Agent skill

Compliance Framework Alignment

by Hack23 in Hack23/cia

Cross-framework compliance alignment and control mapping between ISO 27001, NIST CSF, CIS Controls, and GDPR

Apache-2.0Auto-check passedLegal & Compliance

Install Compliance Framework Alignment

skills CLI
$ npx skills add Hack23/cia --skill compliance-framework-alignment -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia compliance-framework-alignment --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/compliance-framework-alignment .claude/skills/compliance-framework-alignment && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
compliance-framework-alignment
GitHub stars
239
Token cost
~2k tokens
SKILL.md length
626 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cross-framework compliance alignment and control mapping between ISO 27001, NIST CSF, CIS Controls, and GDPR

  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Purpose, When to Use This Skill, Framework Overview and Cross-Framework Control Mapping, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Privacy and GDPR

What it does

Compliance Framework Alignment is an agent skill from Hack23/cia. Cross-framework compliance alignment and control mapping between ISO 27001, NIST CSF, CIS Controls, and GDPR

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance and Privacy and GDPR. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Privacy and GDPR

Example prompts

  • “/compliance-framework-alignment”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • iso.org
    • nist.gov
    • cisecurity.org
    • gdpr-info.eu

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Compliance Framework Alignment loads about 2k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 626 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 626 words, ~1,989 tokens.

Download SKILL.mdSave it as .claude/skills/compliance-framework-alignment/SKILL.md (or your agent's skills folder).
name
compliance-framework-alignment
description
Cross-framework compliance alignment and control mapping between ISO 27001, NIST CSF, CIS Controls, and GDPR
license
Apache-2.0

Compliance Framework Alignment Skill

Purpose

This skill provides a unified cross-framework compliance alignment for the CIA platform, mapping controls between ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, and GDPR. It enables developers and security teams to understand how a single implementation satisfies multiple compliance requirements simultaneously.

When to Use This Skill

Apply this skill when:

  • ✅ Implementing security controls that must satisfy multiple frameworks
  • ✅ Preparing for compliance audits
  • ✅ Documenting control implementations
  • ✅ Assessing compliance gaps
  • ✅ Justifying security investments to stakeholders
  • ✅ Reviewing architecture changes for compliance impact
  • ✅ Updating ISMS documentation

Do NOT use for:

  • ❌ Detailed control implementation (use framework-specific skills)
  • ❌ Risk assessment methodology (use risk-assessment-methodology)
  • ❌ Incident response procedures (use incident-response)

Framework Overview

Frameworks in Scope
FrameworkVersionFocusApplicability
ISO 270012022ISMS certificationMandatory — Hack23 ISMS
NIST CSF2.0Cybersecurity risk managementRecommended — best practice
CIS Controlsv8Prioritized cyber defenseRecommended — IG1/IG2
GDPR2016/679Personal data protectionMandatory — EU data processing
Framework Function Mapping
ISO 27001 Domains    ←→    NIST CSF Functions    ←→    CIS Controls IG
────────────────           ──────────────────           ──────────────
Organizational (5)   ←→    Govern (GV)            ←→    IG1: Essential
People (6)           ←→    Identify (ID)          ←→    IG2: Foundational
Physical (7)         ←→    Protect (PR)           ←→    IG3: Organizational
Technological (8)    ←→    Detect (DE)
                     ←→    Respond (RS)
                     ←→    Recover (RC)

Cross-Framework Control Mapping

Access Control
RequirementISO 27001NIST CSFCIS ControlsGDPR
Access policyA.5.15PR.AA-1CIS 6.1Art. 25
User authenticationA.8.5PR.AA-3CIS 6.3Art. 32
Privileged accessA.8.2PR.AA-5CIS 6.5Art. 32
Access reviewA.5.18PR.AA-6CIS 6.2Art. 5(1)(f)
CIA ImplementationSpring Security RBAC, role-based views
Data Protection
RequirementISO 27001NIST CSFCIS ControlsGDPR
Data classificationA.5.12ID.AM-5CIS 3.1Art. 30
Encryption at restA.8.24PR.DS-1CIS 3.11Art. 32
Encryption in transitA.8.24PR.DS-2CIS 3.10Art. 32
Data retentionA.5.33PR.IP-6CIS 3.4Art. 5(1)(e)
Data minimizationA.5.31——Art. 5(1)(c)
CIA ImplementationTLS 1.2+, RDS encryption, GDPR-compliant user data
Secure Development
RequirementISO 27001NIST CSFCIS ControlsGDPR
Secure SDLCA.8.25PR.IP-12CIS 16.1Art. 25
Security testingA.8.29DE.CM-8CIS 16.4Art. 32
Code reviewA.8.28PR.IP-12CIS 16.11Art. 25
Dependency managementA.8.19ID.SC-2CIS 16.7Art. 32
Change managementA.8.32PR.IP-3CIS 16.3Art. 25
CIA ImplementationCI/CD gates, CodeQL, OWASP DC, SonarCloud
Logging & Monitoring
RequirementISO 27001NIST CSFCIS ControlsGDPR
Audit loggingA.8.15DE.AE-3CIS 8.2Art. 30
Log protectionA.8.15PR.DS-6CIS 8.9Art. 32
MonitoringA.8.16DE.CM-1CIS 8.11Art. 32
AlertingA.8.16DE.AE-4CIS 8.11Art. 33
CIA ImplementationSLF4J + Logback, AWS CloudWatch
Show full SKILL.md (258 more words)Show less
Incident Management
RequirementISO 27001NIST CSFCIS ControlsGDPR
Incident planA.5.24RS.MA-1CIS 17.1Art. 33
Incident detectionA.5.25DE.AE-2CIS 17.3Art. 33
Incident responseA.5.26RS.MA-2CIS 17.4Art. 33
Lessons learnedA.5.27RS.IM-1CIS 17.8Art. 33(3)
Breach notificationA.5.26RS.CO-2CIS 17.2Art. 33, 34
CIA ImplementationGitHub Security Advisories, SECURITY.md process

