nist-csf
把框架转成可审计、可追踪的现实评分系统
将 NIST CSF 2.0 转为可持久化的组织侧记录并跟踪姿态变化。
把 NIST CSF 2.0 变成可落地的组织档案:为 106 个 Subcategory 用 0–3 打分、做差距分析、按风险加权排序,并保留可审计的历史和变更快照。做安全自评、季度汇报或跟踪安全姿态时用,能同时产出运营面和高层看板。特色是把框架转为本地可持久记录、明确优先级和行动清单,方便长期跟踪改进。
▸ 展开 SKILL.md 英文原文
Assess, track, and report a cybersecurity programme against the NIST Cybersecurity Framework 2.0 as an Organizational Profile that persists in a local file and shows how posture changes over time. Rates each of the 106 Subcategories Current vs Target on a 0-3 achievement scale, computes deterministic gap analysis and risk-weighted prioritization, rolls coverage up by Function and Category, characterizes CSF Tiers, keeps an append-only history with rationale, takes named review snapshots with a what-changed diff, and tracks an owned action plan — reported as operational and executive dashboards. Bundles the full CSF 2.0 Core with all 363 Implementation Examples. Use whenever the user mentions NIST CSF, CSF 2.0, a Current or Target Profile, an Organizational Profile, framework coverage or gaps, a cybersecurity framework assessment, security programme maturity or posture, CSF Tiers, where the programme stands against a standard, or reporting framework progress to a board — even if they do
帮我安装这个 skill:https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/nist-csf/SKILL.mdcurl -fsSL "https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/nist-csf/SKILL.md"# NIST CSF Organizational Profile Turn the NIST Cybersecurity Framework 2.0 into a working system of record: where the programme stands, where it should be, what the gap is worth, and what changed since last quarter. It lives in a local file, remembers why every rating moved, and reports to both the team and the board. `risk-register` answers *"what are our top risks and are they within appetite?"* This skill answers *"how complete is our programme against a recognised standard, and what's the plan to close the gap?"* They share the CSF Subcategory ID space, so a gap here becomes a scored risk there. ## What "good" looks like here Each of these is where CSF work usually goes wrong: 1. *