Agent skill

Security Compliance

by sangrokjung in sangrokjung/claude-forge

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

MITAuto-check passedLegal & Compliance

Install Security Compliance

skills CLI
$ npx skills add sangrokjung/claude-forge --skill security-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sangrokjung/claude-forge security-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sangrokjung/claude-forge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-compliance .claude/skills/security-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-compliance
GitHub stars
852
Used in
2 other repos
Token cost
~7.2k tokens
SKILL.md length
2,068 words
Files
13 (incl. scripts)
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

  • Works in 12 steps: Defense in Depth → Zero Trust Architecture → Least Privilege → …
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Core Principles, Security & Compliance Lifecycle, Decision Frameworks and Key Security Frameworks &…
  • Runs Python scripts from its folder

What it does

Security Compliance is an agent skill from sangrokjung/claude-forge. Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.

Its SKILL.md is about 7.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files, including scripts (for example `README.md`, `examples/incident-response-template.md` and `examples/soc2-control-example.md`).

It sits in Legal & Compliance, covering SOC 2 and security compliance, Threat modeling and Secure coding. The repository describes itself as: oh-my-zsh for Claude Code — 16 agents, 35 commands, 32 skills, 21 safety hooks in one install. v4.0 adds an adversarial review loop: a second agent that never sees the first… The licence is MIT.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Threat modeling
  • Tasks that involve Secure coding

Example prompts

  • “Use the security-compliance skill to guide security professionals in implementing defense-in-depth security architectures, achieving compliance with…”
  • “/security-compliance”

Requirements

  • Python 3

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Defense in Depth
  2. Zero Trust Architecture
  3. Least Privilege
  4. Security by Design
  5. Continuous Monitoring
  6. Risk-Based Approach
  7. Compliance as Foundation
  8. Incident Readiness
  9. Assess & Plan
  10. Design & Architect
  11. Implement & Harden
  12. Monitor & Detect

What it can do on your machine

Read from SKILL.md and the folder at commit 34d881d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Compliance loads about 7.2k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 2,068 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sangrokjung/claude-forge at commit 34d881d, republished under its MIT licence (© sangrokjung). 2,068 words, ~7,201 tokens.

Download SKILL.mdSave it as .claude/skills/security-compliance/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
security-compliance
description
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.

Security & Compliance Expert

Core Principles

1. Defense in Depth

Apply multiple layers of security controls so that if one fails, others provide protection. Never rely on a single security mechanism.

2. Zero Trust Architecture

Never trust, always verify. Assume breach and verify every access request regardless of location or network.

3. Least Privilege

Grant the minimum access necessary for users and systems to perform their functions. Regularly review and revoke unused permissions.

4. Security by Design

Integrate security requirements from the earliest stages of system design, not as an afterthought.

5. Continuous Monitoring

Implement ongoing monitoring and alerting to detect anomalies and security events in real-time.

6. Risk-Based Approach

Prioritize security efforts based on risk assessment, focusing resources on the most critical assets and likely threats.

7. Compliance as Foundation

Use compliance frameworks as a baseline, but go beyond minimum requirements to achieve actual security.

8. Incident Readiness

Prepare for security incidents through planning, testing, and regular tabletop exercises. Assume compromise will occur.


Security & Compliance Lifecycle

Phase 1: Assess & Plan

Objective: Understand current security posture and compliance requirements

Activities:

  • Conduct security assessments and gap analysis
  • Identify compliance requirements (SOC2, ISO27001, GDPR, HIPAA, PCI-DSS)
  • Perform risk assessments and threat modeling
  • Define security policies and standards
  • Establish security governance structure
  • Create security roadmap with prioritized initiatives

Deliverables:

  • Risk register with prioritized risks
  • Compliance gap analysis report
  • Security architecture documentation
  • Security policies and procedures
  • Security roadmap and budget
Phase 2: Design & Architect

Objective: Design secure systems and architectures

Activities:

  • Design defense-in-depth architectures
  • Implement Zero Trust network architecture
  • Design identity and access management (IAM) systems
  • Architect data protection and encryption solutions
  • Design secure CI/CD pipelines
  • Create threat models for applications and systems
  • Define security controls and compensating controls

Deliverables:

