Skip to main content
GitHub-Repository

Audit-skills

Audit-skills enthält 12 gesammelte Skills von amurthygithub, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
12
Stars
8
aktualisiert
2026-06-12
Forks
2
Berufsabdeckung
4 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

nist-800-53-rmf
Compliance-Beauftragter

Perform NIST SP 800-53 Rev 5 control selection, implementation, assessment, and continuous monitoring using the NIST Risk Management Framework (SP 800-37 Rev 2 RMF). Covers FIPS 199 categorization, baseline selection (Low/Moderate/High), 800-53A assessment procedures, control inheritance (FedRAMP/shared services/cloud), SAR/POA&M and ATO determination. Activate when performing RMF Step 2 (categorize), Step 3 (select), Step 4 (implement), Step 5 (assess), Step 6 (authorize), or Step 7 (monitor); when mapping SOC 2 / ISO 27001 / PCI / HIPAA to 800-53; when planning or executing a FedRAMP authorization; or when responding to a federal/DoD assessment.

2026-06-12
audit-category-pointer
Compliance-Beauftragter

Pointer to a library of 10 specialized audit/compliance skills — ISACA, COSO, AICPA SOC, Audit Workpapers, NIST 800-53/RMF, NIST CSF 2.0, HIPAA Security Rule, PCI DSS, SOX §302 disclosure controls, and FedRAMP cloud authorization. Use when working on IT audit, internal controls, SOC reporting, audit documentation, federal control baselines, cybersecurity maturity, HIPAA security, PCI DSS payment-security, SOX §302 disclosure-controls certification, or FedRAMP cloud-authorization tasks.

2026-06-12
fedramp-authorization
Compliance-Beauftragter

FedRAMP cloud-authorization program (Rev 5) — the FedRAMP Authorization Act of 2022 (44 U.S.C. 3607-3616), OMB M-24-15, the Rev 5 baselines (Low 156 / Moderate 323 / High 410 / LI-SaaS 156, tailored from NIST SP 800-53 Rev 5), the SSP/SAP/SAR/POA&M package, the 3PAO assessment, monthly Continuous Monitoring, and the FedRAMP 20x direction. Two load-bearing facts: FedRAMP baselines ARE tailored 800-53 controls (not a separate catalog — that is nist-800-53-rmf), and the current authorizer is the statutory FedRAMP Board, NOT the retired JAB. Use to categorize a system (FIPS 199 high-water mark) and select a baseline, scope an authorization package, plan a 3PAO assessment, run monthly ConMon and POA&M, or determine LI-SaaS eligibility. Activate when the user says 'FedRAMP', 'cloud authorization', 'ATO', 'P-ATO', 'agency authorization', '3PAO', 'SSP', 'SAR', 'POA&M', 'ConMon', 'continuous monitoring', 'Li-SaaS', 'FedRAMP baseline', 'FedRAMP Moderate/High', 'FedRAMP 20x', 'authorization to operate', or 'cloud servic

2026-06-11
audit-workpapers
Buchhalter und Wirtschaftsprüfer

Create, organize, evaluate, and review audit workpapers per PCAOB AS 1215, AS 2315, AS 1105, and AS 3105, AICPA AU-C 230, ISA 230, COSO ICIF-2013, and ISACA ITAF. Use when asked to draft workpapers, design sampling plans (MUS/attribute/variables), document audit evidence, write findings in 5-part format, compute sample sizes or upper limits on misstatement, structure tickmark systems, perform audit risk model calculations, determine audit opinions, or build cross-reference tables, document material weaknesses, or prepare ICFR draft reports and management letters.

2026-06-11
sox-302-disclosure-controls
Buchhalter und Wirtschaftsprüfer

SOX §302 Disclosure Controls & Procedures (DC&P) certification — 15 U.S.C. 7241; SEC Rules 17 CFR 240.13a-14 / 240.13a-15; Reg S-K Items 307, 308. The 6-element officer certification (PEO + PFO), quarterly DC&P evaluation, and the load-bearing DC&P-vs-ICFR and §302-vs-§404 boundaries. Use to draft or review a §302 certification, conclude on DC&P effectiveness after a material weakness, determine a newly-public filer's certification obligations, design a multi-entity sub-certification cascade, or scope the non-financial disclosure universe (risk factors, legal, MD&A, cyber 8-K). Activate when the user says 'SOX 302', 'Section 302', 'disclosure controls and procedures', 'DC&P', 'officer certification', '13a-14', '13a-15', 'Item 307', 'Item 308', 'disclosure committee', 'sub-certification', or 'PEO/PFO certification'.

