askill
compliance-frameworks

compliance-frameworksSafety 95Repository

Multi-framework compliance (ISO 27001, NIST CSF, CIS Controls, GDPR, NIS2, EU CRA, SOC 2), control mapping

206 stars
4.1k downloads
Updated 2/22/2026

Package Files

Loading files...
SKILL.md

Compliance Frameworks Skill

Purpose

This skill provides unified compliance mapping across ISO 27001:2022, NIST CSF 2.0, CIS Controls v8, GDPR, NIS2, EU CRA, and SOC 2 for the CIA platform. It enables developers to implement controls that satisfy multiple frameworks simultaneously, reducing compliance overhead.

When to Use This Skill

Apply this skill when:

  • ✅ Implementing a new security control or feature
  • ✅ Documenting compliance evidence for audits
  • ✅ Mapping requirements across multiple frameworks
  • ✅ Assessing regulatory impact of platform changes
  • ✅ Preparing for ISO 27001 certification audits
  • ✅ Evaluating NIS2 or EU CRA applicability
  • ✅ Creating compliance reports for stakeholders

Do NOT use for:

  • ❌ Detailed implementation of specific controls (use dedicated skills)
  • ❌ Runtime security monitoring
  • ❌ Code-level vulnerability fixing

Framework Overview

Compliance Framework Hierarchy for CIA Platform
│
├─ MANDATORY COMPLIANCE
│  ├─ GDPR (data protection, Swedish political data)
│  ├─ NIS2 (network and information security, if applicable)
│  └─ EU CRA (cyber resilience for open-source software)
│
├─ VOLUNTARY STANDARDS (Hack23 ISMS)
│  ├─ ISO 27001:2022 (information security management)
│  ├─ NIST CSF 2.0 (cybersecurity framework)
│  └─ CIS Controls v8 (critical security controls)
│
└─ INDUSTRY BEST PRACTICES
   ├─ SOC 2 Type II (service organization controls)
   ├─ OWASP Top 10 (web application security)
   └─ OpenSSF Scorecard (open-source security posture)

Cross-Framework Control Mapping

Access Control

RequirementISO 27001NIST CSFCIS ControlsGDPRNIS2
AuthenticationA.8.5PR.AA-01CIS 6.3Art. 32Art. 21(2)(d)
AuthorizationA.5.15PR.AA-03CIS 6.8Art. 25Art. 21(2)(d)
Least privilegeA.8.2PR.AA-05CIS 6.1Art. 25Art. 21(2)(i)
MFAA.8.5PR.AA-02CIS 6.5Art. 32Art. 21(2)(j)
Access reviewA.5.18PR.AA-06CIS 6.2Art. 32Art. 21(2)(d)

Data Protection

RequirementISO 27001NIST CSFCIS ControlsGDPREU CRA
Encryption at restA.8.24PR.DS-01CIS 3.11Art. 32(1)(a)Art. 10(1)
Encryption in transitA.8.24PR.DS-02CIS 3.10Art. 32(1)(a)Art. 10(1)
Data classificationA.5.12ID.AM-08CIS 3.7Art. 9
Data retentionA.5.33PR.DS-10CIS 3.1Art. 5(1)(e)
BackupA.8.13PR.DS-11CIS 11.2Art. 32(1)(c)Art. 10(1)

Vulnerability Management

RequirementISO 27001NIST CSFCIS ControlsEU CRASOC 2
Vulnerability scanningA.8.8DE.CM-08CIS 7.5Art. 10(6)CC7.1
Patch managementA.8.8PR.PS-02CIS 7.4Art. 10(6)CC7.1
Dependency checkA.8.28PR.PS-02CIS 16.4Art. 10(6)CC7.1
Pen testingA.8.8DE.CM-08CIS 18.3Art. 10(4)CC7.1
SBOMA.8.28PR.PS-01CIS 16.4Art. 10(5)

Incident Response

RequirementISO 27001NIST CSFCIS ControlsNIS2SOC 2
Incident planA.5.24RS.MA-01CIS 17.1Art. 23CC7.3
Incident detectionA.8.16DE.AE-02CIS 17.3Art. 23(1)CC7.2
ReportingA.5.25RS.CO-02CIS 17.2Art. 23(4)CC7.4
Lessons learnedA.5.27RS.IM-02CIS 17.8Art. 23CC7.5
Evidence preservationA.5.28RS.AN-06CIS 17.4Art. 23CC7.3

