What problem does it solve?
Security and compliance risks in plans that touch customer data, production access, or regulated systems are often discovered too late. This Skill forces a structured risk interrogation before shipping, so threat models, blast radius, detection, and regulatory obligations are addressed upfront.
Core Features & Use Cases
- Six CISO Forcing Questions: Covers STRIDE threat modeling, blast radius quantification via FAIR-based ALE, detection/MTTD, incident response readiness, regulatory notification windows (GDPR 72h, HIPAA 60d), and vendor/supply-chain posture.
- Structured Verdict Output: Produces a markdown review report ending in a SHIP, MITIGATE THEN SHIP, or BLOCK verdict.
- Use Case: Before deploying a feature that stores customer PII, run the review to identify the top STRIDE threat, confirm an IR runbook exists, verify DPA coverage for new vendors, and document risk acceptance.
Quick Start
Ask the AI to run /cs:ciso-review on your launch plan for a feature that handles customer data before your SOC 2 audit.