sota-security-compliance
Installation
SKILL.md
SOTA Security & Compliance Engineering
The engineering half of cybersecurity regulation: how to make a control framework a property of the codebase, pipeline, and infrastructure rather than a binder of policy documents. A control that lives in a schema, an IAM policy, a CI gate, or a signed SBOM survives staff turnover and an assessor's sampling; a control that lives in a wiki page does not.
This skill is the security/regulation counterpart to sota-privacy-compliance
(which owns personal-data lifecycle, GDPR, SOC 2, ISO 27001). It owns the
cybersecurity control frameworks and product-security regulations — NIST CSF
2.0, SP 800-53, SP 800-171 / CMMC, SSDF (SP 800-218), FedRAMP, the EU Cyber
Resilience Act, and ISA/IEC 62443 for OT.