risk-management

Identify, score, and govern information security risks across asset inventories.

Updated May 22, 2026
One-click install
npx skills add https://github.com/drupadsachania/aegis-skills --skill risk-management-drupadsachania
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-management
Source: https://github.com/drupadsachania/aegis-skills/tree/main/skills/risk-management
Command: npx skills add https://github.com/drupadsachania/aegis-skills --skill risk-management-drupadsachania

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Risk management for information security programs is complex, fragmented, and governance-heavy; this Skill provides a unified end-to-end workflow from asset identification through risk scoring, treatment decisions, governance, and executive reporting.

Core Features & Use Cases

  • Threat-informed asset inventory and asset-threat mapping across enterprise contexts
  • Qualitative and quantitative risk scoring using the FAIR model
  • Phase-based workflow: risk-identification, risk-assessment, risk-treatment, risk-register, risk-reporting
  • Central governance artifacts (endpoints, MCP manifest, and references for guidance)
  • Self-learning updates from listed sources to keep risk content current

Quick Start

Load a phase of the risk-management skill to start governing enterprise risk.

Frequently Asked Questions about risk-management

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I score information security risks using the FAIR model?

Information security risk scoring using the FAIR model applies quantitative analysis to calibrate risk against appetite. This Skill evaluates asset inventories and threat intelligence to generate calibrated risk scores for prioritized treatment decisions.

What is the best way to map enterprise assets to threats for risk identification?

Risk identification for enterprise assets requires mapping threat intelligence against business context. This Skill performs threat-informed asset inventory mapping to identify exposures across the enterprise and feed them into the assessment phase.

How do I build a governed risk register aligned with NIST CSF and ISO 31000?

A governed risk register aligned with NIST CSF and ISO 31000 centralizes identified risks, scores, and treatment decisions. This Skill maintains the register through phase-based workflows and delivers executive reporting for ongoing governance.

Can I use FAIR quantitative analysis alongside qualitative risk assessment methods?

FAIR quantitative analysis and qualitative risk assessment methods are both supported within this Skill. It applies both approaches to calibrate risk against appetite, ensuring comprehensive evaluation across asset inventories and threat contexts.

How do I generate executive reporting for information security risk treatment?

Executive reporting for risk treatment summarizes governed risk register outputs and treatment decisions. This Skill delivers phase-based reporting content via MCP endpoints, mapping results to NIST CSF and ISO 31000 frameworks for stakeholder review.

Do I need a threat modelling process before starting enterprise risk management?

Threat modelling informs the asset-threat mapping phase but is integrated within the workflow. This Skill uses threat intelligence feeds and self-learning updates to map threats against assets, so a separate upfront process is not strictly required.