File contents 📋 Compliance Analyst
Sertifikasyon ve uyumluluk araştırma rehberi.
📋 Compliance Areas
Area
Standards
Examples
Security
ISO 27001, SOC 2
Data protection
Privacy
GDPR, KVKK, CCPA
Personal data
Accessibility
WCAG, ADA
Web access
Industry
HIPAA, PCI-DSS
Healthcare, payments
🔧 Compliance Checklist
GDPR
- [ ] Consent management
- [ ] Right to deletion
- [ ] Data portability
- [ ] Privacy policy
- [ ] DPO appointed
- [ ] Breach notification
SOC 2
- [ ] Security controls
- [ ] Availability SLA
- [ ] Processing integrity
- [ ] Confidentiality
- [ ] Privacy practices
📊 Gap Analysis Template
# Compliance Gap Analysis: [Standard]
## Current State
| Control | Required | Current | Gap |
|---------|----------|---------|-----|
| Access Control | Yes | Partial | ⚠️ |
| Encryption | Yes | Yes | ✅ |
| Logging | Yes | No | ❌ |
## Remediation Plan
| Gap | Action | Owner | Deadline |
|-----|--------|-------|----------|
| Logging | Implement audit logs | DevOps | Q1 |
## Timeline to Compliance
- Gap remediation: 3 months
- Audit prep: 1 month
- Certification: 2 months
🎯 Certification Path
Assessment → Gap Analysis → Remediation → Audit → Certification
└─────────────────────────────────────────────┘
6-12 months
🔄 Workflow
Kaynak: Compliance-As-Code (SCAP) & EU AI Act Compliance Framework
Aşama 1: Regulatory Scoping & DORA/AI Act
Aşama 2: Audit & Gap Assessment
Aşama 3: Remediation & Continuous Compliance
Kontrol Noktaları
Aşama
Doğrulama
1
Yeni çıkan "EU AI Act" kriterleri göz önünde bulunduruldu mu?
2
Veri işleme envanteri (ROPA) güncel mi?
3
Tedarikçi (Third-party) riski analiz edildi mi?
Compliance Analyst v1.5 - With Workflow
1 --- 2 name: compliance-analyst 3 description: 📋 Compliance Analyst 4 --- 5 6 # 📋 Compliance Analyst 7 8 > Sertifikasyon ve uyumluluk araştırma rehberi. 9 10 --- 11 12 ## 📋 Compliance Areas 13 14 | Area | Standards | Examples | 15 |------|-----------|----------| 16 | **Security** | ISO 27001, SOC 2 | Data protection | 17 | **Privacy** | GDPR, KVKK, CCPA | Personal data | 18 | **Accessibility** | WCAG, ADA | Web access | 19 | **Industry** | HIPAA, PCI-DSS | Healthcare, payments | 20 21 --- 22 23 ## 🔧 Compliance Checklist 24 25 ### GDPR 26 ```checklist 27 - [ ] Consent management 28 - [ ] Right to deletion 29 - [ ] Data portability 30 - [ ] Privacy policy 31 - [ ] DPO appointed 32 - [ ] Breach notification 33 ``` 34 35 ### SOC 2 36 ```checklist 37 - [ ] Security controls 38 - [ ] Availability SLA 39 - [ ] Processing integrity 40 - [ ] Confidentiality 41 - [ ] Privacy practices 42 ``` 43 44 --- 45 46 ## 📊 Gap Analysis Template 47 48 ```markdown 49 # Compliance Gap Analysis: [Standard] 50 51 ## Current State 52 | Control | Required | Current | Gap | 53 |---------|----------|---------|-----| 54 | Access Control | Yes | Partial | ⚠️ | 55 | Encryption | Yes | Yes | ✅ | 56 | Logging | Yes | No | ❌ | 57 58 ## Remediation Plan 59 | Gap | Action | Owner | Deadline | 60 |-----|--------|-------|----------| 61 | Logging | Implement audit logs | DevOps | Q1 | 62 63 ## Timeline to Compliance 64 - Gap remediation: 3 months 65 - Audit prep: 1 month 66 - Certification: 2 months 67 ``` 68 69 --- 70 71 ## 🎯 Certification Path 72 73 ``` 74 Assessment → Gap Analysis → Remediation → Audit → Certification 75 └─────────────────────────────────────────────┘ 76 6-12 months 77 ``` 78 79 ## 🔄 Workflow 80 81 > **Kaynak:** [Compliance-As-Code (SCAP)](https://github.com/ComplianceAsCode/content) & [EU AI Act Compliance Framework](https://artificialintelligenceact.eu/) 82 83 ### Aşama 1: Regulatory Scoping & DORA/AI Act 84 - [ ] **Inventory**: Sistemin hangi düzenlemelere (DORA, NIS2, EU AI Act) tabi olduğunu belirle. 85 - [ ] **Risk Categorization**: AI sistemlerini risk seviyelerine (Unacceptable, High, Limited, Minimal) göre sınıflandır. 86 - [ ] **Standard Alignment**: ISO 27001 veya NIST framework'leri ile mevcut süreçleri eşleştir. 87 88 ### Aşama 2: Audit & Gap Assessment 89 - [ ] **Evidence Collection**: Politika belgeleri, log kayıtları ve sistem konfigürasyonlarını topla. 90 - [ ] **Gap Analysis**: Standart ile gerçek arasındaki farkları (Checklist tabanlı) raporla. 91 - [ ] **Impact Assessment**: Yeni yasal düzenlemelerin iş süreçleri üzerindeki finansal ve operasyonel etkisini analiz et. 92 93 ### Aşama 3: Remediation & Continuous Compliance 94 - [ ] **Mitigation Plan**: Eksikleri gidermek için aksiyon planı oluştur (Örn: MFA zorunluluğu). 95 - [ ] **Monitoring**: Uyumluluk durumunu otomatik dashboard'lar (SIEM/GRC araçları) ile izle. 96 - [ ] **Certification Prep**: Bağımsız denetçiler için "Audit-Ready" dosyasını hazırla. 97 98 ### Kontrol Noktaları 99 | Aşama | Doğrulama | 100 |-------|-----------| 101 | 1 | Yeni çıkan "EU AI Act" kriterleri göz önünde bulunduruldu mu? | 102 | 2 | Veri işleme envanteri (ROPA) güncel mi? | 103 | 3 | Tedarikçi (Third-party) riski analiz edildi mi? | 104 105 --- 106 *Compliance Analyst v1.5 - With Workflow*
aibot88/sec_skill_store/tree/main/skills/claudskills/compliance-analyst commit 63abf051ec
Frequently asked questions How do I install the Compliance Analyst skill? Run npx skillmds@latest add aibot88/compliance-analyst in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
What does the Compliance Analyst skill do? 📋 Compliance Analyst It is listed under Coding & Dev Tools on SkillMD.
Is Compliance Analyst safe to use? This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
Which AI agents work with Compliance Analyst? This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Is Compliance Analyst free to use? Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Who published Compliance Analyst? aibot88 (@aibot88) published this skill. Their other Agent Skills are listed on their SkillMD profile.