Guide users through a basic risk assessment workflow in CISO Assistant, from asset identification to scenario creation. Use when: (1) User wants to start a risk assessment from scratch (2) User mentions "risk assessment", "identify risks", "threat scenarios", or "risk register" (3) User asks about qualitative vs…
Build a reviewed crosswalk (RequirementMappingSet YAML library + review xlsx/csv) between two CISO Assistant framework YAML files using Claude itself as the reasoning engine. Zero infrastructure — stdlib + pyyaml only, no embedders, no LM Studio, no Qdrant. Use when the user asks to map / crosswalk / generate a…
Enrich a CISO Assistant framework YAML by linking each assessable requirement to reference control URNs from the central doc-pol library (CISO Assistant Key Reference Controls). Produces a reviewable xlsx and patches the framework YAML in place. Use when the user asks to "add reference controls to framework X", "link…
Enforce AI SAFE² v3.0 sovereign governance constraints for every session. Apply this skill automatically at session start and before any tool execution that involves file writes, network access, shell commands, or subagent spawning. Covers identity lock, hard security limits, context isolation, tool authorization…
Apply AI SAFE2 v3.1 to design, build, audit, test, and govern AI agents, multi-agent systems, RAG, MCP/tool integrations, and AI infrastructure. Use the 161-control core taxonomy plus applicable profile overlays such as CP.5.MCP MCP-1 through MCP-19. Classify autonomy with ACT tiers, enforce HEAR and replication…
Apply AI SAFE2 v3.0 to security architecture reviews, code reviews, compliance mapping, and governance decisions for AI agents, multi-agent systems, RAG pipelines, MCP servers, tool-calling workflows, and AI-enabled automations. Use when the task involves agent autonomy classification, HEAR or CP.9 governance, prompt…
Builds learning-safe mini-labs around toy or sanitized artefacts. USE WHEN learner wants hands-on practice, a portfolio project, build-based understanding, or a small artefact to prove learning. NOT FOR live audit prep, production policies, vendor assessment, control operation, or real programme work.
Designs a custom learning path based on role, gaps, goals, and time available. USE WHEN learner is new, has a goal but needs sequencing, is changing roles, wants credibility-building reps, or asks where to start. NOT FOR curating sources only; use reading-guide.
Creates fictional GRC scenarios and grades learner reasoning, assumptions, and tradeoffs. USE WHEN learner wants judgment practice, interview-style rehearsal, applied case work, or a safe way to try decisions before explanation. NOT FOR analyzing a real vendor, audit, control, policy, or programme.
Maps NIST controls to FedRAMP requirements and documents. Use when helping with control implementation, compliance mapping, security baseline alignment, or understanding control requirements.
Analyzes FedRAMP FRMR documents to extract control mappings, KSI entries, and version changes. Use when the user asks about FedRAMP requirements, control mappings, compliance data, or needs to understand FRMR document content.
Use this skill for end-to-end compliance pipelines with Compliance Trestle. Topics include GRC personas, artifact ownership, multi-repository coordination, two-phase component definition authoring, CI/CD pipeline integration, and the Compliance-to-Policy (C2P) bridge. Use it for compliance pipelines, personas…
Use this skill to write control implementation responses, rules, parameters, and component-level responses. Use it for inheritance and leveraged SSPs in Compliance Trestle. Use it for control responses, implementation status, rules, parameters, component definitions, SSP implementation details, or compliance…
Use this skill for the Compliance Trestle task system for data conversion and transformation. Use it for CSV import, XLSX import, XCCDF results, Tanium results, and CIS benchmarks. Use it for config.ini task configuration, trestle tasks, or conversion of scan results to assessment results.
Cryptographic compliance verification. Sign security tool output into verifiable CPOEs (JWT-VC), verify vendor proofs via trust.txt, detect drift with diff, and assess third-party risk. Use when the user mentions compliance proofs, CPOE, trust.txt, SCITT, vendor assessment, GRC evidence, or compliance drift.
Expert Canadian GRC and cyber law advisor covering OSFI B-10/B-13/E-21/I-CRT, FSRA, AMF/Loi 25, BCFSA, CIRO, AER Reg 84/CSA Z246.1, PIPEDA, PHIPA, PIPA BC, PIPA AB, Bill C-26, and AIDA. Use this skill whenever the user mentions any Canadian financial regulator, provincial privacy law, Alberta energy security, Canadian…
Use when the user asks about ISO/IEC 27001:2022 from an engineering perspective — building an ISMS that runs on systems and code rather than spreadsheets, instrumenting Annex A controls, designing risk registers as data, and producing evidence pipelines that hold up to a certification audit. Engineer-voice, not…
Use when the user asks about NIST SP 800-53 Rev. 5 from an engineering perspective — selecting baselines, tailoring controls, modeling control inheritance from cloud providers and shared services, emitting OSCAL artifacts, or implementing controls in IaC and code rather than running them as a documentation exercise.…
Use when the user asks about SOC 2 from an engineering perspective — Trust Services Criteria (TSC) implementation, evidence-as-code, continuous monitoring patterns, instrumenting controls, or designing systems that produce audit-ready evidence by default. Engineer-voice, not auditor-voice.
Run the compliance copilot loop — observe posture, identify gaps, dry-run proposed evidence records where possible, present for human approval, then write approved records. Use when the user asks to close compliance gaps, improve their EU AI Act score, or fix failing governance gates.
Run the quarterly evidence collection workflow — find the stalest controls by record type, collect completion details for each, dry-run to confirm controls earned, then write approved records. Use at the end of each quarter when a GRC manager has completed governance activities (risk assessments, model evaluations…
Run the Art. 9 intake workflow — find every AI system without an airiskassessment record, gather the required fields, and register each one. Use when the user asks to register systems, fix Art. 9 gaps, or prepare for the EU AI Act deadline.
Compliance audits on the CISO Assistant platform via the ciso-assistant-api MCP server — list and read compliance assessments (audits), their frameworks, progress, computed outcome and applied controls, surface requirement gaps, and natively ingest audits into the knowledge graph as typed :Audit nodes linked to their…