Pointer to a library of 10 specialized audit/compliance skills — ISACA, COSO, AICPA SOC, Audit Workpapers, NIST 800-53/RMF, NIST CSF 2.0, HIPAA Security Rule, PCI DSS, SOX §302 disclosure controls, and FedRAMP cloud authorization. Use when working on IT audit, internal controls, SOC reporting, audit documentation, federal control baselines, cybersecurity maturity, HIPAA security, PCI DSS payment-security, SOX §302 disclosure-controls certification, or FedRAMP cloud-authorization tasks.
Instalação
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
This is a pointer skill. The 10 specialized skills are stored on disk to keep your startup
context minimal. Counts and framework facts live in each skill (verified against live
sources at its G4.5 gate) — this pointer deliberately repeats none of them.
fedramp-authorization — FedRAMP cloud-authorization program (Rev 5): the FedRAMP Authorization Act of 2022 and OMB M-24-15 governance (FedRAMP Board, not the retired JAB), FIPS 199 categorization and the Low/Moderate/High/LI-SaaS baselines (tailored from NIST SP 800-53 Rev 5), the SSP/SAP/SAR/POA&M package, 3PAO assessment, monthly ConMon, and the FedRAMP 20x direction.
How to load a skill
Identify the skill name above matching your task.
Read skills/<skill-name>/SKILL.md (the router); load the chunks its §11 routing table
selects for your intent. In an installed environment, read the skill's SKILL.md from
wherever this library was installed.
Follow those instructions to complete the request.
Do not guess best practices — always read from the skill file first.
Quick reference: Which skill to use?
Task
Skill
IT audit planning, COBIT assessment, ITGC/ITAC testing
isaca-audit-methodology
SOX 404, internal control evaluation, deficiency classification
coso-internal-controls
SOC 1/2/3 scoping, TSC criteria, service org reporting