risk-management-specialist

Automate IT risk assessment and treatment planning across ISO 27005 and ISO 31000.

10|1|Updated Nov 5, 2025
One-click install
npx skills add https://github.com/moag1000/Little-ISMS-Helper --skill risk-management-specialist-moag1000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-management-specialist
Source: https://github.com/moag1000/Little-ISMS-Helper/tree/main/.claude/skills/risk-management-specialist
Command: npx skills add https://github.com/moag1000/Little-ISMS-Helper --skill risk-management-specialist-moag1000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Risk Management Specialist helps implement IT risk management using ISO 27005 and ISO 31000, with a Data Reuse approach to reuse assets, incidents, controls, and processes to accelerate risk assessments and governance.

Core Features & Use Cases

  • Risk Identification & Analysis: comprehensive threat and vulnerability assessment.
  • Risk Treatment & Acceptance: develop mitigation plans and formal acceptance workflows.
  • Risk Monitoring: KRIs, ongoing reviews, escalation paths.
  • Data Reuse Optimization: leverage existing risk data to streamline new assessments.
  • ISO Integration: alignment with ISO 27001 Annex A and cross-maps to related standards (27005, 31000, 22301).

Quick Start

Risk, perform an assessment for a new project, create a treatment plan, and link it to relevant controls.

Frequently Asked Questions about risk-management-specialist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform IT risk assessment using ISO 27005 and ISO 31000 frameworks?

ISO 27005 and ISO 31000 risk assessment involves identifying threats and vulnerabilities, analyzing their impact and likelihood, evaluating risk levels against tolerance thresholds, and documenting findings. This Skill automates the full cycle—threat identification, risk scoring (inherent and residual), risk matrix mapping, and treatment planning—while maintaining alignment with ISO 27001 Annex A controls.

Can I reuse existing asset, incident, and control data to speed up new risk assessments?

Yes. Data Reuse optimization leverages existing asset inventories, incident histories, control implementations, and business process documentation to accelerate new assessments. This Skill applies that data across multiple evaluations, reducing manual effort and ensuring consistency in risk identification and scoring.

How do I create and track IT risk treatment plans with ownership and review workflows?

Risk treatment planning defines mitigation strategies, assigns ownership, sets timelines, and establishes review checkpoints. This Skill automates treatment plan creation linked to relevant controls, manages multi-tenant data isolation, and supports escalation paths so teams can monitor progress and compliance status continuously.

What's the difference between inherent and residual risk scoring?

Inherent risk is the baseline threat level before controls are applied; residual risk reflects the remaining threat after mitigation measures are in place. This Skill calculates both scores and maps them to risk matrices, helping teams understand the effectiveness of their control investments.

Can I integrate risk management with existing ISO 27001 compliance processes?

Yes. This Skill aligns risk assessments with ISO 27001 Annex A and cross-references ISO 27005, ISO 31000, and ISO 22301, enabling unified governance. Risk findings and treatment plans feed directly into control selection and compliance workflows.

How do I monitor ongoing risks and set key risk indicators (KRIs)?

Key Risk Indicators (KRIs) track risk trends over time through quantifiable metrics tied to threat and vulnerability sources. This Skill enables KRI definition, ongoing monitoring dashboards, and automated escalation when thresholds are breached, supporting continuous risk oversight.