Security Compliance Framework
Paste the following prompt into your AI chat to install this skill:
Install @user_2354702d/security-compliance into your AI assistant by following https://skillhub.cn/install/skillhub.md.
About this skill
Problems it addresses
Security compliance work often fails because requirements are scattered and evidence is weak: MLPS 2.0 levels are unclear, assessment deductions are hard to trace, data-law obligations remain abstract, and data classification lacks executable standards. For internet, finance, and cross-border teams, the core problem is mapping regulations to engineering controls across physical, network, host, application, and data security.
How it works
- MLPS 2.0: determines the protection level, breaks controls into physical, network, host, application, and data security, and flags common deductions such as weak boundary access control, stale host patches,
SQL injection, and unvalidated backups. - Three-law compliance: organizes requirements from the
Cybersecurity Law,Data Security Law, andPersonal Information Protection Law, including log retention, incident response, data classification, minimal collection, sensitive-data protection, and DPIA. - Data classification: classifies data by customer, operations, finance, employee, and supplier attributes, then provides public, internal, sensitive, confidential, and top-secret examples with protection requirements.
- Compliance readiness: guides self-assessment, gap analysis, remediation planning, evidence collection, and ongoing operations; for offshore listings or foreign-invested contexts, it adds SOX 404 ITGC topics such as access control, change management, and segregation of duties.
Boundaries
It helps with gap analysis, remediation planning, and audit evidence organization. It does not replace legal counsel, formal assessment agencies, or penetration testing. Passing MLPS or meeting three-law requirements is a baseline, not proof that security operations are mature.
Use Cases
- An internet company preparing for an MLPS Level 3 assessment needs to map remediation evidence across physical, network, host, application, and data security controls.
- A data team must build a classification matrix for customer, finance, and source-code data, then assign access, encryption, and audit requirements.
- A cross-border business team needs to assemble ITGC evidence for financial-system access control, change management, and segregation of duties before audit.
- Legal and security teams need a three-law self-assessment covering log retention, consent, data export, and sensitive personal-data handling.
Best For
- Security engineers who need to turn MLPS requirements into concrete control items and remediation checklists.
- Data compliance owners who must classify customer, finance, and source-code data and define protection controls.
- Cross-border security liaisons who need to prepare SOX ITGC evidence for access control and change management.
- Legal specialists who want to convert three-law obligations into reviewable business processes and gap tables.
Related Skills
Based on Hengsheng Juyuan MCP financial data, it assesses equity, bond, commodity, and overseas markets and produces sourced risk reports with allocation guidance.
Applies a six-question industry-chain framework for structured fundamental analysis of sectors, profit pools, competition, ROIC, valuation, and domestic substitution.
Performs structured contract risk assessment, adds revision suggestions in the document, and generates a standalone review report.
A single-stock research framework that produces seven-dimension drafts, integrated analysis, scenario projections, and dual-track reference, with optional comparison and no investment advice.