Conducts systematic access reviews and certifications to ensure role-appropriate user permissions. Covers activity design, risk-based prioritization, reviewer selection, micro-certification, and remediation tracking for SOX, HIPAA, PCI DSS compliance.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
开展系统性的访问审查和认证,确保用户拥有与其角色相符的访问权限。涵盖审查活动设计、审查员选择、基于风险的优先级排序、微认证策略,以及满足 SOX、HIPAA 和 PCI DSS 要求的整改跟踪。
Conducts systematic access reviews and certifications to ensure users have role-aligned access rights. Covers campaign design, reviewer selection, risk prioritization, and remediation for SOX, HIPAA, PCI DSS compliance.
Conducts systematic access reviews and certifications for IAM compliance, including campaign design, risk-based prioritization, reviewer selection, remediation tracking, and reporting.
Executes SailPoint IdentityIQ entitlement reviews including manager certifications, targeted access reviews, role verification, SoD remediation, and automated revocation workflows. For IGA compliance and access governance.
Share bugs, ideas, or general feedback.
开展系统性的访问审查和认证,确保用户拥有与其角色相符的访问权限。涵盖审查活动设计、审查员选择、基于风险的优先级排序、微认证策略,以及满足 SOX、HIPAA 和 PCI DSS 要求的整改跟踪。
| 控制项 | NIST 800-53 | 描述 |
|---|---|---|
| 访问审查 | AC-2(3) | 定期审查账户权限 |
| 账户管理 | AC-2 | 账户生命周期管理 |
| 最小权限 | AC-6 | 强制执行最小必要访问 |
| 职责分离 | AC-5 | SoD 冲突识别 |
| 审计日志 | AU-6 | 访问审计记录审查 |