Skip to main content
Manusで任意のスキルを実行
ワンクリックで
GitHub リポジトリ

GRC-Claude-Skills

GRC-Claude-Skills には scytale-labs から収集した 10 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
10
Stars
25
更新
2026-04-15
Forks
10
職業カバレッジ
6 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

fedramp
コンプライアンスオフィサー

Use when the user asks about FedRAMP — the US government cloud authorization program, impact levels (Low/Moderate/High/LI-SaaS), NIST SP 800-53 control baselines, the System Security Plan (SSP), 3PAO assessment, JAB vs Agency authorization paths, the FedRAMP Marketplace, the ATO (Authority to Operate), or continuous monitoring obligations. For cloud service providers selling to US federal agencies.

2026-04-15
gdpr
弁護士パラリーガル・法律アシスタント

Use when the user asks about GDPR — lawful bases for processing, data subject rights (DSRs), Records of Processing Activities (ROPA, Article 30), Data Protection Impact Assessments (DPIA, Article 35), international data transfers (SCCs, adequacy, TIA), controller vs processor obligations, breach notification (Articles 33–34), or DPO appointment. For controllers, processors, and sub-processors operating in the EU/EEA or targeting EU residents.

2026-04-15
hipaa
その他医師

Use when the user asks about HIPAA — Privacy Rule, Security Rule (administrative, physical, technical safeguards), Breach Notification Rule, Business Associate Agreements (BAAs), the HITECH Act, OCR audits, or determining whether an organisation is a covered entity or business associate. For US healthcare providers, health plans, clearinghouses, and their business associates and subcontractors.

2026-04-15
iso-27001
コンプライアンスオフィサー

Use when the user asks about ISO/IEC 27001 — Information Security Management System (ISMS), Statement of Applicability, the 93 Annex A controls (2022 revision), risk assessment and treatment, Stage 1/Stage 2 certification audits, surveillance audits, or cross-walks with SOC 2, HIPAA, or GDPR. For organizations seeking certification globally.

2026-04-15
iso-42001
コンプライアンスオフィサー

Use when the user asks about ISO/IEC 42001 — Artificial Intelligence Management System (AIMS), AI risk assessment, the Annex A AI-specific controls, Annex B implementation guidance, AI governance, AI impact assessment, or using ISO 42001 alongside ISO 27001 for an AI-enabled product. For organizations building, deploying, or governing AI systems.

2026-04-15
nist-csf
情報セキュリティアナリスト

Use when the user asks about NIST Cybersecurity Framework — the CSF 2.0 six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Implementation Tiers (1–4), Profiles (Current and Target), Organizational Profile, or using CSF as a structuring lens for a security program. Voluntary framework — useful for any sector, often paired with sector-specific regulation.

2026-04-15
pci-dss
弁護士

Use when the user asks about PCI DSS — the v4.0 (or v4.0.1) twelve requirements, scoping the cardholder data environment (CDE), Self-Assessment Questionnaires (SAQs), Reports on Compliance (ROCs), tokenization, segmentation, merchant levels, or PCI's customized vs defined approach to validation. For merchants, service providers, and their assessors.

2026-04-15
soc-2
コンプライアンスオフィサー

Use when the user asks about SOC 2 — Trust Services Criteria (TSC), Type 1 vs Type 2, evidence collection, gap assessments, control design, auditor preparation, or readiness for a SOC 2 attestation. For SaaS and service organizations in North America and globally.

2026-04-15
sox-itgc
コンプライアンスオフィサー会計士・監査役

Use when the user asks about SOX ITGC (Sarbanes-Oxley IT General Controls) — access management, change management, computer operations, system development, control testing, working papers, deficiency remediation, deficiency severity (SD / MW), or moving from point-in-time to continuous ITGC monitoring. For publicly traded companies, pre-IPO companies preparing for SOX, and their internal audit and finance teams.

2026-04-15
tsa-cybersecurity
情報セキュリティアナリスト

Use when the user asks about TSA Cybersecurity Security Directives — pipeline (SD Pipeline-2021-01, -02), rail (SD-1580/82-2022-01), aviation (SD-1542/44-22, SD-1580-21-01), the four required cybersecurity measures (network segmentation, access control, continuous monitoring, patch management), Cybersecurity Implementation Plans (CIP), Cybersecurity Assessment Plans (CAP), or TSA reporting obligations to CISA. For US owners and operators of designated critical pipelines, freight/passenger railroads, and certain airports/aircraft operators.

2026-04-15