Compliance & Audit
Compliance & Audit
10 skills in Compliance & Audit.
10 skills in this category.
Audit Prep Review
An audit is coming — run the pre-audit sweep for unresolved prior findings, documentation gaps, and stale evidence, and return a ranked readiness report before the auditor finds it first.
Change Request Prerequisites
A change request needs validating before it goes for approval — check it against the prerequisites template (justification, scope, rollback, window, approver) and bounce incomplete requests with an itemized list.
CMMC Readiness Brief
Produce a CMMC level-readiness snapshot for a defense-adjacent client — where they likely stand against the target level's practices and the obvious gaps — then flag it to the compliance owner; never a certification or an assessment.
Compliance Questionnaire Assist
A client received a security or compliance questionnaire (from their customer, prospect, or regulator) — draft answers from documented facts only, cite sources, and flag unknowns honestly instead of guessing.
Cyber Insurance Form Prep
A cyber-insurance application or renewal questionnaire needs filling — draft answers from ticket, RMM, and posture evidence, cite the source for each, and mark every unverifiable answer for human review.
HIPAA Safeguards Checklist
Walk a healthcare client's environment against the HIPAA Security Rule technical safeguards and return a checklist of what's in place versus missing — a technical review to inform the client's compliance work, explicitly not legal advice.
NIST CSF Gap Brief
Map a client's current security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — where they stand per function and what's missing — with no certification or compliance claims.
PCI DSS Scope Review
Help a client understand their PCI DSS scope — what counts as the cardholder data environment (CDE), what's in versus out, and hold the "we don't touch cardholder data" boundary honestly — not a QSA assessment or an Attestation of Compliance.
Security Questionnaire Vendor DDQ
An inbound vendor security questionnaire or due-diligence questionnaire (DDQ) needs answering — draft responses from documented facts only, cite the evidence for each, and flag every unknown for human review rather than guessing.
SOC2 Evidence Collection
An auditor sent an evidence request list (SOC 2 or similar) — map each request to ticket, change, and access evidence, and package it with citations and honestly flagged gaps.
Was this page helpful?
⌘I