Skip to content
Back to skills

Compliance Checklist

ASecurity

Pre-release security & compliance control checklist mapped to SOC 2 and ISO 27001. Use when preparing a release, doing a go/no-go review, an audit-readiness pass, or when the user mentions SOC 2, ISO 27001, access control, change management, audit logging, encryption, or incident response. Triggers on "compliance check", "pre-release review", "SOC 2", "ISO 27001", "audit readiness", "control gap".

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsrustgosecurity

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill compliance-checklist --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Compliance Checklist?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Compliance Checklist
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-compliance-checklist/badge)](https://www.skillsdirectory.com/skills/matthews-wong-compliance-checklist)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: compliance-checklist
description: 'Pre-release security & compliance control checklist mapped to SOC 2 and ISO 27001. Use when preparing a release, doing a go/no-go review, an audit-readiness pass, or when the user mentions SOC 2, ISO 27001, access control, change management, audit logging, encryption, or incident response. Triggers on "compliance check", "pre-release review", "SOC 2", "ISO 27001", "audit readiness", "control gap".'
---

# Compliance Checklist

A lean, framework-mapped control checklist for pre-release reviews. Grade each item **Pass / Gap / N/A / Needs-evidence** — never Pass without evidence.

## Five control categories

### 1. Access control
- Least-privilege enforced; no wildcard/admin defaults.
- Auth required on every non-public endpoint; authz checked server-side.
- No hardcoded credentials; secrets from a manager/env, not the repo.
- MFA / SSO for privileged access where applicable.

### 2. Change management
- Change went through PR review and CI checks.
- Migrations are reversible or have a documented rollback.
- Release is versioned and traceable to an approved change.
- No direct-to-production changes bypassing the pipeline.

### 3. Logging & monitoring
- Security-relevant events logged (authn, authz failures, admin actions).
- Logs exclude secrets and raw PII (masked/tokenized).
- Logs are tamper-resistant and retained per policy.
- Alerting exists for anomalies / failures.

### 4. Encryption
- TLS for all data in transit.
- Sensitive data encrypted at rest.
- Keys managed by a KMS; no keys in the repo; rotation defined.
- Strong, current algorithms (no MD5/SHA1 for security, no weak ciphers).

### 5. Incident response
- On-call / escalation path defined.
- Runbook exists for this component's likely failures.
- Breach/incident notification process referenced.
- Backups exist and restore is tested.

## How to use

Walk each category against the actual change set. Cite evidence for every Pass. Rank gaps by risk and give a Go / Go-with-conditions / No-go verdict.

## Framework mapping (progressive disclosure)

For SOC 2 Trust Services Criteria mappings, read `reference/soc2.md`. For ISO 27001 Annex A control mappings, read `reference/iso27001.md`. Load only the framework you need. These references give the control identifiers; do not invent numbers not listed there.

Files in this skill

  • SKILL.md2.3 KB
  • reference/iso27001.md2.3 KB
  • reference/soc2.md2.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…