Skip to main content
在 Manus 中运行任何 Skill
一键导入

risk-register-csf

星标0
分支0
更新时间2026年6月23日 12:19

Builds and maintains a solo operator's security risk program as three durable, machine-checkable artifacts: a living risk register (likelihood x impact, owner, treatment, review date), a NIST CSF 2.0 self-assessment scorecard (Govern/Identify/Protect/Detect/Respond/Recover at maturity tiers), and a lightweight NIST-endorsed incident-response plan (severity tiers, escalation tree, per-scenario runbooks, notification clock). Scans the repo, IaC, and dependency manifests to seed an asset inventory, scores risks deterministically, and on re-run diffs prior artifacts to surface drift and FORCE re-acceptance of overdue risks. Use whenever the user touches their own security, risk, or compliance posture even if they don't explicitly ask: when they mention a risk register, threat or exposure, "are we SOC2-ish / secure enough", a data breach or leaked secret, an incident or 2am outage plan, NIST CSF / ISO 27001, audit prep, or "what could go wrong with this system". Also use on any periodic security review or when a p

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly