AI Agent Hub
Back to skills
⚖️

Security Compliance Framework

Professional Updated 2026.08.29

Paste the following prompt into your AI chat to install this skill:

Install @user_2354702d/security-compliance into your AI assistant by following https://skillhub.cn/install/skillhub.md.

About this skill

Problems it addresses

Security compliance work often fails because requirements are scattered and evidence is weak: MLPS 2.0 levels are unclear, assessment deductions are hard to trace, data-law obligations remain abstract, and data classification lacks executable standards. For internet, finance, and cross-border teams, the core problem is mapping regulations to engineering controls across physical, network, host, application, and data security.

How it works

  • MLPS 2.0: determines the protection level, breaks controls into physical, network, host, application, and data security, and flags common deductions such as weak boundary access control, stale host patches, SQL injection, and unvalidated backups.
  • Three-law compliance: organizes requirements from the Cybersecurity Law, Data Security Law, and Personal Information Protection Law, including log retention, incident response, data classification, minimal collection, sensitive-data protection, and DPIA.
  • Data classification: classifies data by customer, operations, finance, employee, and supplier attributes, then provides public, internal, sensitive, confidential, and top-secret examples with protection requirements.
  • Compliance readiness: guides self-assessment, gap analysis, remediation planning, evidence collection, and ongoing operations; for offshore listings or foreign-invested contexts, it adds SOX 404 ITGC topics such as access control, change management, and segregation of duties.

Boundaries

It helps with gap analysis, remediation planning, and audit evidence organization. It does not replace legal counsel, formal assessment agencies, or penetration testing. Passing MLPS or meeting three-law requirements is a baseline, not proof that security operations are mature.

Use Cases

  • An internet company preparing for an MLPS Level 3 assessment needs to map remediation evidence across physical, network, host, application, and data security controls.
  • A data team must build a classification matrix for customer, finance, and source-code data, then assign access, encryption, and audit requirements.
  • A cross-border business team needs to assemble ITGC evidence for financial-system access control, change management, and segregation of duties before audit.
  • Legal and security teams need a three-law self-assessment covering log retention, consent, data export, and sensitive personal-data handling.

Best For

  • Security engineers who need to turn MLPS requirements into concrete control items and remediation checklists.
  • Data compliance owners who must classify customer, finance, and source-code data and define protection controls.
  • Cross-border security liaisons who need to prepare SOX ITGC evidence for access control and change management.
  • Legal specialists who want to convert three-law obligations into reviewable business processes and gap tables.