Add comprehensive security skills library with 15 specialized domains - #23
Merged
Merged
Conversation
…5 reference files) Full enterprise security skills organized into 3-tier leadership hierarchy: STRATEGIC LEVEL (1 skill): - ciso: CISO orchestrator — risk posture, program design, board reporting, CISO dashboard VP LEVEL (5 skills): - security-operations: SOC, SIEM, threat detection, IR orchestration, SRE fusion - compliance-governance: SOC 2, NIST CSF, ISO 27001, GDPR, HIPAA, SOX, CCPA, EU AI Act - infrastructure-security: ZTA, cloud security (AWS/Azure/GCP), on-prem, IAM, encryption, DB - application-security: Secure SDLC, SAST/DAST/SCA, OWASP, API security, vuln management - ai-ethics-security: AI agentic framework, hallucination controls, responsible AI, PII in AI TASK LEVEL (10 skills): - threat-hunter: MITRE ATT&CK hunts, IOC sweeps, KQL/SPL queries, adversary emulation - incident-responder: IR playbooks (ransomware, BEC, insider), forensics, breach notification, ITIL change/problem mgmt - sre-operations: SRE+security SLOs, ITIL 4, Six Sigma DMAIC, Global Delivery Framework - compliance-auditor: SOC 2 testing, NIST CSF assessment, ISO 27001, HIPAA, SOX ITGC, GRC - industry-compliance: Banking (FFIEC/FINRA/DORA/PSD2), Healthcare (HITRUST/FDA 21 CFR/GxP), Hi-Tech (CMMC/ITAR) - iam-specialist: RBAC, ABAC (Cedar policies), RBA risk scoring, PAM, JIT, lifecycle automation - network-data-security: Firewall policy, IDS/IPS, DNS security, email (DMARC/DKIM/SPF), SSL/TLS lifecycle, DLP, data classification - penetration-tester: Full OWASP methodology, social engineering, cloud pen test, phishing sim, reporting standards - ai-security-analyst: Prompt injection taxonomy, hallucination assessment, agentic security testing, model supply chain - security-trainer: Role-based curriculum (5 tiers), phishing simulations, tabletop exercises, CISO dashboard design REFERENCE FILES (5 documents): - ciso/references/security-frameworks-map.md: Cross-framework control harmonization + penalty reference - ciso/references/risk-register-template.md: Risk scoring model + sample entries - compliance-governance/references/compliance-calendar-template.md: Full 12-month compliance calendar - infrastructure-security/references/encryption-standards.md: Approved algorithms, TLS config, key management - application-security/references/secure-code-review-checklist.md: 10-section code review checklist Coverage: SOC 2, NIST CSF 2.0, ISO 27001:2022, ISO 42001, HIPAA, SOX, GDPR, CCPA, EU AI Act, PCI-DSS v4, DORA, FFIEC, FINRA, HITRUST, FDA 21 CFR Part 11, CMMC 2.0, ITAR/EAR, NERC CIP, NIST AI RMF, Six Sigma, ITIL 4, Global Delivery Framework, ZTA, MITRE ATT&CK https://claude.ai/code/session_01DCyDb6K6GYb45Z61GmQ6dN
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR introduces a complete security skills library comprising 15 specialized security domains, each with detailed implementation guidance, control frameworks, and operational procedures. The library establishes a structured approach to enterprise security across strategy, operations, compliance, infrastructure, applications, and emerging AI security concerns.
Key Changes
Core Security Skills Added:
Reference Materials Added:
Implementation Details
Skill Architecture:
Coverage Areas:
Operational Standards:
https://claude.ai/code/session_01DCyDb6K6GYb45Z61GmQ6dN