Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Cloud Compliance Specialist

  • 28 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Prepare cloud compliance: map SOC 2/ISO/HIPAA/PCI/FedRAMP to cloud controls, collect API evidence, and prove residency in multi-account estates.

About

Guides cloud compliance covering framework-to-cloud-control mapping, audit evidence from AWS/GCP/Azure APIs, shared-responsibility narratives, CSPM monitoring, and data residency. A developer uses it when preparing cloud control evidence for auditors or proving residency.

  • Maps SOC 2/ISO/HIPAA/PCI/FedRAMP to cloud-native evidence
  • Evidence collectors from AWS/GCP/Azure APIs and CSPM dashboards

Cloud Compliance Specialist by the numbers

  • 28 all-time installs (skills.sh)
  • Ranked #1,512 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill cloud-compliance-specialist

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs28
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Prepare cloud compliance: map SOC 2/ISO/HIPAA/PCI/FedRAMP to cloud controls, collect API evidence, and prove residency in multi-account estates.

Files

SKILL.mdMarkdownGitHub ↗

Cloud Compliance Specialist

When to Use

  • Scope cloud workloads for SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or regional privacy rules
  • Map framework controls to cloud-native evidence (Config, org trails, IAM reports, KMS)
  • Build evidence collectors from cloud APIs and central log archive
  • Prepare auditor walkthroughs for multi-account landing zones and SaaS on IaaS/PaaS
  • Respond to customer security questionnaires with cloud control proof
  • Design continuous cloud compliance dashboards (CIS conformance, posture rules)
  • Document data residency — regions, replication, cross-border transfers (technical facts)
  • Track cloud gap remediation before observation period or assessor visit
  • Interpret provider shared responsibility and inheritance in audit narratives

When NOT to Use

  • Enterprise-wide GRC program, policies, audit prep (non-cloud) → compliance-specialist
  • Org-wide technical evidence automation → compliance-engineer
  • Implement SCPs, IAM hardening, CSPM rules → cloud-security-engineer
  • Landing zone architecture without compliance lens → cloud-architect, enterprise-cloud-architect
  • Cloud program strategy and migration portfolio governance → vp-of-cloud
  • Legal advice, DPAs, regulatory interpretation → commercial-counsel, corporate-counsel
  • SOX financial controls and journal testing → senior-revenue-accountant
  • Pipeline SAST/SBOM configuration → devsecops
  • AI model regulatory classification → ai-risk-governance

Related skills

NeedSkill
VP cloud program and regulated placement themesvp-of-cloud
GRC program, scope, gap plans, audit coordinationcompliance-specialist
Cross-domain compliance and evidence automationcompliance-engineer
Cloud security control implementationcloud-security-engineer
Enterprise cloud governance and CCoEenterprise-cloud-architect
Cloud reference architecturecloud-architect
Security program strategycybersecurity
Pipeline and SSDF evidencedevsecops
Data governance and privacy architecturedata-architect
Physical DC compliance evidencedata-center-design-execution-lead
FinOps spend analysisfinops-analyst
GL mapping and invoice reconciliationcompute-accounting-manager
Security risk registers and third-party risk tierssecurity-risk-analyst

Core Workflows

1. Scope and shared responsibility

Cloud in-scope boundaries and provider vs customer duties for audits.

See `references/cloud_compliance_scope.md`.

2. Framework mapping in cloud

SOC 2, ISO, HIPAA, PCI, FedRAMP control patterns on cloud.

See `references/framework_cloud_mapping.md`.

3. Cloud evidence collection

API sources, samples, retention for assessors.

See `references/cloud_evidence_collection.md`.

4. Residency and sovereignty

Regions, replication, cross-border technical documentation.

See `references/residency_sovereignty.md`.

5. Continuous cloud monitoring

CSPM, Config rules, drift and exceptions.

See `references/continuous_cloud_monitoring.md`.

6. Audit readiness and customer assurance

Walkthroughs, CAIQ/SIG, gap closure.

See `references/audit_readiness_cloud.md`.

Outputs

  • Cloud compliance scope memo — accounts, services, data classes, inherited controls
  • Control-to-evidence matrix — framework ID, cloud check, source, cadence, owner
  • Evidence package — exports with timestamps and population notes
  • Residency diagram — regions, backups, DR, subprocessors (technical)
  • CCM dashboard spec — rules, thresholds, exception register
  • Assessor FAQ — shared responsibility, logging, encryption, access

Principles

  • Inherit explicitly — document what the hyperscaler attests vs what you must prove
  • Evidence from systems of record — APIs and logs, not screenshots alone
  • Scope narrow — exclude out-of-scope accounts and legacy unless required
  • Continuous over point-in-time — drift detection before the auditor finds it
  • Partner with security — compliance defines what; cloud-security-engineer implements how

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.