risk-register

仓库创建 2026年7月27日最近提交 7 小时前SkillHot 收录 1 小时前
▸ 精选理由

自动化一致的风险措辞与可比较评分,节省评审时间

▸ 风险提示

会保存本地风险数据,注意权限与敏感信息管理

这个 Skill 做什么

把杂乱输入整理为符合 NIST 的可跟踪、可评分的风险登记表。

把零散的安全问题、评估或笔记整理成符合 NIST 要求的可跟踪风险登记表:把风险表述成可辩护的事件句式,按 SP 800-30 用 Likelihood×Impact 打分并分级,标记风险胃纳并记录不可删改的变更历史。适合做正式的风险评估、给管理层或审计展示、跟踪残余风险和治理执行情况。亮点是自动化规则化表述和评分、保留时间序列的变更理由,并能输出热力图与高层/运营报告。

▸ 展开 SKILL.md 英文原文

Build, score, maintain, and report a NIST-aligned cybersecurity risk register that persists in a local file and tracks how risk changes over time. Turns messy inputs (a CSF gap export, an assessment, rough notes, or a conversation) into properly-worded risks (NISTIR 8286 event statements), deterministic Likelihood×Impact scoring and banding (SP 800-30), risk-appetite flagging (CSF 2.0 GV.RM), an append-only change log with rationale, named review snapshots, and reporting — heat matrix, themes, trend, and operational and executive/board dashboards. Use whenever the user mentions a risk register, risk log, risk matrix, heat map, risk assessment, residual vs inherent risk, risk treatment or acceptance, over-appetite risks, tracking risk over time, running a risk review, or reporting risk to the board — even if they don't say "NIST." Not for writing security policies, running a maturity assessment itself, or generic project risk logs.

垂直行业风险登记NIST风险评分通用
0
Stars
0
Forks
3
仓库内 Skill
积累中
7 日增星
安装 / 使用
给你的 Agent 一句话(通用)
帮我安装这个 skill:https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/risk-register/SKILL.md
或 curl 直取 SKILL.md
curl -fsSL "https://raw.githubusercontent.com/cyberaware-creations/cac-ciso-toolkit/main/skills/risk-register/SKILL.md"
SKILL.MD 节选查看完整文件 ↗
# Risk Register

Turn identified security risks into a tracked, scored, board-ready register aligned to NIST
guidance — one that lives in a local file, remembers how it changed, and reports to both the team
and the board. This skill does the parts a spreadsheet can't: wording risks so they're defensible,
scoring them identically every time, tracking change with reasons, and translating the result into
language a board acts on.

## What "good" looks like here

A register earns its keep only if these are true, and each is where people usually fail:

1. **Risks are written as events, not topics.** "Phishing" is a topic. "If employees are targeted by
   credential-harvesting phishing, then stole
via SKILL·HOT · 数据来自 GitHub 公开信息 · 原文版权归作者所有