security-risk-analyst

Build scenario-based risk registers and score inherent and residual risk.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill security-risk-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-risk-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/security-risk-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill security-risk-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Risk analysis guidance and decision support for information security, enabling risk identification, scoring, TVC mapping, risk registers, treatment decisions, third-party risk framing, KRIs, and executive risk narratives.

Core Features & Use Cases

  • Structured risk identification and scoring (inherent and residual) aligned to ISO 27005/NIST RMF
  • Threat–vulnerability–control mapping with gap analysis and evidence tracking
  • Risk treatment planning, acceptance, and KPI-driven governance reporting for boards and risk committees
  • Third-party and supply-chain risk assessment with tiering and questionnaire scope
  • Deliverables like risk registers, heat maps, KRIs, and executive briefing materials

Quick Start

Provide a concise risk assessment memo capturing top scenarios and residual risk for board-ready reporting.

Frequently Asked Questions about security-risk-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a security risk register aligned to ISO 27005 or NIST RMF?

Inherent risk scoring evaluates threat and vulnerability exposure before controls are applied, while residual risk scoring measures remaining exposure after controls. TVC mapping links these threats, vulnerabilities, and controls to justify the risk treatment decisions.

How do I generate executive risk narratives and KRIs for board reporting?

You generate executive risk narratives and KRIs by summarizing scenario-based risk registers, residual scores, and treatment statuses. This translates technical TVC mapping and gap analysis into board-ready governance reporting and committee briefing materials.

Can I use this for third-party risk assessment and tiering?

Yes, you can use this for third-party risk assessment. It supports supply-chain risk evaluation by framing questionnaire scopes and tiering vendors, which integrates external threats into your inherent and residual risk scoring workflows.

What is the best way to map threats, vulnerabilities, and controls with gap analysis?

The best way to map threats, vulnerabilities, and controls is through structured TVC mapping. This identifies control gaps, tracks evidence, and calculates residual risk scores to inform risk treatment planning and acceptance decisions.