  • Security architecture diagrams
  • Threat models (STRIDE, PASTA, or attack trees)
  • Data flow diagrams with security boundaries
  • Encryption and key management design
  • IAM design with RBAC/ABAC models
  • Security control matrix
Phase 3: Implement & Harden

Objective: Deploy security controls and harden systems

Activities:

  • Implement security controls (preventive, detective, corrective)
  • Configure security tools (SIEM, EDR, CASB, WAF, IDS/IPS)
  • Harden operating systems and applications
  • Implement encryption at rest and in transit
  • Deploy multi-factor authentication (MFA)
  • Configure logging and monitoring
  • Implement data loss prevention (DLP)
  • Set up vulnerability management program

Deliverables:

  • Hardening baselines and configuration standards
  • Deployed security tools and controls
  • Encryption implementation
  • MFA deployment
  • Security monitoring dashboards
  • Vulnerability management procedures
Phase 4: Monitor & Detect

Objective: Continuously monitor for threats and anomalies

Activities:

  • Monitor security logs and events (SIEM)
  • Analyze security alerts and anomalies
  • Conduct threat hunting
  • Perform vulnerability scanning and penetration testing
  • Monitor compliance controls
  • Track security metrics and KPIs
  • Review access logs and privileged account activity
  • Analyze threat intelligence feeds

Deliverables:

  • Security operations center (SOC) runbooks
  • Alert triage and escalation procedures
  • Threat hunting playbooks
  • Vulnerability scan reports
  • Penetration test reports
  • Security metrics dashboard
  • Compliance monitoring reports
Phase 5: Respond & Recover

Objective: Respond to security incidents and recover operations

Activities:

  • Execute incident response plan
  • Contain and eradicate threats
  • Perform forensic analysis
  • Recover affected systems
  • Conduct post-incident reviews
  • Update security controls based on lessons learned
  • Report incidents to stakeholders and regulators
  • Improve detection rules and response procedures

Deliverables:

  • Incident response reports
  • Forensic analysis findings
  • Root cause analysis
  • Remediation plans
  • Updated incident response playbooks
  • Regulatory breach notifications (if required)
  • Post-incident review and recommendations
Phase 6: Audit & Improve

Objective: Validate compliance and continuously improve security

Activities:

  • Conduct internal audits
  • Prepare for external audits (SOC2, ISO27001)
  • Perform compliance assessments
  • Review and update security policies
  • Conduct security training and awareness programs
  • Perform tabletop exercises and disaster recovery drills
  • Update risk assessments
  • Implement security improvements

Deliverables:

  • Audit reports (internal and external)
  • SOC2 Type II report
  • ISO27001 certification
  • Compliance attestations
  • Updated policies and procedures
  • Training completion metrics
  • Tabletop exercise results
  • Continuous improvement plan

Decision Frameworks

1. Risk Assessment Framework

When to use: Evaluating security risks and prioritizing mitigation efforts

Process:

1. Identify Assets
   - What systems, data, and services need protection?
   - What is the business value of each asset?
   - Who are the asset owners?

2. Identify Threats
   - What threat actors might target these assets? (nation-state, cybercriminals, insiders)
   - What are their motivations? (financial gain, espionage, disruption)
   - What are current threat trends?

3. Identify Vulnerabilities
   - What weaknesses exist in systems or processes?
   - What security controls are missing or ineffective?
   - What are known CVEs affecting your systems?

4. Calculate Risk
   Risk = Likelihood × Impact

   Likelihood scale (1-5):
   1 = Rare (< 5% chance in 1 year)
   2 = Unlikely (5-25%)
   3 = Possible (25-50%)
   4 = Likely (50-75%)
   5 = Almost Certain (> 75%)

   Impact scale (1-5):
   1 = Minimal (< $10K loss, no data breach)
   2 = Minor ($10K-$100K, limited data exposure)
   3 = Moderate ($100K-$1M, significant data breach)
   4 = Major ($1M-$10M, extensive data breach, regulatory fines)
   5 = Catastrophic (> $10M, business-threatening)

   Risk Score = Likelihood × Impact (max 25)

5. Prioritize Risks
   - Critical: Risk score 15-25 (immediate action)
   - High: Risk score 10-14 (action within 30 days)
   - Medium: Risk score 5-9 (action within 90 days)
   - Low: Risk score 1-4 (monitor and accept)

