Back to Skills

security-frameworks

verified

Security framework alignment including ISO 27001, SOC 2, NIST CSF 2.0, and CIS Controls mapping

View on GitHub

Marketplace

melodic-software

melodic-software/claude-code-plugins

Plugin

compliance-planning

Repository
Verified Org

melodic-software/claude-code-plugins
13stars

plugins/compliance-planning/skills/security-frameworks/SKILL.md

Last Verified

January 21, 2026

Install Skill

Select agents to install to:

Scope:
npx add-skill https://github.com/melodic-software/claude-code-plugins/blob/main/plugins/compliance-planning/skills/security-frameworks/SKILL.md -a claude-code --skill security-frameworks

Installation paths:

Claude
.claude/skills/security-frameworks/
Powered by add-skill CLI

Instructions

# Security Frameworks Planning

Comprehensive guidance for security framework alignment and control mapping before development begins.

## When to Use This Skill

- Preparing for ISO 27001 certification
- Planning SOC 2 Type I or Type II audits
- Implementing NIST Cybersecurity Framework 2.0
- Mapping CIS Controls to your environment
- Creating cross-framework control mappings

## Framework Comparison

### When to Use Which Framework

| Framework | Best For | Certification? | Geography |
|-----------|----------|---------------|-----------|
| **ISO 27001** | Enterprise ISMS, international recognition | Yes (3rd party) | Global |
| **SOC 2** | SaaS/Cloud providers, customer trust | Yes (CPA firm) | Primarily US |
| **NIST CSF** | Risk management, federal requirements | No | US-focused |
| **CIS Controls** | Tactical implementation, prioritization | No | Global |

### Framework Relationships

```text
                    ┌─────────────────┐
                    │   Regulations   │
                    │ (GDPR, HIPAA)   │
                    └────────┬────────┘
                             │ drives
                    ┌────────▼────────┐
                    │   Frameworks    │
                    │(ISO, NIST, CIS) │
                    └────────┬────────┘
                             │ implements
                    ┌────────▼────────┐
                    │    Controls     │
                    │ (specific tech) │
                    └────────┬────────┘
                             │ evidenced by
                    ┌────────▼────────┐
                    │    Audits       │
                    │ (SOC 2, ISO)    │
                    └─────────────────┘
```

## ISO 27001:2022

### Structure Overview

```text
Clauses 4-10: Management System Requirements
├── 4. Context of the organization
├── 5. Leadership
├── 6. Planning
├── 7. Support
├── 8. Operation
├── 9. Performance evaluation
└── 10. Improvement

Annex A: 93 Controls in 4 Themes
├── A.5 Organizational controls (37)
├─

Validation Details

Front Matter
Required Fields
Valid Name Format
Valid Description
Has Sections
Allowed Tools
Instruction Length:
13355 chars