2026-06-11
coso-internal-controls
Buchhalter und Wirtschaftsprüfer

Perform COSO 2013 ICIF-based internal control assessments including SOX 404 ICFR evaluation, PCAOB AS 2201 top-down audit, deficiency classification, walkthrough procedures, Risk and Control Matrix documentation, entity-level and process-level control assessment, COSO 2017 ERM integration, and emerging technology controls. Activate for COSO framework application, ICFR assessment, SOX 404 compliance, internal control deficiency evaluation, or PCAOB AS 2201 audit procedures.

2026-06-11
pci-dss-assessment
Compliance-Beauftragter

PCI DSS v4.0.1 (Payment Card Industry Data Security Standard, Requirements and Testing Procedures): 6 goals, 12 principal requirements, 63 sections, 249 main-body defined requirements, plus appendices A-G. Serves BOTH an auditee path (merchant/service-provider scoping, SAQ selection, self-assessment) and an assessor path (QSA/ISA workflow, ROC vs AOC, customized-approach and compensating-control validation). Use to scope a cardholder data environment (CDE), select among the 10 SAQ types, walk Requirements 1-12, distinguish the defined vs customized approach, build a compensating-control worksheet, or confirm v4.0.1 currency. Activate when the user says 'PCI DSS', 'PCI compliance', 'cardholder data', 'CDE', 'SAQ', 'ROC', 'AOC', 'QSA', 'network security controls', 'account data', 'segmentation', 'customized approach', or 'compensating control'.

2026-06-11
hipaa-security-rule
Compliance-Beauftragter

HIPAA Security Rule (45 CFR Part 164, Subpart C): 22 standards across administrative (9), physical (4), technical (5), organizational (2), and policies/documentation (2) families, with Required vs Addressable implementation specifications. Serves BOTH auditor and auditee personas. Use to run a §164.308(a)(1)(ii)(A) risk analysis, work addressable-specification dispositions per §164.306(d)(3), check a BAA against §164.314(a)(2)(i), build an OCR-readiness matrix across all 22 standards, or right-size safeguards via the §164.306(b)(2) flexibility factors. Activate when the user says 'HIPAA Security Rule', 'ePHI', '45 CFR 164', 'addressable specification', 'business associate agreement', 'BAA', 'OCR audit', 'security risk analysis', 'HIPAA safeguards', or 'recognized security practices'.

2026-06-11
nist-csf-2
Unternehmensberater

NIST Cybersecurity Framework 2.0 (Feb 2024): 6 Functions, 22 Categories, 106 Subcategories, Tiers 1-4, Current/Target/Organizational/Community Profiles. The bridge skill between executive risk language and IT controls. Use to assess organizational cybersecurity maturity, build a Current or Target Profile, run a Current/Target gap analysis, produce a 6-function radar for the board, or map CSF to NIST 800-53 / ISO 27001 / SOC 2 / HIPAA / PCI / COBIT. Activate when the user says 'CSF 2.0', 'NIST cybersecurity framework', 'cybersecurity maturity', 'maturity assessment', 'Current Profile', 'Target Profile', '6 functions', 'GOVERN function', 'Tier 1-4', or asks for an executive-legible cyber maturity view.

2026-06-10
isaca-audit-methodology
Buchhalter und Wirtschaftsprüfer

Perform ISACA-based IT audit work including CISA methodology, COBIT 2019 governance/management objectives, ITAF standards, ITGC/ITAC testing, risk-based audit planning, 5-part audit observations, COBIT maturity assessment, and cross-framework mapping. Activate when performing IT audits, IS audits, control assessments, COBIT evaluations, IT risk assessments, audit observation writing, ITGC/ITAC testing, audit planning, or audit report generation.

2026-06-10
aicpa-soc-reporting
Buchhalter und Wirtschaftsprüfer

Perform AICPA System and Organization Controls (SOC) reporting work including SOC 1, SOC 2, SOC 3, SOC for Cybersecurity, and SOC for Supply Chain engagements. Activates when the user asks about SOC report types, trust services criteria (TSC), TSP Section 100, management assertions, service auditor opinions, CUECs, CSOCs, bridge letters, readiness assessments, Type I vs Type II reports, AT-C 105/205/320 standards (or the older 100/200/300 series shorthand), or SSAE 18/21.

2026-06-10
template
Softwareentwickler

TEMPLATE — copy this directory to start a new skill. Provides folder skeleton, frontmatter contract, section requirements, telemetry schema, and acceptance gate. NOT a real skill — used as the Spine that every published skill (e.g., nist-800-53-rmf) is built from.

2026-06-10