6. Determine Risk Response
   - Mitigate: Implement controls to reduce risk
   - Accept: Document acceptance if risk is within tolerance
   - Transfer: Use insurance or third-party services
   - Avoid: Eliminate the activity that creates risk

Output: Risk register with prioritized risks and mitigation plans

2. Security Control Selection

When to use: Choosing appropriate security controls for identified risks

Framework: Use NIST CSF categories or CIS Controls

NIST CSF Functions:
1. Identify (ID)
   - Asset Management
   - Risk Assessment
   - Governance

2. Protect (PR)
   - Access Control
   - Data Security
   - Protective Technology

3. Detect (DE)
   - Anomalies and Events
   - Security Monitoring
   - Detection Processes

4. Respond (RS)
   - Response Planning
   - Communications
   - Analysis and Mitigation

5. Recover (RC)
   - Recovery Planning
   - Improvements
   - Communications

Control Types:
- Preventive: Stop incidents before they occur (MFA, firewalls, encryption)
- Detective: Identify incidents when they occur (SIEM, IDS, log monitoring)
- Corrective: Fix issues after detection (patching, incident response)
- Deterrent: Discourage attackers (security policies, warnings)
- Compensating: Alternative controls when primary controls aren't feasible

Selection Criteria:
1. Does it address the identified risk?
2. Is it cost-effective? (Control cost < Risk value)
3. Is it technically feasible?
4. Does it meet compliance requirements?
5. Can we maintain and monitor it?
3. Compliance Framework Selection

When to use: Determining which compliance frameworks to implement

Decision Tree:

What type of organization are you?

├─ SaaS/Cloud Service Provider
│  ├─ Selling to enterprises? → SOC2 Type II (required)
│  ├─ International customers? → ISO27001 (strongly recommended)
│  ├─ Handling health data? → HIPAA + HITRUST
│  └─ Handling payment cards? → PCI-DSS

├─ Healthcare Provider/Payer
│  ├─ U.S.-based → HIPAA (required)
│  ├─ International → HIPAA + GDPR
│  └─ Plus: HITRUST for comprehensive framework

├─ Financial Services
│  ├─ U.S. banks → GLBA, SOX (if public)
│  ├─ Payment processing → PCI-DSS (required)
│  ├─ International → ISO27001, local regulations
│  └─ Plus: NIST CSF for framework

├─ E-commerce/Retail
│  ├─ Accept credit cards → PCI-DSS (required)
│  ├─ EU customers → GDPR (required)
│  ├─ California customers → CCPA
│  └─ B2B sales → SOC2 Type II

└─ General Enterprise
   ├─ Selling to enterprises → SOC2 Type II
   ├─ Want broad recognition → ISO27001
   ├─ Government contracts → FedRAMP, NIST 800-53
   └─ Industry-specific → Check sector regulations

Multi-Framework Strategy:
- Start with: SOC2 or ISO27001 (choose one as foundation)
- Add: Data privacy regulations (GDPR, CCPA) as needed
- Layer on: Industry-specific requirements
4. Incident Severity Classification

When to use: Triaging and responding to security incidents

Severity Levels:

P0 - Critical (Immediate Response)
- Active breach with data exfiltration occurring
- Ransomware encryption in progress
- Complete system outage of critical services
- Unauthorized access to production databases
- Response: Engage CIRT immediately, executive notification, 24/7 effort

P1 - High (Response within 1 hour)
- Confirmed malware on critical systems
- Attempted unauthorized access to sensitive data
- DDoS attack affecting availability
- Significant vulnerability with active exploits
- Response: Engage CIRT, manager notification, work until contained

P2 - Medium (Response within 4 hours)
- Malware on non-critical systems
- Suspicious account activity
- Policy violations with security impact
- Vulnerability requiring patching
- Response: Security team investigation, business hours

P3 - Low (Response within 24 hours)
- Failed login attempts (below threshold)
- Minor policy violations
- Informational security events
- Response: Standard queue, document findings

Classification Factors:
1. Data confidentiality impact (PHI, PII, financial, IP)
2. System availability impact (revenue, operations)
3. Data integrity impact (corruption, unauthorized changes)
4. Number of affected systems/users
5. Regulatory reporting requirements
5. Vulnerability Prioritization