Compliance Gap Analysis Template

Per-Control Assessment
markdown
## Control: [Name]

### Framework References
- ISO 27001: [Control ID]
- NIST CSF: [Function.Category-Subcategory]
- CIS Controls: [Control ID]
- GDPR: [Article]

### Current Implementation
- **Status:** Implemented / Partial / Not Implemented
- **Implementation:** [Description]
- **Evidence:** [Where to find proof]

### Gap Assessment
- **Gap:** [What's missing]
- **Risk:** Critical / High / Medium / Low
- **Remediation:** [What needs to be done]
- **Timeline:** [When]
- **Owner:** [Who]

Audit Preparation

Evidence Collection Matrix
Control AreaEvidence TypeLocationFormat
Access ControlSecurity configSecurityConfig.javaCode review
EncryptionTLS configCloudFormation templatesConfig review
SAST/DASTScan reportsGitHub Actions artifactsAutomated reports
Code ReviewPR reviewsGitHub PR historyAudit trail
Dependency ScanOWASP DC reportsCI/CD artifactsAutomated reports
LoggingLog configlogback.xmlConfig review
Change MgmtGit historyGitHub commits/PRsAutomated trail
TestingCoverage reportsJaCoCo/SonarCloudAutomated reports
Incident MgmtSecurity advisoriesGitHub Security tabDocumented process
Audit Readiness Checklist
□ ISMS documentation current and approved
□ Risk assessment completed within last year
□ Security controls implemented and documented
□ Evidence artifacts collected and organized
□ Training records available
□ Incident response plan tested
□ Business continuity plan reviewed
□ Third-party security assessments completed
□ Corrective actions from previous audit closed
□ Management review conducted

GDPR-Specific Requirements

CIA Platform GDPR Obligations
GDPR RequirementArticleCIA Implementation
Lawful basisArt. 6Legitimate interest (political transparency)
Data minimizationArt. 5(1)(c)Collect only necessary user data
Purpose limitationArt. 5(1)(b)Political transparency analysis only
Storage limitationArt. 5(1)(e)Defined retention periods
Integrity & confidentialityArt. 5(1)(f)Encryption, access controls
Privacy by designArt. 25Built into architecture
Data protection officerArt. 37Assessed — not required (small org)
Records of processingArt. 30Maintained in ISMS docs
Breach notificationArt. 3372-hour notification process
Data subject rightsArt. 15-22Account deletion, data export

Decision Framework

Implementing a New Security Control
    │
    ├─→ Identify all applicable framework requirements
    │   └─→ Check ISO 27001, NIST CSF, CIS, GDPR mappings above
    │
    ├─→ Design control to satisfy ALL applicable frameworks
    │   └─→ One implementation, multiple compliance benefits
    │
    ├─→ Document control implementation
    │   └─→ Map to specific control IDs in each framework
    │
    ├─→ Collect evidence of implementation
    │   └─→ Automated where possible (CI/CD, logs, configs)
    │
    └─→ Verify control effectiveness
        └─→ Test, review, and audit periodically

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/compliance-framework-alignment of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Compliance Framework Alignment next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Compliance Framework Alignment compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Compliance Framework Alignment this skillHack23/cia239—~2kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.3kAutomated safety check: PassMIT
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Cis ControlsSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~4.2kAutomated safety check: PassMIT
Security Compliancesangrokjung/claude-forge8492 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    939 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Cis Controls

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

    939 GitHub starsUsed in 1 repo~4.2k tokens
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    849 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Compliance Framework Alignment

What does Compliance Framework Alignment do?

Cross-framework compliance alignment and control mapping between ISO 27001, NIST CSF, CIS Controls, and GDPR. Compliance Framework Alignment is an agent skill from Hack23/cia.

When should I use Compliance Framework Alignment?

Compliance Framework Alignment fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Privacy and GDPR.

How do I install Compliance Framework Alignment in Claude Code?

Run `npx skills add Hack23/cia --skill compliance-framework-alignment -a claude-code`. Or copy the skill folder (.github/skills/compliance-framework-alignment in Hack23/cia) into .claude/skills/compliance-framework-alignment in your project. Claude Code loads it when a task matches its description.

How do I install Compliance Framework Alignment in Codex?

Run `npx skills add Hack23/cia --skill compliance-framework-alignment -a codex`. Or copy the skill folder (.github/skills/compliance-framework-alignment in Hack23/cia) into .agents/skills/compliance-framework-alignment in your project. Codex loads it when a task matches its description.

Can I use Compliance Framework Alignment in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill compliance-framework-alignment -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/compliance-framework-alignment, .gemini/skills/compliance-framework-alignment, .github/skills/compliance-framework-alignment and .opencode/skills/compliance-framework-alignment in your project.

What does Compliance Framework Alignment need to run?

SKILL.md names no scripts, command-line tools or credentials: Compliance Framework Alignment is instructions for the agent only.

Does Compliance Framework Alignment access the network?

SKILL.md names 4 domains. As links in the text: iso.org, nist.gov, cisecurity.org and gdpr-info.eu. This is read from the text; nothing was executed.

Is Compliance Framework Alignment safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Compliance Framework Alignment use?

Compliance Framework Alignment is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Compliance Framework Alignment use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Compliance Framework Alignment?

Skills that share tags, products or a category with Compliance Framework Alignment: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars), Audit Report (harness/harness-skills, 115 stars), Cis Controls (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars) and Security Compliance (sangrokjung/claude-forge, 849 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Compliance Framework Alignment?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.