bacen-compliance-sentinel-rafael-mastronardi
Orientação completa sobre conformidade com regulamentações do Banco Central do Brasil: Resolução CMN nº 4.893/2021 (Política de Segurança Cibernética), Resolução BCB nº 85/2021 (GRSIC), Open Finance Brasil (Resoluções BCB nº 32/2020 e atualizações), e demais normas prudenciais do BACEN. Cobre elaboração e revisão de Política de Segurança Cibernética, Plano de Ação e Resposta a Incidentes (PARI), Gestão de Riscos de Serviços de Informação e Comunicação (GRSIC), consentimento e compartilhamento de dados no Open Finance, requisitos de API, gestão de terceiros (outsourcing) e sanções do BACEN. Tri
npx skills add lawve-ai/awesome-legal-skills --skill bacen-compliance-sentinel-rafael-mastronardi --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
Provides guidance on regulatory conformity for Brazilian financial institutions, covering PSC, PARI, GRSIC, Open Finance/Banking data sharing, Open Finance consent, API requirements, outsourcing, and BACEN sanctions. Includes a routing table to map user needs to normative actions and a step-by-step flow for elaborating the Política de Segurança Cibernética (PSC), including asset risk mapping, mandatory PSC sections, governance, training, and annual reporting. Also outlines Open Finance compliance, incident reporting timelines to BACEN, and sanctions framework, plus a PARI incident response script with identification, containment, and regulatory communication phases.
How it works
- Identifies user need and directs action using the routing table, mapping needs like PSC, PARI, GRSIC, Open Finance, consent, API, Pix security, incidents, sanctions, and annual reports to specific regulatory actions.
- For PSC, guides through diagnosis/segmentation, asset/risk mapping, and a structured PSC outline with sections: objectives, controls (IAM, encryption, monitoring, vulnerability management), data classification, third-party due diligence, PARI, tests/exercises, governance, training, and RAS.
- For GRSIC, notes due diligence, contract clauses, data location, and cloud requirements; emphasizes responsibility remains with the institution.
- For Open Finance, enumerates data phases, consent requirements, data providers/receivers roles, API standards, and SLA expectations, plus consent specifics and data use restrictions.
- For Pix/DICT and incident reporting, states reporting timelines to BACEN and required data in the communications form.
- Provides a PARI incident response script with phases: identification/classification, containment, and regulatory communication, including timelines (e.g., 3 days úteis to BACEN).
When to use it
Use when designing or reviewing a financial institution’s cyber and information governance programs to ensure compliance with CMN 4.893/2021, BCB 85/2021, Open Finance regulations, DICT, and related BACEN sanctions.
What it can touch
No explicit tool invocations are listed in the provided content beyond the referenced regulatory concepts. The skill references "Triggers" and a routing table but does not specify executable tool interactions in the FACTS section.
Caveats
- Includes a prominent aviso that guidance is not legal or regulatory advice and to consult specialized counsel.
- Contains regulatory interpretations and thresholds (e.g., incident timelines, data classifications, and reporting periods) as described in the bullet points, without asserting new outcomes.
- License declared as agpl-3.0; ensure compliance with license terms when integrating.
# BACEN Compliance Sentinel ## Aviso Importante (exibir no início da sessão) > **Atenção:** Esta skill fornece orientação estruturada sobre regulamentações do Banco Central do Brasil. Não constitui aconselhamento jurídico ou regulatório. Para decisões finais, consulte advogado especializado e o Diretor responsável pela área de Segurança Cibernética da instituição. --- ## Roteamento por Tarefa Identifique a necessidade do usuário e atue conforme a tabela: | Necessidade do Usuário | Normativo Central | Ação | |---|---|---| | "Política de Segurança Cibernética" / "PSC" | Res. CMN 4.893/2021 | Análise/elaboração da PSC | | "Plano de ação" / "resposta a incidente" / "PARI" | Res. CMN 4.893/2021, Art. 6º | Estruturar o PARI | | "GRSIC" / "serviços de TI" / "cloud" / "outsourcing" | Res. BCB 85/2021 | Avaliação de risco de terceiros | | "Open Finance" / "Open Banking" / "compartilhamento de dados" | Res. BCB 32/2020 e atualizações | Análise de conformidade Open Finance | | "Consentimento Open Finance" | Res. BCB 32/2020 | Requisitos de consentimento | | "API" / "requisitos técnicos Open Finance" | Manual Open Finance Brasil | Análise de requisitos técnicos | | "Pix segurança" / "DICT" / "
- Aviso Importante (exibir no início da sessão)
- Roteamento por Tarefa
- Pontos de Precisão Regulatória
- Resolução CMN nº 4.893/2021 — Segurança Cibernética
- Resolução BCB nº 85/2021 — GRSIC (Gestão de Riscos de TI)
- Open Finance Brasil — Resoluções BCB nº 32/2020 e atualizações
- Pix — Segurança e Conformidade
- Comunicação de Incidentes ao BACEN
- Sanções do BACEN
- Fluxo de Elaboração da Política de Segurança Cibernética (PSC)
- Fase 1: Diagnóstico e Segmentação
- Fase 2: Mapeamento de Ativos e Riscos
- Fase 3: Estrutura da PSC
- Fase 4: Aprovação e Comunicação
What does the bacen-compliance-sentinel-rafael-mastronardi skill do?
Orientação completa sobre conformidade com regulamentações do Banco Central do Brasil: Resolução CMN nº 4.893/2021 (Política de Segurança Cibernética), Resolução BCB nº 85/2021 (GRSIC), Open Finance Brasil (Resoluções BCB nº 32/2020 e atualizações), e demais normas prudenciais do BACEN. Cobre elaboração e revisão de Política de Segurança Cibernética, Plano de Ação e Resposta a Incidentes (PARI), Gestão de Riscos de Serviços de Informação e Comunicação (GRSIC), consentimento e compartilhamento de dados no Open Finance, requisitos de API, gestão de terceiros (outsourcing) e sanções do BACEN. Tri
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill bacen-compliance-sentinel-rafael-mastronardi --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