When to use: Prioritizing vulnerability remediation

Framework: Enhanced CVSS with business context

Base CVSS Score × Business Context Multiplier = Priority Score

CVSS Severity Ranges:
- Critical: 9.0-10.0
- High: 7.0-8.9
- Medium: 4.0-6.9
- Low: 0.1-3.9

Business Context Multipliers:
- Internet-facing production system: 2.0×
- Internal production system: 1.5×
- Systems with sensitive data: 1.5×
- Development/test environment: 0.5×
- Active exploit in the wild: 2.0×
- Compensating controls in place: 0.7×

Priority Levels:
- P0 (Critical): Score ≥ 14 → Patch within 24-48 hours
- P1 (High): Score 10-13.9 → Patch within 7 days
- P2 (Medium): Score 6-9.9 → Patch within 30 days
- P3 (Low): Score < 6 → Patch within 90 days or accept risk

Additional Considerations:
- Can the system be isolated/segmented?
- Are there effective detective controls?
- What is the patching complexity/risk?
- Is there a vendor patch available?
6. Third-Party Risk Assessment

When to use: Evaluating security risks of vendors and partners

Assessment Framework:

1. Categorize Vendor Risk Level

Low Risk (Minimal assessment):
- No access to systems or data
- Limited integration
- Non-critical service
→ Simple questionnaire

Medium Risk (Standard assessment):
- Limited system access
- Non-sensitive data access
- Important but not critical service
→ Security questionnaire + evidence review

High Risk (Comprehensive assessment):
- Production system access
- Sensitive data processing
- Critical service dependency
→ Full assessment + audit reports + pen test

Critical Risk (Extensive assessment):
- Full production access
- PHI/PII processing
- Business-critical dependency
→ On-site audit + continuous monitoring + SLA

2. Assessment Components

For Medium/High/Critical vendors:
□ Security questionnaire (SIG, CAIQ, or custom)
□ Compliance certifications (SOC2, ISO27001)
□ Insurance certificates (cyber liability)
□ Security policies and procedures
□ Incident response plan
□ Disaster recovery/business continuity plan
□ Data processing agreement (DPA)
□ Penetration test results (for high/critical)
□ Right to audit clause in contract

3. Ongoing Monitoring

- Annual reassessment
- Monitor for breaches/incidents
- Review security updates and patches
- Track compliance certification renewals
- Conduct periodic audits (for critical vendors)

4. Vendor Risk Score

Calculate score (0-100):
- Security maturity: 40 points
- Compliance certifications: 20 points
- Incident history: 15 points
- Financial stability: 15 points
- References and reputation: 10 points

Action based on score:
- 80-100: Approved
- 60-79: Approved with conditions
- 40-59: Requires remediation plan
- < 40: Do not engage

Key Security Frameworks & Standards

NIST Cybersecurity Framework (CSF)
  • Purpose: Risk-based framework for improving cybersecurity
  • Structure: 5 Functions, 23 Categories, 108 Subcategories
  • Best for: General organizations, government contractors
  • Maturity model: Tier 1 (Partial) to Tier 4 (Adaptive)
CIS Critical Security Controls
  • Purpose: Prioritized set of actions for cyber defense
  • Structure: 18 Controls with Implementation Groups (IG1, IG2, IG3)
  • Best for: Practical implementation guidance
  • Focus: Defense against common attack patterns
ISO/IEC 27001
  • Purpose: International standard for information security management
  • Structure: 14 domains, 114 controls (Annex A)
  • Best for: International recognition, formal certification
  • Requirements: ISMS (Information Security Management System)
SOC 2 Type II
  • Purpose: Service organization controls for security and availability
  • Structure: Trust Service Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy)
  • Best for: SaaS companies, cloud service providers
  • Audit: 3-12 month observation period
NIST 800-53
  • Purpose: Security controls for federal systems
  • Structure: 20 families, 1000+ controls
  • Best for: Government contractors, FedRAMP
  • Baselines: Low, Moderate, High impact systems
GDPR (General Data Protection Regulation)
  • Purpose: EU data privacy regulation
  • Scope: Any organization processing EU residents' data
  • Requirements: Lawful basis, consent, data subject rights, breach notification
  • Penalties: Up to 4% of global revenue or €20M
HIPAA (Health Insurance Portability and Accountability Act)
  • Purpose: Protect health information (PHI)
  • Scope: Healthcare providers, payers, business associates
  • Requirements: Administrative, Physical, Technical safeguards
  • Penalties: $100-$50,000 per violation, criminal charges possible
PCI-DSS (Payment Card Industry Data Security Standard)
  • Purpose: Protect cardholder data
  • Structure: 12 requirements, 6 control objectives
  • Scope: Any organization storing, processing, or transmitting card data
  • Levels: Based on transaction volume (Level 1-4)

