. Track gaps with owners and dates — an audit is a deadline.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin grc