CIA Platform Compliance Decision Tree

New Feature Compliance Assessment
│
├─→ Does it process personal data?
│   ├─ YES → GDPR (Art. 6 legal basis, Art. 25 privacy by design)
│   └─ NO → Continue
│
├─→ Does it affect network/information security?
│   ├─ YES → NIS2 (Art. 21 risk management measures)
│   └─ NO → Continue
│
├─→ Is it a software product/component?
│   ├─ YES → EU CRA (Art. 10 vulnerability handling)
│   └─ NO → Continue
│
├─→ Does it change security controls?
│   ├─ YES → ISO 27001 (Annex A controls)
│   │        NIST CSF (relevant function)
│   │        CIS Controls (implementation group)
│   └─ NO → Continue
│
└─→ Apply general secure development practices
    └─ OWASP Top 10, secure coding standards

NIS2 Directive Compliance

Applicability Assessment

NIS2 applies to CIA platform if:
- Essential entity: Public administration ICT services
- Important entity: Digital infrastructure providers
- Open-source steward: Maintained open-source project (Art. 15a)

Hack23/CIA classification: Open-Source Steward
Obligations: Due diligence, vulnerability handling, coordination

Key Requirements

NIS2 ArticleRequirementCIA Implementation
Art. 21(2)(a)Risk analysis and IS policiesHack23 ISMS policies
Art. 21(2)(b)Incident handlingIncident response plan
Art. 21(2)(d)Supply chain securityOWASP dependency check
Art. 21(2)(e)Secure developmentSDLC security gates
Art. 21(2)(h)Security awarenessDeveloper training
Art. 21(2)(j)MFA and encryptionSpring Security, AES-256

EU Cyber Resilience Act (CRA)

Open-Source Software Obligations

EU CRA Open-Source Steward Requirements:
├─ Vulnerability disclosure policy (SECURITY.md)
├─ Coordinated vulnerability handling
├─ Security update distribution
├─ Software Bill of Materials (SBOM)
├─ CE marking considerations
└─ Documentation of security properties

Implementation Evidence

CRA RequirementEvidence
Vulnerability handlingSECURITY.md, GitHub Security Advisories
Security updatesDependabot, automated dependency updates
SBOM generationMaven CycloneDX plugin
Secure by defaultSpring Security configuration
DocumentationSECURITY_ARCHITECTURE.md, THREAT_MODEL.md

Compliance Evidence Collection

Per-Sprint Evidence

Sprint Compliance Artifacts:
□ Code review records (GitHub PR reviews)
□ Security scan results (CodeQL, OWASP)
□ Test coverage reports (JaCoCo)
□ Dependency audit (Dependabot alerts)
□ Access control changes (audit log)
□ Configuration changes (git history)

Annual Evidence

Annual Compliance Review:
□ ISMS policy review and update
□ Risk assessment update
□ Penetration testing results
□ Business continuity test
□ Access rights review
□ Security awareness training records
□ Supplier security assessments
□ Incident response drill results

ISMS Alignment

PolicyFrameworks CoveredLocation
Information Security PolicyISO 27001, NIST CSFHack23 ISMS
Classification PolicyISO 27001, GDPRHack23 ISMS
Access Control PolicyISO 27001, CIS, NIS2Hack23 ISMS
Secure Development PolicyISO 27001, EU CRAHack23 ISMS
Incident Response PolicyISO 27001, NIS2Hack23 ISMS
Cryptography PolicyISO 27001, GDPRHack23 ISMS

References

Install

Download ZIP
Requires askill CLI v1.0+

AI Quality Score

78/100Analyzed 2/23/2026

Comprehensive compliance mapping skill covering 7 frameworks with structured tables and decision trees. Strong actionability through control mappings and evidence checklists. Some internal references (Hack23 ISMS, CIA platform) limit reusability, but the framework mappings themselves are broadly applicable. Path in .github/skills suggests internal configuration use.

95
90
68
88
82

Metadata

Licenseunknown
Version-
Updated2/22/2026
PublisherHack23

Tags

apigithubobservabilitysecuritytesting