一键导入
security-documentation
Master security documentation with security policies, incident response plans, security procedures, and compliance documentation.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Master security documentation with security policies, incident response plans, security procedures, and compliance documentation.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | security-documentation |
| description | Master security documentation with security policies, incident response plans, security procedures, and compliance documentation. |
Create comprehensive security documentation including policies, procedures, incident response plans, and compliance documentation.
# Information Security Policy
## Purpose
Define security requirements and responsibilities for protecting company information assets.
## Scope
All employees, contractors, systems, and data.
## Password Policy
- Minimum 12 characters
- Complexity requirements (upper, lower, number, special)
- No password reuse (last 10)
- 90-day expiration
- MFA required for sensitive systems
## Access Control
- Principle of least privilege
- Role-based access control
- Access review quarterly
- Termination procedures
- Remote access via VPN only
## Data Classification
- Public: No restrictions
- Internal: Company personnel only
- Confidential: Need-to-know basis
- Restricted: Executive approval required
## Incident Reporting
- Report security incidents within 1 hour
- Contact: security@company.com
- Incident response team activation
## Compliance
- Violation consequences
- Review annually
- Approval: CISO
**Effective Date**: 2024-01-01
**Version**: 1.0
# Incident Response Plan
## Incident Types
- Data breach
- Malware infection
- Unauthorized access
- Denial of service
- Physical security breach
## Response Team
- Incident Commander: CISO
- Technical Lead: IT Director
- Communications: PR Manager
- Legal: General Counsel
- HR: HR Director
## Response Phases
### 1. Detection & Analysis (0-1 hour)
- Identify incident type
- Assess severity
- Activate response team
- Begin logging
### 2. Containment (1-4 hours)
- Isolate affected systems
- Preserve evidence
- Implement temporary controls
- Prevent spread
### 3. Eradication (4-24 hours)
- Remove threat
- Patch vulnerabilities
- Reset credentials
- Verify clean
### 4. Recovery (24-72 hours)
- Restore systems
- Monitor for reoccurrence
- Validate functionality
- Return to normal
### 5. Post-Incident (Week 1)
- Document timeline
- Lessons learned
- Update procedures
- Report to stakeholders
## Communication Protocol
- Internal: Email, Slack
- External: PR team approval
- Customers: Within 72 hours (GDPR)
- Regulators: As required
Master business documentation including BRD, FRD, specifications, and technical documentation for clear communication and requirements management.
Master process modeling with BPMN, flowcharts, swimlane diagrams, and process optimization techniques for business process improvement.
Master requirements gathering techniques including interviews, workshops, observation, and documentation for effective requirement elicitation.
Master use case development with actors, scenarios, preconditions, postconditions, and detailed specifications for comprehensive requirements.
Master data visualization with chart selection, dashboard design, Tableau, Power BI, and effective data storytelling.
Master Excel for data analysis with pivot tables, formulas, Power Query, and advanced Excel techniques.