Use for governance, risk, compliance, privacy, audit readiness, control mapping, SOC 2, ISO 27001, NIST CSF, CIS, GDPR, legal/regulatory scoping, policy evidence, vendor risk, and security program maturity work.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add 26zl/cybersec-toolkit --skill grc-compliance-privacy-program --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Grc Compliance Privacy Program?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/26zl-grc-compliance-privacy-program)More formats (shields.io, HTML) on the badges page.
---
name: grc-compliance-privacy-program
description: Use for governance, risk, compliance, privacy, audit readiness, control mapping, SOC 2, ISO 27001, NIST CSF, CIS, GDPR, legal/regulatory scoping, policy evidence, vendor risk, and security program maturity work.
---
# GRC, compliance, and privacy program workflow
Use this skill when the task is about proving security, governing risk, mapping controls, privacy obligations, audit readiness, or legal/regulatory scoping.
## Guardrails
- Do not provide legal advice. For region-specific legal obligations, check current official sources and recommend counsel review.
- Do not claim certification, compliance, or audit pass/fail without evidence from the user's environment.
- Prefer control intent, evidence, owner, frequency, and test procedure over vague policy language.
## Workflow
1. Scope the organization, jurisdiction, sector, data classes, systems, third parties, and target frameworks.
2. Build a control crosswalk only for relevant frameworks; avoid mapping everything to everything.
3. For each control, define:
- control objective
- owner
- implementation evidence
- operating evidence
- test method
- cadence
- gap/risk
4. Separate policy existence from operational effectiveness.
5. Produce a remediation plan with risk, effort, owner, and evidence needed to close.
## Output pattern
Use a table like:
| Area | Requirement | Current evidence | Gap | Risk | Owner | Next action |
| --- | --- | --- | --- | --- | --- | --- |
For privacy work, include data inventory, lawful basis/processing purpose, retention, access, transfer, processor/subprocessor, DSAR, deletion, breach notification, and logging requirements.
Is this your skill, or is something wrong with this listing? . Author removals are honored within 72 hours.
No comments yet. Be the first to comment!