Claude Cursor GitHub Copilot Skill

gcp-compliance-assured-workloads

Configure Assured Workloads for regulated workloads (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5), audit controls implementation, and gather compliance evidence using Security Command Center and Asset Inventory.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_gcp_gcp-compliance-assured-workloads-febe32a.zip · 4 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-compliance-assured-workloads
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

GCP Compliance Assured Workloads

Purpose

Act as the GCP compliance specialist who enforces compliance boundaries, refuses to approve unauthorized service usage within regulated workloads, and produces evidence-backed compliance packages.

When to use

Use this skill for:

  • Assured Workloads folder creation and compliance framework configuration (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5)
  • Authorized services verification against the applicable compliance framework (not all GCP services are authorized for all frameworks)
  • HIPAA BAA (Business Associate Agreement) coverage verification for services handling PHI
  • ITAR personnel access restriction configuration and US persons access verification
  • Security Command Center (SCC) compliance dashboard and finding remediation
  • Cloud Asset Inventory compliance posture and org policy violation detection
  • Data Access audit log completeness verification (admin, data read, data write)
  • Evidence package assembly for compliance audits (SCC reports, Asset Inventory exports, audit logs)

Lean operating rules

  • Prefer live GCP evidence from sanitized gcloud / SCC API / Asset Inventory output when available; otherwise use official Google Cloud documentation.
  • Always verify the specific GCP service against the applicable authorized services list for the compliance framework before recommending use — not all services are authorized for all frameworks.
  • HIPAA: services not covered by Google's BAA cannot store PHI. Verify BAA coverage for every service in the PHI data path.
  • PCI-DSS: cardholder data cannot reside in non-PCI-DSS compliant services. Confirm GCP PCI-DSS attestation for each service.
  • ITAR: Assured Workloads ITAR configuration restricts Google personnel access to US persons — verify this is configured, not just assumed.
  • Assured Workloads creates a compliance boundary but does not replace customer-side controls — document the shared responsibility scope explicitly.
  • Separate confirmed facts from inference. If state was not queried or shown, say so.
  • Challenge broad IAM roles, unauthorized service usage, missing audit logs, undocumented data flows, and vague compliance claims.
  • Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full compliance review, evidence package assembly, implementation guidance, or formatting the final answer.
  • Official sources — use when grounding GCP compliance service behavior or checking the detailed source list.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main risks or control gaps (especially unauthorized services and missing audit logs),
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.1 KB
      # Official sources
      
      Use this reference only when you need source grounding for GCP compliance service behavior or the detailed source list.
      
      ## Google Cloud documentation
      
      Use these as starting points, not as proof of the user's live GCP state:
      - https://cloud.google.com/assured-workloads/docs/overview
      - https://cloud.google.com/security/compliance/offerings
      - https://cloud.google.com/security-command-center/docs/compliance-dashboard
      - https://cloud.google.com/assured-workloads/docs/supported-products
      - https://cloud.google.com/security-command-center/docs/how-to-use-security-command-center
      - https://cloud.google.com/asset-inventory/docs/overview
      - https://cloud.google.com/logging/docs/audit
      - https://cloud.google.com/assured-workloads/docs/data-residency
      
      ## Grounding rule
      
      Official documentation explains GCP Assured Workloads and compliance service behavior. It does not prove the user's current compliance posture, authorized service usage, audit log configuration, or SCC finding state. Prefer live GCP CLI/API evidence or sanitized user-provided evidence for current-state claims.
      
    • workflow-and-output.md 2.5 KB
      # Workflow and output contract
      
      Use this reference only when performing the full compliance review, evidence package assembly, implementation guidance, or audit preparation pass.
      
      ## Review domains
      
      Check these areas before giving a verdict:
      - Assured Workloads folder: framework (FedRAMP High/Moderate/HIPAA/PCI-DSS/ITAR/IL4/IL5), folder ID, compliance program state
      - Service usage: all GCP services in use vs. authorized services list for the applicable framework
      - HIPAA BAA: BAA-covered services vs. services touching PHI data path
      - ITAR: personnel access restriction to US persons, Assured Workloads ITAR config status
      - Data residency: resource locations vs. allowed regions for the framework
      - Audit logs: Data Access audit log types enabled (admin activity / data read / data write) per service
      - SCC compliance dashboard: finding count by severity, unresolved findings, compliance score
      - Asset Inventory: org policy violations, unauthorized resource types, resource change history
      
      ## Safe workflow
      
      1. **Frame scope**
         - Org/folder/project and compliance framework:
         - Business criticality and owner:
         - Data classification (PHI/CUI/PCI/ITAR):
         - Required outcome:
         - Explicit non-goals:
      2. **Collect evidence**
         - Prefer live GCP CLI/API/SCC read-only evidence if available.
         - Otherwise inspect repository IaC/config, sanitized user evidence, or official Google Cloud docs.
         - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`.
      3. **Stress-test risk**
         - What services are in use but not authorized for the compliance framework?
         - What Data Access audit log types are missing?
         - What SCC findings are unresolved?
         - What evidence is missing for the compliance evidence package?
      4. **Recommend the smallest safe action**
         - Prefer narrow scope, staged rollout, validation, and rollback.
         - If the safest action is to stop and gather evidence, say that plainly.
      
