Pointer to a library of 10 specialized audit/compliance skills — ISACA, COSO, AICPA SOC, Audit Workpapers, NIST 800-53/RMF, NIST CSF 2.0, HIPAA Security Rule, PCI DSS, SOX §302 disclosure controls, and FedRAMP cloud authorization. Use when working on IT audit, internal controls, SOC reporting, audit documentation, federal control baselines, cybersecurity maturity, HIPAA security, PCI DSS payment-security, SOX §302 disclosure-controls certification, or FedRAMP cloud-authorization tasks.
Installation
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
This is a pointer skill. The 10 specialized skills are stored on disk to keep your startup
context minimal. Counts and framework facts live in each skill (verified against live
sources at its G4.5 gate) — this pointer deliberately repeats none of them.
fedramp-authorization — FedRAMP cloud-authorization program (Rev 5): the FedRAMP Authorization Act of 2022 and OMB M-24-15 governance (FedRAMP Board, not the retired JAB), FIPS 199 categorization and the Low/Moderate/High/LI-SaaS baselines (tailored from NIST SP 800-53 Rev 5), the SSP/SAP/SAR/POA&M package, 3PAO assessment, monthly ConMon, and the FedRAMP 20x direction.
How to load a skill
Identify the skill name above matching your task.
Read skills/<skill-name>/SKILL.md (the router); load the chunks its §11 routing table
selects for your intent. In an installed environment, read the skill's SKILL.md from
wherever this library was installed.
Follow those instructions to complete the request.
Do not guess best practices — always read from the skill file first.
Quick reference: Which skill to use?
Task
Skill
IT audit planning, COBIT assessment, ITGC/ITAC testing
isaca-audit-methodology
SOX 404, internal control evaluation, deficiency classification
coso-internal-controls
SOC 1/2/3 scoping, TSC criteria, service org reporting