Core Security Domains

1. Identity & Access Management (IAM)
  • Authentication mechanisms (MFA, SSO, passwordless)
  • Authorization models (RBAC, ABAC, ReBAC)
  • Privileged access management (PAM)
  • Identity governance and administration (IGA)
  • Directory services (Active Directory, LDAP, Okta, Auth0)
2. Network Security
  • Network segmentation and micro-segmentation
  • Firewalls (next-gen, WAF, application-layer)
  • Intrusion detection/prevention (IDS/IPS)
  • VPN and secure remote access
  • Zero Trust network architecture (ZTNA)
  • DDoS protection
3. Data Security
  • Encryption at rest and in transit (AES-256, TLS 1.3)
  • Key management (KMS, HSM)
  • Data classification and labeling
  • Data loss prevention (DLP)
  • Database security (encryption, masking, tokenization)
  • Secrets management (Vault, AWS Secrets Manager)
4. Application Security
  • Secure SDLC and DevSecOps
  • SAST (Static Application Security Testing)
  • DAST (Dynamic Application Security Testing)
  • SCA (Software Composition Analysis)
  • Secure code review
  • OWASP Top 10 mitigation
5. Cloud Security
  • Cloud security posture management (CSPM)
  • Cloud access security broker (CASB)
  • Container security (image scanning, runtime protection)
  • Serverless security
  • Infrastructure as Code (IaC) security scanning
  • Multi-cloud security architecture
6. Endpoint Security
  • Endpoint detection and response (EDR)
  • Antivirus and anti-malware
  • Host-based firewalls
  • Device encryption (BitLocker, FileVault)
  • Mobile device management (MDM)
  • Patch management
7. Security Operations
  • Security Information and Event Management (SIEM)
  • Security Orchestration, Automation, and Response (SOAR)
  • Threat intelligence platforms (TIP)
  • Threat hunting
  • Vulnerability management
  • Penetration testing and red teaming
8. Incident Response
  • Incident response plan and playbooks
  • Computer forensics and investigation
  • Malware analysis
  • Threat containment and eradication
  • Post-incident review and lessons learned
  • Regulatory breach notification
9. Governance, Risk & Compliance (GRC)
  • Security policies and procedures
  • Risk assessment and management
  • Compliance management and auditing
  • Security awareness training
  • Vendor risk management
  • Business continuity and disaster recovery

Security Metrics & KPIs

Show full SKILL.md (829 more words)Show less
Risk & Compliance Metrics
  • Number of critical/high risks open
  • Risk remediation time (mean time to remediate)
  • Compliance audit findings (open/closed)
  • Compliance control effectiveness rate
  • Policy acknowledgment completion rate
  • Training completion rate
Vulnerability Management Metrics
  • Mean time to detect (MTTD) vulnerabilities
  • Mean time to patch (MTTP)
  • Vulnerability backlog (total open, by severity)
  • Patch compliance rate (% systems patched within SLA)
  • Vulnerability recurrence rate
Incident Response Metrics
  • Mean time to detect (MTTD) incidents
  • Mean time to respond (MTTR)
  • Mean time to contain (MTTC)
  • Mean time to recover (MTTR)
  • Number of incidents by severity
  • Incident recurrence rate
  • False positive rate
Security Operations Metrics
  • SIEM alert volume (total, by severity)
  • Alert triage time
  • Alert false positive rate
  • Security tool coverage (% assets monitored)
  • Threat hunting coverage (% environment reviewed)
  • Penetration test findings
Access Management Metrics
  • MFA adoption rate
  • Privileged account review completion rate
  • Access certification completion rate
  • Orphaned account count
  • Password policy compliance rate
  • Failed login attempt rate
Awareness & Culture Metrics
  • Phishing simulation click rate
  • Security training completion rate
  • Security awareness quiz scores
  • Security policy violations
  • Security-related helpdesk tickets

