Generate an automated SOC2 compliance framework with evidence collection, control mapping, continuous monitoring, and audit-ready reporting.
You are a compliance automation engineer specializing in SOC2 Type II audits. Build a comprehensive compliance automation framework. ## Configuration - **Trust Service Criteria**: [CRITERIA e.g. Security / Availability / Processing Integrity / Confidentiality / Privacy] - **Cloud Provider**: [CLOUD e.g. AWS / Azure / GCP / multi-cloud] - **Tech Stack**: [STACK e.g. Kubernetes / serverless / VMs / hybrid] - **Team Size**: [TEAM e.g. 10 / 50 / 200 engineers] - **Audit Timeline**: [TIMELINE e.g. 3 months / 6 months / 12 months] ## Framework Components ### 1. Control Mapping - Map [CRITERIA] trust service criteria to specific controls - Control ownership assignment matrix for [TEAM] engineers - Gap analysis between current state and SOC2 requirements - Risk assessment and prioritization framework - Control implementation timeline for [TIMELINE] ### 2. Automated Evidence Collection - [CLOUD] API-based configuration snapshots - Access review automation scripts - Change management evidence from Git/Jira - Infrastructure compliance scanning with Prowler/ScoutSuite - Automated screenshot and log collection ### 3. Continuous Monitoring - Real-time control effectiveness monitoring - Configuration drift detection for [STACK] - Access anomaly detection and alerting - Vendor risk assessment automation - Policy violation tracking and remediation workflows ### 4. Audit-Ready Reporting - Control matrix with evidence links - Exception tracking with remediation plans - Management assertion letter template - Auditor-facing dashboard with drill-down - Historical compliance trend reporting Generate Python automation scripts, Terraform compliance modules for [CLOUD], monitoring configurations, and report templates. Include a 90-day implementation roadmap.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro, Gemini 2.0 Flash.
Select the trust service criteria relevant to your organization. Specify your cloud provider and tech stack. Begin with the gap analysis to prioritize controls, then implement automated evidence collection.
Initial release
Sign in and download this prompt to leave a review.