security-posture-score

Aggregate security findings across domains into a 0-100 executive scorecard.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill security-posture-score
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-posture-score
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/governance/security-posture-score
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill security-posture-score

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a consolidated, executive-level view of an organization's security posture by aggregating findings and metrics across various domains into a single, easy-to-understand scorecard.

Core Features & Use Cases

  • Cross-Domain Scoring: Aggregates data from Detection, Response, Cloud, AppSec, Identity, Governance, and Red Team domains.
  • Executive Reporting: Generates a 0-100 scorecard with clear ratings and domain breakdowns, suitable for board-level briefings.
  • Trend Analysis: Tracks security posture improvements over time.
  • Use Case: A CISO can use this skill before a board meeting to quickly understand the overall security health, identify weak areas (like Detection), and justify investment in specific security initiatives.

Quick Start

Run the security posture score tool to generate a JSON output of the current security posture.

Frequently Asked Questions about security-posture-score

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate an executive security scorecard for board reporting?

To generate an executive security scorecard, aggregate security findings, metrics, and control coverage across multiple domains into a unified 0-100 composite score. This requires weighted criteria and maturity multipliers for domain-level scoring and board-ready reporting.

Can I track security posture improvements over time for trend analysis?

Yes, security posture trend analysis tracks improvements over time by comparing aggregated metrics and control coverage across domains. This generates historical scorecard data, enabling security leadership to monitor posture changes and peer benchmarking progress.

What cybersecurity metrics are needed to calculate a security posture score?

Calculating a security posture score requires cybersecurity metrics and findings from domains like Detection, Response, Cloud, AppSec, Identity, Governance, and Red Team. You also need weighted criteria and maturity multipliers for domain-level scoring and composite calculation.

Does security posture scoring support cross-domain governance and risk management?

Yes, security posture scoring supports cross-domain governance and risk management by aggregating findings across Detection, Response, Cloud, AppSec, Identity, and Red Team domains. This creates a unified executive scorecard for comprehensive risk visibility.

What's the best way to benchmark security posture against peer organizations?

The best way to benchmark security posture is using a unified 0-100 scorecard that aggregates cross-domain security metrics. This facilitates peer benchmarking and trend analysis by applying weighted criteria and maturity multipliers for executive reporting.

How do I prepare security metrics for a CISO board meeting?

Prepare for a CISO board meeting by aggregating security findings and control coverage across domains into a 0-100 executive scorecard. This highlights weak areas and justifies investment in specific security initiatives using clear domain breakdowns.