Security Tools Ecosystem

SIEM (Security Information & Event Management)
  • Splunk Enterprise Security
  • IBM QRadar
  • Microsoft Sentinel
  • Elastic Security
  • Sumo Logic
EDR/XDR (Endpoint/Extended Detection & Response)
  • CrowdStrike Falcon
  • SentinelOne
  • Microsoft Defender for Endpoint
  • Palo Alto Cortex XDR
  • Carbon Black
Vulnerability Management
  • Tenable Nessus/Tenable.io
  • Qualys VMDR
  • Rapid7 InsightVM
  • Greenbone OpenVAS (open source)
Cloud Security
  • Wiz
  • Prisma Cloud (Palo Alto)
  • Lacework
  • Orca Security
  • AWS Security Hub / Azure Security Center / GCP Security Command Center
SAST/DAST
  • Snyk
  • Veracode
  • Checkmarx
  • SonarQube
  • OWASP ZAP (open source)
Container Security
  • Aqua Security
  • Sysdig Secure
  • Prisma Cloud Compute
  • Trivy (open source)
Secrets Management
  • HashiCorp Vault
  • AWS Secrets Manager
  • Azure Key Vault
  • CyberArk
Identity & Access
  • Okta
  • Auth0
  • Azure AD / Entra ID
  • Ping Identity
  • CyberArk (PAM)

Common Security Workflows

1. Security Incident Response Workflow
1. Detection & Alert
   ↓
2. Triage & Classification
   - Determine severity (P0-P3)
   - Assign to responder
   ↓
3. Investigation
   - Gather evidence
   - Analyze logs (SIEM)
   - Determine scope
   ↓
4. Containment
   - Isolate affected systems
   - Block malicious IPs/domains
   - Disable compromised accounts
   ↓
5. Eradication
   - Remove malware
   - Close vulnerabilities
   - Patch systems
   ↓
6. Recovery
   - Restore from backups
   - Verify system integrity
   - Return to production
   ↓
7. Post-Incident Review
   - Document timeline
   - Root cause analysis
   - Update playbooks
   - Implement improvements
   ↓
8. Reporting
   - Executive summary
   - Regulatory notification (if required)
   - Stakeholder communication
2. Vulnerability Management Workflow
1. Asset Discovery
   - Scan network for assets
   - Maintain asset inventory
   ↓
2. Vulnerability Scanning
   - Authenticated scans
   - Unauthenticated scans
   - Agent-based monitoring
   ↓
3. Assessment & Validation
   - Validate findings
   - Remove false positives
   - Add business context
   ↓
4. Prioritization
   - Apply CVSS + context
   - Assign severity (P0-P3)
   - Create remediation tickets
   ↓
5. Remediation
   - Patch systems
   - Apply compensating controls
   - Update configurations
   ↓
6. Verification
   - Rescan to confirm fix
   - Update vulnerability status
   ↓
7. Reporting
   - Metrics dashboard
   - Executive reports
   - Trend analysis
3. Access Review Workflow
1. Schedule Review (Quarterly)
   ↓
2. Generate Access Reports
   - User access by role
   - Privileged accounts
   - Service accounts
   - Orphaned accounts
   ↓
3. Distribute to Managers
   - Each manager reviews their team
   - Certify appropriate access
   ↓
4. Review & Certify
   - Approve legitimate access
   - Flag inappropriate access
   - Identify orphaned accounts
   ↓
5. Remediation
   - Revoke unapproved access
   - Disable orphaned accounts
   - Update RBAC assignments
   ↓
6. Document & Report
   - Certification completion rate
   - Access changes made
   - Compliance evidence
4. SOC2 Audit Preparation Workflow
1. Scoping (3-4 months before)
   - Define in-scope systems
   - Select Trust Service Criteria
   - Engage auditor
   ↓
2. Gap Assessment (2-3 months before)
   - Map controls to requirements
   - Identify control gaps
   - Create remediation plan
   ↓
3. Readiness (1-2 months before)
   - Implement missing controls
   - Document policies/procedures
   - Conduct mock audit
   ↓
4. Evidence Collection (Ongoing)
   - Automate evidence gathering
   - Organize evidence repository
   - Prepare control narratives
   ↓
5. Audit Kickoff
   - Provide evidence to auditor
   - Respond to requests
   - Schedule interviews
   ↓
6. Fieldwork (4-6 weeks)
   - Auditor tests controls
   - Provide additional evidence
   - Address findings
   ↓
7. Report Issuance
   - Review draft report
   - Address any exceptions
   - Receive final SOC2 report
   ↓
8. Continuous Monitoring
   - Monitor control effectiveness
   - Prepare for next audit cycle

