From ciso-toolkit
Build or assess a security program strategy and roadmap — current-vs-target maturity, gaps, prioritized initiatives aligned to business objectives and risk appetite, with outcomes, metrics, and budget framing. Use for security program planning, a strategy refresh, or a maturity assessment.
How this skill is triggered — by the user, by Claude, or both
Slash command
/ciso-toolkit:security-strategyThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A defensible security strategy: where the program is, where it needs to be (driven by
A defensible security strategy: where the program is, where it needs to be (driven by business risk, not fashion), and the prioritized, resourced roadmap to get there.
threat-modeling, threat intel) — not "max everything."cyber-risk-quantification).A strategy document: business context · current vs. target maturity · gaps (with
risk) · prioritized initiative roadmap (phased, with outcomes/metrics/budget). Use
security-reporting; visualize the maturity and roadmap with security-diagramming.
Feed the headline into board-deck.
Anchor everything to business risk and appetite — a strategy that maximizes controls regardless of risk burns budget and credibility. Prioritize by risk-reduction-per- dollar, and make the roadmap outcome- and metric-driven so progress is measurable.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin ciso-toolkit