risk-register
自动化一致的风险措辞与可比较评分,节省评审时间
会保存本地风险数据,注意权限与敏感信息管理
把杂乱输入整理为符合 NIST 的可跟踪、可评分的风险登记表。
把零散的安全问题、评估或笔记整理成符合 NIST 要求的可跟踪风险登记表:把风险表述成可辩护的事件句式,按 SP 800-30 用 Likelihood×Impact 打分并分级,标记风险胃纳并记录不可删改的变更历史。适合做正式的风险评估、给管理层或审计展示、跟踪残余风险和治理执行情况。亮点是自动化规则化表述和评分、保留时间序列的变更理由,并能输出热力图与高层/运营报告。
▸ 展开 SKILL.md 英文原文
Build, score, maintain, and report a NIST-aligned cybersecurity risk register that persists in a local file and tracks how risk changes over time. Turns messy inputs (a CSF gap export, an assessment, rough notes, or a conversation) into properly-worded risks (NISTIR 8286 event statements), deterministic Likelihood×Impact scoring and banding (SP 800-30), risk-appetite flagging (CSF 2.0 GV.RM), an append-only change log with rationale, named review snapshots, and reporting — heat matrix, themes, trend, and operational and executive/board dashboards. Use whenever the user mentions a risk register, risk log, risk matrix, heat map, risk assessment, residual vs inherent risk, risk treatment or acceptance, over-appetite risks, tracking risk over time, running a risk review, or reporting risk to the board — even if they don't say "NIST." Not for writing security policies, running a maturity assessment itself, or generic project risk logs.
帮我安装这个 skill:https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/risk-register/SKILL.mdcurl -fsSL "https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/risk-register/SKILL.md"# Risk Register Turn identified security risks into a tracked, scored, board-ready register aligned to NIST guidance — one that lives in a local file, remembers how it changed, and reports to both the team and the board. This skill does the parts a spreadsheet can't: wording risks so they're defensible, scoring them identically every time, tracking change with reasons, and translating the result into language a board acts on. ## What "good" looks like here A register earns its keep only if these are true, and each is where people usually fail: 1. **Risks are written as events, not topics.** "Phishing" is a topic. "If employees are targeted by credential-harvesting phishing, then stole