Expert approach to defect-prevention in quality measurement. Use when working with .
Skills in this repository
sethdford/claude-skills - Page 7
SkillsMP has collected 383 skills from sethdford/claude-skills. Open a skill to review its source and details.
sethdford/claude-skillsShowing 40 of 383 collected skills.
Expert approach to escaped-defect-analysis in quality measurement. Use when working with .
Expert approach to quality-dashboard in quality measurement. Use when working with .
Expert approach to quality-gate-design in quality measurement. Use when working with .
Expert approach to root-cause-analysis-qa in quality measurement. Use when working with .
Expert approach to test-effectiveness-measurement in quality measurement. Use when working with .
Expert approach to test-metrics-framework in quality measurement. Use when working with .
Develop regression test strategies and maintenance approaches. Use when managing regression risk across releases.
Prioritize test efforts based on risk assessment. Use when allocating limited testing resources to maximize defect detection.
Design shift-left testing strategies to catch defects early. Use when planning early involvement of QA in development.
Measure and analyze test coverage gaps. Use when identifying untested code paths and assessing coverage sufficiency.
Design test data management approaches. Use when planning data provisioning for testing.
Plan and design test environment strategies. Use when setting up testing infrastructure and environment requirements.
Estimate testing effort and resource requirements. Use when planning test cycles and allocating QA resources.
Design test pyramid architecture balancing unit, integration, and E2E tests. Use when establishing test level distribution and automation strategy.
Design comprehensive test strategies aligned with project goals, risks, and constraints. Use when planning testing efforts for new projects or major releases.
Review API security including authentication, authorization, rate limiting, input validation, and data exposure.
Design and deploy Content-Security-Policy (CSP) to prevent XSS attacks and unauthorized resource loading.
Design and execute Dynamic Application Security Testing (DAST) test plans to find runtime vulnerabilities in web applications.
Scan application dependencies for known vulnerabilities and manage security updates across supply chain.
Define penetration test scope, objectives, and constraints to align testing with business goals and compliance requirements.
Configure and deploy Static Application Security Testing (SAST) tools to find vulnerabilities in source code during development.
Develop comprehensive security test plans covering functional security, vulnerability scanning, and attack scenarios.
Configure security HTTP headers to mitigate XSS, clickjacking, MIME sniffing, and other browser-based attacks.
Prepare for compliance audits by collecting evidence, organizing documentation, and coordinating with auditors.
Map security controls to compliance framework requirements (NIST, CIS, ISO 27001, PCI-DSS, HIPAA, GDPR, SOC 2).
Classify organizational data by sensitivity level and define handling, storage, and access requirements.
Assess GDPR compliance for data processing, rights, privacy controls, and incident response obligations.
Review PCI-DSS compliance for payment card data security across network, systems, and processes.
Conduct Privacy Impact Assessments (PIA) to evaluate privacy risks and compliance for data processing activities.
Develop organization-wide security policies covering access control, data handling, incident response, and vendor management.
Implement SOC 2 Trust Services Criteria controls for security, availability, processing integrity, confidentiality, and privacy.
Develop containment strategies to isolate compromised systems, prevent lateral movement, and stop ongoing attacks.
Preserve evidence during incident response to enable forensic analysis and maintain legal admissibility.
Conduct forensic analysis to determine attack vectors, scope of compromise, and evidence for legal proceedings.
Develop incident communication strategies for internal teams, customers, regulators, and media during and after security incidents.
Develop comprehensive incident response plans with clear roles, procedures, communication protocols, and recovery workflows. Use when establishing IR processes, conducting tabletops, or updating response procedures after incidents.
Conduct post-incident reviews to document lessons learned and implement process improvements preventing recurrence.
Establish recovery procedures to restore systems, verify integrity, and validate business continuity after incidents.
Conduct root-cause analysis (RCA) to identify underlying causes of security incidents and prevent recurrence.