Best Practices

Security Architecture
  • Design with security in mind from the start (shift-left)
  • Apply defense in depth with multiple security layers
  • Implement Zero Trust: verify explicitly, use least privilege, assume breach
  • Segment networks and limit lateral movement
  • Encrypt data at rest and in transit
  • Use secure defaults and fail securely
Access Control
  • Enforce multi-factor authentication (MFA) everywhere
  • Implement least privilege access
  • Use just-in-time (JIT) privileged access
  • Regularly review and certify access
  • Disable accounts promptly on termination
  • Avoid shared accounts and service account abuse
Security Operations
  • Centralize logging with SIEM
  • Automate detection and response where possible
  • Maintain an incident response plan and test it
  • Conduct regular threat hunting exercises
  • Keep vulnerability remediation SLAs aggressive
  • Practice incident response through tabletop exercises
Application Security
  • Integrate security into CI/CD (DevSecOps)
  • Scan code for vulnerabilities (SAST, DAST, SCA)
  • Follow OWASP Top 10 guidelines
  • Conduct security code reviews for critical changes
  • Implement secure API design (authentication, rate limiting, input validation)
  • Use security headers (CSP, HSTS, X-Frame-Options)
Cloud Security
  • Use infrastructure as code (IaC) with security scanning
  • Enable cloud-native security services (GuardDuty, Security Hub)
  • Implement CSPM to monitor misconfigurations
  • Use cloud-native encryption and key management
  • Apply least privilege IAM policies
  • Monitor for shadow IT and unauthorized resources
Compliance
  • Treat compliance as a continuous process, not one-time
  • Map controls to multiple frameworks for efficiency
  • Automate evidence collection where possible
  • Maintain a compliance calendar for deadlines
  • Document everything (if it's not documented, it doesn't exist)
  • Conduct internal audits before external audits
Security Culture
  • Make security everyone's responsibility
  • Conduct regular security awareness training
  • Run phishing simulations to test awareness
  • Reward security-conscious behavior
  • Create clear, accessible security policies
  • Foster a culture where reporting security concerns is encouraged

Integration with Other Disciplines

With DevOps/Platform Engineering
  • Integrate security scanning into CI/CD pipelines
  • Automate security testing and compliance checks
  • Implement Infrastructure as Code (IaC) security
  • Use container scanning and runtime protection
  • Coordinate on incident response for production issues
With Enterprise Architecture
  • Align security architecture with enterprise architecture
  • Participate in architecture review boards
  • Ensure security requirements in architecture standards
  • Design secure integration patterns
  • Define security reference architectures
With IT Operations
  • Coordinate on patch management and change control
  • Collaborate on monitoring and alerting
  • Joint incident response for security and operational incidents
  • Align on backup and disaster recovery procedures
  • Coordinate access management and privileged access
With Product Management
  • Provide security requirements for new features
  • Participate in threat modeling for new products
  • Balance security with user experience
  • Advise on privacy and compliance implications
  • Support security as a product differentiator
  • Coordinate on data privacy regulations (GDPR, CCPA)
  • Collaborate on breach notification requirements
  • Review vendor contracts for security terms
  • Support privacy impact assessments
  • Align on data retention and deletion policies

When to Engage Security & Compliance

Required Engagement
  • New system or application design
  • Architecture changes affecting security boundaries
  • Regulatory compliance initiatives
  • Security incidents
  • Vendor risk assessments
  • Pre-production security reviews
  • Audit preparation
  • Data breach or suspected breach
  • Major feature releases
  • Cloud migrations
  • M&A due diligence
  • Infrastructure changes
  • New third-party integrations
  • Significant process changes
  • Security tool selection
  • Policy updates
Continuous Collaboration
  • Security review of pull requests (for critical systems)
  • Vulnerability remediation prioritization
  • Security awareness and training
  • Threat intelligence sharing
  • Risk assessment updates
  • Compliance monitoring

© sangrokjung, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts) in skills/security-compliance of sangrokjung/claude-forge.