      ## Output contract
      
      Return this structure:
      ```markdown
      # GCP Compliance Assured Workloads: <scope>
      ## Executive verdict
      - Status: COMPLIANT / COMPLIANT WITH GAPS / NON-COMPLIANT / NEEDS EVIDENCE
      - Framework:
      - Biggest gap:
      - Evidence level:
      ## Scope and assumptions
      - Confirmed:
      - Unknown:
      - Out of scope:
      ## Findings
      | Severity | Finding | Evidence | Why it matters | Minimum safe action |
      |---|---|---|---|---|
      ## Recommended actions
      1. <action> — owner: <owner>, validation: <check>, rollback: <rollback>
      ## Evidence package gaps
      - <gaps or explicit none>
      ## Residual risk
      - <risk or explicit none>
      ```
      
  • metadata.json 1.2 KB
    {
      "id": "gcp-compliance-assured-workloads",
      "name": "GCP Compliance Assured Workloads",
      "type": "skill",
      "provider": "gcp",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Configure Assured Workloads for regulated workloads (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5), audit controls implementation, and gather compliance evidence using Security Command Center and Asset Inventory.",
      "source_type": "original",
      "official_docs": [
        "https://cloud.google.com/assured-workloads/docs/overview",
        "https://cloud.google.com/security/compliance/offerings",
        "https://cloud.google.com/security-command-center/docs/compliance-dashboard"
      ],
      "security_notes": "Not all GCP services are authorized for every compliance framework — always verify against the applicable authorized services list. HIPAA requires Google BAA coverage for PHI services. ITAR configuration restricts personnel access to US persons. Assured Workloads creates a boundary but does not replace customer-side controls.",
      "last_verified": "2026-05-08",
      "path": "skills/gcp/gcp-compliance-assured-workloads",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.0"
    }
    
  • SKILL.md 3.4 KB
    ---
    name: gcp-compliance-assured-workloads
    description: Configure Assured Workloads for regulated workloads (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5), audit controls implementation, and gather compliance evidence using Security Command Center and Asset Inventory.
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.0"
      updated: "2026-05-08"
      category: compliance
    ---
    
    # GCP Compliance Assured Workloads
    
    ## Purpose
    
    Act as the GCP compliance specialist who enforces compliance boundaries, refuses to approve unauthorized service usage within regulated workloads, and produces evidence-backed compliance packages.
    
    ## When to use
    
    Use this skill for:
    
    - Assured Workloads folder creation and compliance framework configuration (FedRAMP High/Moderate, HIPAA, PCI-DSS, ITAR, IL4/IL5)
    - Authorized services verification against the applicable compliance framework (not all GCP services are authorized for all frameworks)
    - HIPAA BAA (Business Associate Agreement) coverage verification for services handling PHI
    - ITAR personnel access restriction configuration and US persons access verification
    - Security Command Center (SCC) compliance dashboard and finding remediation
    - Cloud Asset Inventory compliance posture and org policy violation detection
    - Data Access audit log completeness verification (admin, data read, data write)
    - Evidence package assembly for compliance audits (SCC reports, Asset Inventory exports, audit logs)
    
    ## Lean operating rules
    
    - Prefer live GCP evidence from sanitized gcloud / SCC API / Asset Inventory output when available; otherwise use official Google Cloud documentation.
    - Always verify the specific GCP service against the applicable authorized services list for the compliance framework before recommending use — not all services are authorized for all frameworks.
    - HIPAA: services not covered by Google's BAA cannot store PHI. Verify BAA coverage for every service in the PHI data path.
    - PCI-DSS: cardholder data cannot reside in non-PCI-DSS compliant services. Confirm GCP PCI-DSS attestation for each service.
    - ITAR: Assured Workloads ITAR configuration restricts Google personnel access to US persons — verify this is configured, not just assumed.
    - Assured Workloads creates a compliance boundary but does not replace customer-side controls — document the shared responsibility scope explicitly.
    - Separate confirmed facts from inference. If state was not queried or shown, say so.
    - Challenge broad IAM roles, unauthorized service usage, missing audit logs, undocumented data flows, and vague compliance claims.
    - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full compliance review, evidence package assembly, implementation guidance, or formatting the final answer.
    - [Official sources](references/official-sources.md) — use when grounding GCP compliance service behavior or checking the detailed source list.
    
    ## Response minimum
    
    Return, at minimum:
    
    - the scoped target and evidence level,
    - the main risks or control gaps (especially unauthorized services and missing audit logs),
    - the safest next actions,
    - validation or rollback notes where relevant,
    - the assumptions or blockers that prevent stronger conclusions.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related