governance

Orchestrate security governance program design across policy, maturity, metrics, and third-party risk.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill governance-drupadsachania
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: governance
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/governance
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill governance-drupadsachania

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Governance program design and management for policy, maturity, metrics, and third-party risk.

Core Features & Use Cases

  • Policy framework design and hierarchy aligned to ISO 27001 and NIST CSF
  • Maturity assessment and roadmap planning (CSF tiers, CMMC)
  • KPI/KRI design, board reporting, and third-party governance (TPRM)
  • Phase-guided content loading and cross-platform workflow support

Quick Start

Load the policy-framework phase to begin establishing your governance framework.

Frequently Asked Questions about governance

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a security governance policy framework aligned to ISO 27001 and NIST CSF?

Security governance policy framework design involves establishing a policy hierarchy aligned to ISO 27001 and NIST CSF. You can load the policy-framework phase to begin structuring your enterprise, hybrid, or cloud security programs deterministically.

What metrics should I include in board reporting for security governance?

Board reporting for security governance requires specific KPI and KRI metrics to communicate program effectiveness. Designing these metrics involves selecting indicators that accurately reflect your enterprise, hybrid, and cloud risk posture.

How do I manage third-party risk management activities for enterprise security programs?

Third-party risk management (TPRM) for security governance involves assessing and monitoring vendor risks across enterprise environments. The governance workflow guides TPRM activities alongside policy framework development and maturity assessments.

Can I use this governance workflow for hybrid and cloud security environments?

Yes, security governance program design applies to enterprise, hybrid, and cloud environments. The phase-based workflow supports cross-platform deployment, allowing you to manage policy frameworks and metrics across diverse infrastructure.

What is the best way to start building a security governance program from scratch?

The best way to start building a security governance program is to load the policy-framework phase to establish your foundational framework. This initiates a phase-based workflow covering maturity, metrics, and third-party risk management.