What problem does it solve? Security decisions are often made without grounding in first principles, leading to misconfigured controls, framework confusion, and repeated architectural mistakes. This Skill provides a structured mental model of cybersecurity fundamentals so you can explain why controls exist, evaluate trade-offs, and map principles to modern threats. ## Core Features & Use Cases - Foundational Principles: Covers the Saltzer-Schroeder eight design principles, CIA triad, AAA model, Zero Trust architecture, and defense in depth with real breach case studies (Target, SolarWinds, OPM). - Framework Guidance: Details NIST CSF 2.0, CIS Controls v8.1, ISO 27001:2022, NIST SP 800-63-4, and incident response per NIST SP 800-61 Rev 3, including which framework fits which audience. - Modern IAM & AI-Era Security: Explains phishing-resistant MFA (FIDO2/passkeys), PAM with zero standing privileges, SASE platforms, and maps classic principles to agentic AI risks like prompt injection and non-human identity sprawl. - Use Case: When an engineer asks "why do we need phishing-resistant MFA instead of SMS codes," the Skill explains origin binding, prompt bombing statistics from the Verizon DBIR, and NIST AAL3 requirements. ## Quick Start Ask the assistant to explain why a specific security control exists or which framework to use for a given scenario, such as "why is least privilege important for service accounts."