
Claude Skills by CyberStrikeus
github.com/CyberStrikeusLegal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and manag
Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
Outcomes, capabilities, and services that the organization depends on are understood and communicated
Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and
Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and
Risk management objectives are established and agreed to by organizational stakeholders
Risk appetite and risk tolerance statements are established, communicated, and maintained
Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
Strategic direction that describes appropriate risk response options is established and communicated
Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties
A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated
Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually imp
Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
Cybersecurity is included in human resources practices
A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational st
Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and external
Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes
Suppliers are known and prioritized by criticality
Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements
Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships
The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and
Relevant suppliers and other third parties are included in incident planning, response, and recovery activities
Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored througho
Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreeme
The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
Organizational cybersecurity policy is established, communicated, and enforced
The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established an
Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
Business Environment
Governance
Inventories of hardware managed by the organization are maintained
Inventories of software, services, and systems managed by the organization are maintained
Representations of the organization's authorized network communication and internal and external network data flows are maintained
Inventories of services provided by suppliers are maintained
Assets are prioritized based on classification, criticality, resources, and impact on the mission
Cybersecurity roles and responsibilities for the entire workforce and third-party stakeholders (e.g., suppliers, customers, partners) are established
Inventories of data and corresponding metadata for designated data types are maintained
Systems, hardware, software, services, and data are managed throughout their life cycles
The organization’s role in the supply chain is identified and communicated
The organization’s place in critical infrastructure and its industry sector is identified and communicated
Priorities for organizational mission, objectives, and activities are established and communicated
Dependencies and critical functions for delivery of critical services are established
Resilience requirements to support delivery of critical services are established for all operating states (e.g.