risk-assessment

Automate ISO 27005 / NIST SP 800-30 risk assessments with a structured risk register.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill risk-assessment-jassics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-assessment
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/grc/skills/risk-assessment
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill risk-assessment-jassics

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill streamlines the process of conducting security risk assessments, helping you identify, analyze, evaluate, and treat risks in a structured and maintainable manner.

Core Features & Use Cases

  • Structured Risk Assessment: Perform assessments according to ISO 27005 / NIST SP 800-30 standards.
  • Risk Register Management: Maintain a detailed risk register for tracking risks and treatment decisions.
  • Use Case: Ideal for enterprise or security risk assessments, where you need to analyze risks against established criteria and determine the most effective risk treatment strategies.

Quick Start

Run a risk assessment with the risk-assessment skill by executing '/risk-assessment:start' and follow the prompts to define your context, identify risks, and assign treatment decisions.

Frequently Asked Questions about risk-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a security risk assessment following ISO 27005 or NIST SP 800-30?

Security risk assessment following ISO 27005 or NIST SP 800-30 is streamlined by guiding you through risk identification, analysis, evaluation, and treatment within a structured register. You define your context, identify risks, and assign treatment decisions.

What is the best way to maintain a risk register for IT risk management?

Maintaining a risk register for IT risk management is handled by tracking identified risks and their treatment decisions in a structured format. This approach ensures risks are analyzed against established criteria and evaluated systematically.

Can I automate risk treatment decisions for enterprise security assessments?

Risk treatment decisions for enterprise security assessments require your input to determine the most effective strategies, but the assessment process itself is automated. You need to define risk criteria before the tool can evaluate and support treatment decision-making.

Do I need to define risk criteria before starting a security risk assessment?

Defining risk criteria is required before starting a security risk assessment. The process depends on established criteria to properly analyze, evaluate, and determine the most effective risk treatment strategies for your enterprise environment.

How does a structured risk register support risk evaluation and treatment?

A structured risk register supports evaluation and treatment by organizing identified risks for systematic analysis against your defined criteria. This maintainable format helps security professionals track risks and document treatment decisions accurately.

Related Skills