All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
GV.OC 03 Gvoc 03A

Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag

securitygosecurity
0
291
GV.OC 04 Gvoc 04A

Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

securitygosecurity
0
291
GV.OC 05 Gvoc 05A

Outcomes, capabilities, and services that the organization depends on are understood and communicated

securitygosecurity
0
291
GV.OV 01 Gvov 01A

Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

securitygosecurity
0
291
GV.OV 02 Gvov 02A

The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

securitygosecurity
0
291
GV.OV 03 Gvov 03A

Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

securitygosecurity
0
291
GV.PO 01 Gvpo 01A

Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and

securitygosecurity
0
291
GV.PO 02 Gvpo 02A

Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and

securitygosecurity
0
291
GV.RM 01 Gvrm 01A

Risk management objectives are established and agreed to by organizational stakeholders

securitygosecurity
0
291
GV.RM 02 Gvrm 02A

Risk appetite and risk tolerance statements are established, communicated, and maintained

securitygosecurity
0
291
GV.RM 03 Gvrm 03A

Cybersecurity risk management activities and outcomes are included in enterprise risk management processes

securitygosecurity
0
291
GV.RM 04 Gvrm 04A

Strategic direction that describes appropriate risk response options is established and communicated

securitygosecurity
0
291
GV.RM 05 Gvrm 05A

Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

securitygosecurity
0
291
GV.RM 06 Gvrm 06A

A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated

securitygosecurity
0
291
GV.RM 07 Gvrm 07A

Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

securitygosecurity
0
291
GV.RR 01 Gvrr 01A

Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp

securitygosecurity
0
291
GV.RR 02 Gvrr 02A

Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced

securitygosecurity
0
291
GV.RR 03 Gvrr 03A

Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

securitygosecurity
0
291
GV.RR 04 Gvrr 04A

Cybersecurity is included in human resources practices

securitygosecurity
0
291
GV.SC 01 Gvsc 01A

A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st

securitygosecurity
0
291
GV.SC 02 Gvsc 02A

Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external

securitygosecurity
0
291
GV.SC 03 Gvsc 03A

Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

securitygosecurity
0
291
GV.SC 04 Gvsc 04A

Suppliers are known and prioritized by criticality

securitygosecurity
0
291
GV.SC 05 Gvsc 05A

Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements

securitygosecurity
0
291
GV.SC 06 Gvsc 06A

Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships

securitygosecurity
0
291
GV.SC 07 Gvsc 07A

The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and

securitygosecurity
0
291
GV.SC 08 Gvsc 08A

Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

securitygosecurity
0
291
GV.SC 09 Gvsc 09A

Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho

securitygosecurity
0
291
GV.SC 10 Gvsc 10A

Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme

securitygosecurity
0
291
Organizational Context (GV.OC) Organizational ContextA

The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio

securitygosecurity
0
291
Oversight (GV.OV) OversightA

Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra

securitygosecurity
0
291
Policy (GV.PO) PolicyA

Organizational cybersecurity policy is established, communicated, and enforced

securitygosecurity
0
291
Risk Management Strategy (GV.RM) Risk Management StrategyA

The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support

securitygosecurity
0
291
Roles, Responsibilities, And Authorities (GV.RR) Roles Responsibilities And AuthoritiesA

Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established an

securitygosecurity
0
291
Asset Management (ID.AM) Asset ManagementA

Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie

securitygoaws
0
291
Business Environment (ID.BE) Business EnvironmentA

Business Environment

securitygoaws
0
291
Governance (ID.GV) GovernanceA

Governance

securitygoaws
0
291
ID.AM 01 Idam 01A

Inventories of hardware managed by the organization are maintained

securitygoaws
0
291
ID.AM 02 Idam 02A

Inventories of software, services, and systems managed by the organization are maintained

securitygoaws
0
291
ID.AM 03 Idam 03A

Representations of the organization's authorized network communication and internal and external network data flows are maintained

securitygoaws
0
291
ID.AM 04 Idam 04A

Inventories of services provided by suppliers are maintained

securitygoaws
0
291
ID.AM 05 Idam 05A

Assets are prioritized based on classification, criticality, resources, and impact on the mission

securitygoaws
0
291
ID.AM 06 Idam 06A

Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established

securitygoaws
0
291
ID.AM 07 Idam 07A

Inventories of data and corresponding metadata for designated data types are maintained

securitygoaws
0
291
ID.AM 08 Idam 08A

Systems, hardware, software, services, and data are managed throughout their life cycles

securitygoaws
0
291
ID.BE 01 Idbe 01A

The organization’s role in the supply chain is identified and communicated

securitygoaws
0
291
ID.BE 02 Idbe 02A

The organization’s place in critical infrastructure and its industry sector is identified and communicated

securitygoaws
0
291
ID.BE 03 Idbe 03A

Priorities for organizational mission, objectives, and activities are established and communicated

securitygoaws
0
291
ID.BE 04 Idbe 04A

Dependencies and critical functions for delivery of critical services are established

securitygoaws
0
291
ID.BE 05 Idbe 05A

Resilience requirements to support delivery of critical services are established for all operating states (e.g.

securitygoaws
0
291