security-requirements-classification

Classify data sensitivity to generate security requirements and control mappings.

1|Updated Nov 29, 2025
One-click install
npx skills add https://github.com/SSiertsema/claude-code-plugins --skill security-requirements-classification
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-requirements-classification
Source: https://github.com/SSiertsema/claude-code-plugins/tree/main/security-requirements-classification/skills/security-requirements-classification
Command: npx skills add https://github.com/SSiertsema/claude-code-plugins --skill security-requirements-classification

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Classify data and functionality by sensitivity to derive concrete security requirements, producing data-classification tiers, per-tier controls (authn / authz / encryption / logging / retention / access review), CIA triad impact, abuse cases, and mappings to control-framework-mapping and data-flow diagramming.

Core Features & Use Cases

  • Generates data sensitivity tiers and corresponding required controls for authentication, authorization, encryption, logging, retention, and access reviews.
  • Produces abuse-case sets per subject and links requirements to relevant control-framework mappings for audit readiness.
  • Outputs structured security requirements that teams can implement in product design, development, and compliance processes.

Quick Start

Provide the Subject and Data assets to generate the complete security requirements specification.

Frequently Asked Questions about security-requirements-classification

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I derive security controls from data sensitivity for a new product feature?

Deriving security controls from data sensitivity requires classifying data assets into tiers and generating corresponding authentication, authorization, encryption, logging, retention, and access review requirements for design and development workflows.

What is CIA triad impact assessment and how does it map to compliance frameworks?

CIA triad impact assessment evaluates confidentiality, integrity, and availability risks for data assets, mapping derived security requirements to control frameworks to ensure audit readiness and structured compliance governance.

How do I generate abuse cases and data classification tiers for compliance workflows?

Generating abuse cases and data classification tiers involves analyzing data sensitivity by subject to produce structured security requirements, linking per-tier controls to data-flow diagramming for compliance tracking.

Can I use data classification and risk assessment for service contexts without prior security framework setup?

Yes, data classification and risk assessment applies to product, feature, or service contexts by processing provided subject and data assets to output complete security specifications without requiring prior framework setup.

What's the best way to map security requirements to control frameworks for audit readiness?

Mapping security requirements to control frameworks involves generating data sensitivity tiers and per-tier controls, then linking those requirements directly to relevant framework mappings for audit readiness.

Why does my risk assessment need abuse case generation and data flow diagramming together?

Risk assessment needs abuse case generation and data flow diagramming together to satisfy end-to-end security governance workflows, ensuring concrete security requirements cover classification, CIA scoring, and control mapping.