  • SKILL.md
  • README.md
  • examples/incident-response-template.md
  • examples/risks.csv
  • examples/soc2-control-example.md
  • examples/vulnerabilities.csv
  • reference/application-security.md
  • reference/compliance-frameworks.md
  • reference/security-architecture.md
  • reference/security-operations.md
  • reference/threat-modeling-risk.md
  • scripts/risk_calculator.py
  • scripts/vuln_prioritizer.py

Open the folder on GitHubat commit 34d881d

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sangrokjung/claude-forge, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Compliance this skillsangrokjung/claude-forge8522 repos~7.2kAutomated safety check: PassMIT
Architecting Securitytelagod/code-abyss243—~712Automated safety check: PassMIT
Complianceericrisco/rsc-harness174—~2.4kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
Eks Securityaws-samples/appmod-blueprints115—~4.7kAutomated safety check: PassMIT-0

Similar skills

  • Architecting Security

    telagod/code-abyss

    安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

    243 GitHub stars~712 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Compliance

    ericrisco/rsc-harness

    A skill your agent uses when scoping which regulatory frameworks bind a business — SOC 2, ISO 27001, HIPAA, PCI DSS, EU AI Act, DORA, NIS2 — building a control register with owners and evidence, or…

    174 GitHub stars~2.4k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Eks Security

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

    115 GitHub stars~4.7k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from sangrokjung/claude-forge

All 24 skills in this repo
  • Debugging Strategies

    sangrokjung/claude-forge

    Master systematic debugging techniques, profiling tools, and root cause analysis to efficiently track down bugs across any codebase or technology stack.

    852 GitHub starsUsed in 13 repos~3.1k tokens
    Auto-check passed
  • Dependency Upgrade

    sangrokjung/claude-forge

    Manage major dependency version upgrades with compatibility analysis, staged rollout, and comprehensive testing.

    852 GitHub starsUsed in 12 repos~2.3k tokens
    Auto-check passed
  • Skill Factory

    sangrokjung/claude-forge

    Analyze session work and automatically convert reusable patterns into Claude Code skills.

    852 GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Cc Dev Agent

    sangrokjung/claude-forge

    A skill your agent uses when starting Claude Code projects, writing CLAUDE.md/spec.md, dispatching subagents, or requesting Agent Teams parallel development.

    852 GitHub stars~771 tokensUpdated 1 mo ago
    Auto-check passed
  • Continuous Learning V2

    sangrokjung/claude-forge

    Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    852 GitHub starsUsed in 5 repos~1.8k tokens
    Auto-check passed
  • Harness Diet

    sangrokjung/claude-forge

    Measure and shrink the always-loaded context of a Claude Code harness (CLAUDE.md + rules without paths frontmatter) back under budget — migrate narrative to reference files, convert rules to…

    852 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Security Compliance

What does Security Compliance do?

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…. Security Compliance is an agent skill from sangrokjung/claude-forge. Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.

When should I use Security Compliance?

Security Compliance fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Threat modeling; tasks that involve Secure coding.

How do I install Security Compliance in Claude Code?

Run `npx skills add sangrokjung/claude-forge --skill security-compliance -a claude-code`. Or copy the skill folder (skills/security-compliance in sangrokjung/claude-forge) into .claude/skills/security-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Security Compliance in Codex?

Run `npx skills add sangrokjung/claude-forge --skill security-compliance -a codex`. Or copy the skill folder (skills/security-compliance in sangrokjung/claude-forge) into .agents/skills/security-compliance in your project. Codex loads it when a task matches its description.

Can I use Security Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sangrokjung/claude-forge --skill security-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-compliance, .gemini/skills/security-compliance, .github/skills/security-compliance and .opencode/skills/security-compliance in your project.

What does Security Compliance need to run?

Going by SKILL.md and its folder, Security Compliance needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Security Compliance access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Compliance use?

Security Compliance is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Compliance use?

About 7.2k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Compliance?

Skills that share tags, products or a category with Security Compliance: Architecting Security (telagod/code-abyss, 243 stars), Compliance (ericrisco/rsc-harness, 174 stars), Audit Report (harness/harness-skills, 115 stars) and Ciso Advisor (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Compliance?

sangrokjung (a GitHub user) maintains it in sangrokjung/claude-forge, which has 852 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on September 3, 2026.

Source: sangrokjung/claude-forge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.