ciso-assistant-basic-risk-assessment

Set up a basic risk assessment workflow in CISO Assistant.

4.3k|810|Updated Sep 20, 2023
One-click install
npx skills add https://github.com/intuitem/ciso-assistant-community --skill ciso-assistant-basic-risk-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ciso-assistant-basic-risk-assessment
Source: https://github.com/intuitem/ciso-assistant-community/tree/main/.claude/skills/ciso-assistant-basic-risk-assessment
Command: npx skills add https://github.com/intuitem/ciso-assistant-community --skill ciso-assistant-basic-risk-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps security teams set up and run a basic risk assessment workflow in CISO Assistant, from asset discovery to risk scenario creation.

Core Features & Use Cases

  • Asset identification and scoping: gather organizational context and label primary and supporting assets.
  • Threat catalog integration and scenario generation: import and query the threat library and generate threat-asset pairings to inform risk scenarios.
  • Risk study creation: create qualitative risk assessments with matrices or quantitative risk studies, and attach associated scenarios.

Quick Start

Identify your organizational context, select assets and threats, ensure MCP connectivity, then create a risk assessment and related scenarios using the common risk catalog.

Frequently Asked Questions about ciso-assistant-basic-risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I set up a basic risk assessment workflow in CISO Assistant?

To set up a basic risk assessment workflow in CISO Assistant, identify your organizational context, label primary and supporting assets, query the threat library, and generate threat-asset pairings to create risk scenarios.

Can I generate risk scenarios from a threat catalog in CISO Assistant?

Yes, you can generate risk scenarios by importing and querying the intuitem-common threat library catalog, pairing identified threats with your organizational assets to inform your qualitative or quantitative risk studies.

What is needed to create a qualitative risk assessment with a risk matrix?

Creating a qualitative risk assessment with a risk matrix requires MCP server connectivity, backend access, and folder_id scoping to utilize the threat_library for generating and attaching scenarios to your risk study.

Does CISO Assistant support quantitative risk study creation?

Yes, CISO Assistant supports both qualitative risk assessments using matrices and quantitative risk studies, allowing you to attach associated scenarios generated from your asset and threat catalogs.

How do I identify and scope organizational assets for risk assessment?

You identify and scope organizational assets by gathering your organizational context within CISO Assistant, then labeling primary assets and supporting assets to prepare for threat catalog integration and scenario generation.

What are the limitations of basic risk assessment in CISO Assistant?

Basic risk assessment in CISO Assistant requires MCP server connectivity and backend access to function, and relies on folder_id scoping within the intuitem-common catalog to properly access the threat library.