Generate automated scripts for collecting SOC2 compliance evidence from cloud infrastructure, identity providers, and development workflows.
You are a GRC automation engineer. Generate scripts for automated SOC2 evidence collection. ## Configuration - **Cloud Provider**: [CLOUD e.g. AWS / Azure / GCP] - **Identity Provider**: [IDP e.g. Okta / Entra ID / Auth0] - **Source Control**: [SCM e.g. GitHub / GitLab / Bitbucket] - **Monitoring**: [MONITORING e.g. Datadog / Splunk / CloudWatch] - **Trust Criteria**: [CRITERIA e.g. CC6.1 Logical Access / CC7.2 System Monitoring / CC8.1 Change Management] ## Evidence Collection Scripts ### 1. Logical Access Controls (CC6.x) - Export [IDP] user list with role assignments and last login - MFA enrollment status report - Privileged access inventory from [CLOUD] IAM - Service account audit with permission scope - Access review completion tracking - Terminated user deprovisioning verification ### 2. System Operations (CC7.x) - [MONITORING] alert configuration export - Uptime SLA compliance report from [CLOUD] - Backup execution and restoration test logs - Vulnerability scan results summary - Patch management compliance status - Incident ticket resolution metrics ### 3. Change Management (CC8.x) - [SCM] pull request approval workflow evidence - Deployment pipeline configuration with required approvals - Production change log with rollback evidence - Code review completion rates - Release notes and change advisory board records ### 4. Risk Management (CC9.x) - Vendor risk assessment inventory - Business continuity plan test results - Risk register with treatment plans - Insurance coverage documentation Generate Python scripts using [CLOUD] SDK, [IDP] API, and [SCM] API. Include scheduling with cron, output in auditor-friendly formats (CSV, PDF), and a central evidence repository structure.
Free to copy and use. Compatible with Claude 4 Opus, Claude 4 Sonnet, GPT-5, Gemini 2.0 Flash.
Specify your cloud provider, identity provider, and source control platform. Set up API credentials with read-only permissions. Schedule weekly evidence collection and store outputs in a versioned repository.
Initial release
Sign in and download this prompt to leave a review.