一键导入
audit-assess
Audit preparation, evidence checklists, assessment simulation, gap analysis, and maturity scoring.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Audit preparation, evidence checklists, assessment simulation, gap analysis, and maturity scoring.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Draft SSP sections, SAR responses, boundary definitions, inheritance models, OSCAL guidance, and multi-framework coverage analyses.
Operational compliance workflows: continuous monitoring, calendaring, POA&M management, change management, and framework transitions.
Maps controls across cybersecurity frameworks using NIST IR 8477 Set-Theory Relationship Mapping (STRM). Use when helping with control implementation, compliance mapping, cross-framework alignment, or understanding control relationships.
Control lookup, cross-framework mapping, search, and coverage analysis across 15 compliance frameworks.
Review SSPs, narratives, POA&Ms, policies, and CRMs for structural completeness and quality.
Generate tabletop exercise scenarios for incident response and contingency planning.
| name | audit-assess |
| description | Audit preparation, evidence checklists, assessment simulation, gap analysis, and maturity scoring. |
Prepare for audits, generate evidence checklists, simulate 3PAO assessments, conduct gap analyses, and score organizational maturity.
| Command | Description |
|---|---|
/grc:audit-prep | Audit preparation guidance by framework |
/grc:evidence-checklist | Generate evidence requirement checklists by control |
/grc:evidence-examples | Evidence examples by control |
/grc:3pao-dryrun | Simulate a FedRAMP 3PAO assessment |
/grc:pmo-review | PMO review templates |
/grc:isora-assess | ISORA assessment guidance |
/grc:score-maturity | Maturity scoring on 0-5 scale |
/grc:gap-analysis | Structured gap analysis by framework and scope |
Use this skill when the user needs to:
grc-pro/knowledge/audits/*.md — All audit guidance (3PAO, SOC 2, ISO, PCI QSA, internal, gap analysis)grc-pro/knowledge/audits/narrative-quality-criteria.md — Maturity scoring rubricgrc-pro/knowledge/frameworks/*.md — Framework requirements contextgrc-pro/config/guardrails.md — Operational principlesWhen the grc-mcp-server is available:
| MCP Tool | Use For |
|---|---|
grc_get_oscal_control | Extract assessment objectives and methods for evidence checklists |
grc_lookup_risk | Risk context for gap analysis |
grc_search_risks | Find risks related to specific controls |
grc_coverage_report | Coverage analysis between frameworks |
grc_strm_analyze | IR 8477 STRM analysis to understand mapping strength and gaps |
grc_map_control | Cross-framework mapping for multi-framework audits |