Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Compliance Mapper

ASecurity

Map security controls across frameworks — one control set satisfying ISO 27001, SOC 2, NIST, PCI DSS, and more.

2 stars
0 votes
0 copies
1 views
Added 9/29/2026
ai-agentsgotestinggitapisecuritydocumentation

Works with

api

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill compliance-mapper --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Compliance Mapper?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Compliance Mapper
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-compliance-mapper/badge)](https://www.skillsdirectory.com/skills/aicodedecode-compliance-mapper)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: compliance-mapper
description: Map security controls across frameworks — one control set satisfying ISO 27001, SOC 2, NIST, PCI DSS, and more.
category: security
---

## Overview

Most organizations face multiple compliance frameworks simultaneously — ISO 27001, SOC 2, PCI DSS, NIST CSF, plus sector and regional rules — and auditing each separately multiplies cost and fatigue. Control mapping solves this: build one unified control set, map each control to every framework's requirements, and test once to satisfy many.

This skill covers building and operating the mapping: framework analysis, unified control design, evidence reuse, and keeping the mapping current as frameworks evolve.

Map to the strongest requirement, not the average: when frameworks differ on a control (e.g., review frequency), implement the strictest version once. A single control that satisfies the toughest framework automatically satisfies the lenient ones — this is where the efficiency comes from.

## When to use

- Facing 2+ frameworks and drowning in duplicate audit work.
- Building the initial control set for a growing company.
- Preparing for a new certification while maintaining existing ones.
- Rationalizing controls after mergers or rapid growth.
- Responding to customer questionnaires efficiently.

## Core concepts

- **Unified control framework.** One set of controls with clear ownership, each mapped to the relevant clauses of every applicable framework (ISO 27001 Annex A, SOC 2 criteria, PCI DSS requirements, NIST CSF subcategories).
- **Map once, test once, use many times.** A single test of access reviews produces evidence usable for ISO A.5.17, SOC 2 CC6.2, and PCI DSS 7.x — the mapping is what makes reuse legitimate.
- **Gap analysis per framework.** The unified set reveals exactly what each new framework adds — usually 10–20% net-new controls, not a whole new program. Scope new certifications precisely.
- **Authoritative sources.** Use official mappings where they exist (framework crosswalks published by the bodies) and validate custom mappings with auditors before relying on them.
- **Evidence architecture.** Centralized evidence repository tagged by control — when the SOC 2 auditor asks, you pull the same tested evidence the ISO auditor saw, with the mapping as the bridge.
- **Framework versioning.** Frameworks update (ISO 27001:2022, PCI DSS v4.0, NIST CSF 2.0) — track versions in the mapping and run delta analyses on each release.
- **Control inheritance.** Cloud providers and shared services provide some controls (physical security, hypervisor patching) — document inheritance explicitly rather than re-testing what you cannot test.

- **Control inheritance documentation.** For cloud/shared-service inherited controls, document exactly what is inherited, from whom, and the evidence source — vague inheritance claims fail audits.
- **Mapping maintenance ownership.** Assign an owner to the mapping itself with a review cadence; unowned mappings rot silently as frameworks evolve.

## Practical workflow

1. **Inventory obligations:** list every framework, regulation, and customer requirement in scope, with versions and audit cycles. This is the demand side.
2. **Build the unified set:** draft controls covering the union of requirements, mapped clause-by-clause. Start from the strictest requirements; consolidate duplicates ruthlessly.
3. **Assign ownership and evidence:** every control gets an owner, a defined evidence artifact, and a testing cadence. Unowned controls are unimplemented controls.
4. **Run gap analyses:** for each framework, show mapped vs missing. New certifications become scoped projects (the 15% delta), not new programs.
5. **Test once:** execute the control testing program on its own cadence; tag evidence to controls; auditors across frameworks consume the same tested evidence via the mapping.
6. **Maintain:** update mappings on framework revisions; review control effectiveness annually; prune controls that no framework or risk requires.

### Quick wins

- Pick your two heaviest frameworks and map their overlap this quarter
- Centralize audit evidence in one tagged repository before the next audit cycle
- Run a delta analysis on the most recent framework version update

### Sustaining the practice

- Review framework updates within 90 days of publication; run delta mappings
- Re-validate custom mappings with auditors annually
- Audit the evidence repository for completeness before each audit cycle
- Retire controls that have lost their framework or risk justification

### Metrics that prove it works

- Audit effort hours per framework, trending down with reuse
- % of controls with current, tested evidence
- Time to onboard a new framework (should shrink with each addition)
- Audit finding recurrence across frameworks (same root cause, multiple reports)

## Common pitfalls

- **Mapping without testing.** A beautiful spreadsheet of mappings with untested controls is fiction. The mapping's value comes from tested evidence behind it.
- **Framework-of-the-month controls.** Bolting on controls per audit creates sprawl. Route every new requirement through the unified set first.
- **Ignoring version drift.** Auditing against ISO 27001:2013 mappings two years after 2022 published. Track versions explicitly.
- **Over-mapping.** Mapping every control to every framework "just in case" creates maintenance hell. Map where genuine overlap exists; keep the rest framework-specific.
- **No auditor buy-in.** Custom mappings the auditor rejects waste the effort. Validate mapping approaches with auditors early.
- **Evidence silos.** Each audit team collecting its own evidence destroys the reuse model. Centralize the repository and enforce tagging.
- **Confusing mapping with compliance.** The map shows coverage; only implemented, tested controls provide it. Report control effectiveness, not mapping completeness.
- **Static mapping.** Frameworks, products, and risks change. An unmaintained mapping quietly becomes wrong — schedule its maintenance like any control.
- **Mapping at the wrong granularity.** One-to-one clause mapping where many-to-many is the reality (or vice versa) produces misleading coverage claims. Map honestly.
- **Letting consultants own the mapping.** External mappings you cannot maintain internally decay the day the engagement ends. Build internal ownership from the start.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →