security-roadmap-planner

Generate a 12-month security roadmap prioritizing initiatives by risk-reduction-per-dollar.

3|3|Updated Mar 8, 2026
One-click install
npx skills add https://github.com/jaskaranhundal/usap-skills --skill security-roadmap-planner
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-roadmap-planner
Source: https://github.com/jaskaranhundal/usap-skills/tree/main/governance/security-roadmap-planner
Command: npx skills add https://github.com/jaskaranhundal/usap-skills --skill security-roadmap-planner

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill transforms raw security data into a clear, actionable, and investment-prioritized 12-month security program roadmap, ensuring every initiative directly addresses identified risks or compliance gaps.

Core Features & Use Cases

  • Data-Driven Prioritization: Ranks initiatives by risk-reduction-per-dollar, optimizing security investments.
  • Gap-to-Initiative Mapping: Ensures every roadmap item is traceable to a specific posture gap, risk finding, or compliance requirement.
  • Quarterly Planning: Buckets initiatives into Q1-Q4 based on capacity and initiative profile, with overflow managed in a backlog.
  • Use Case: A CISO needs to present a clear plan for the next year. This Skill takes the latest security posture scores, enterprise risk assessments, and compliance findings to generate a prioritized list of security initiatives, complete with estimated investment levels and success metrics, ready for executive review.

Quick Start

Use the security-roadmap-planner skill to generate a prioritized 12-month security roadmap based on available posture, risk, and compliance data.

Frequently Asked Questions about security-roadmap-planner

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I build a security roadmap based on risk and compliance data?

To build a security roadmap, you analyze security posture gaps, quantified enterprise risk, and compliance obligations to generate an investment-prioritized 12-month program schedule. This process ensures every initiative directly addresses identified risks.

What is risk-reduction-per-dollar prioritization in security planning?

Risk-reduction-per-dollar prioritization is a data-driven method that ranks security initiatives by their quantified impact on enterprise risk relative to their estimated investment cost. This approach optimizes security investments by maximizing mitigation value.

How do I map security findings to quarterly initiatives?

You map security findings to quarterly initiatives by bucketing prioritized actions into Q1-Q4 milestones based on organizational capacity and initiative profile. Overflow initiatives are managed in a backlog to maintain a realistic 12-month security roadmap.

Can I use Python scripts to prioritize my enterprise risk management roadmap?

Yes, you can use Python scripts for data processing and prioritization logic to generate your enterprise risk management roadmap. The scripts analyze posture gaps and compliance findings to calculate risk-reduction-per-dollar rankings automatically.

What is the best way to prepare a CISO security roadmap for executive review?

The best way to prepare a CISO security roadmap for executive review is to generate an investment-prioritized plan complete with estimated investment levels and success metrics. This ensures the plan is traceable to specific posture gaps and compliance requirements.