skills/hack23/riksdagsmonitor/information-security-strategy

information-security-strategy

SKILL.md

Information Security Strategy Skill

Purpose

Defines the information security strategy framework for Hack23 projects, integrating risk management with compliance requirements.

Security Strategy Pillars

  1. Governance — Policies, procedures, roles
  2. Risk Management — Identify, assess, treat risks
  3. Compliance — ISO 27001, NIST CSF, CIS Controls
  4. Operations — Monitoring, incident response
  5. Assurance — Audits, testing, continuous improvement

Risk Management Process

  1. Context — Scope, stakeholders, criteria
  2. Assessment — Identify, analyze, evaluate risks
  3. Treatment — Accept, mitigate, transfer, avoid
  4. Monitoring — Continuous risk review
  5. Communication — Stakeholder reporting

Compliance Framework Integration

Framework Focus Key Controls
ISO 27001:2022 ISMS 93 controls in 4 themes
NIST CSF 2.0 Cybersecurity Govern, Identify, Protect, Detect, Respond, Recover
CIS Controls v8.1 Implementation 18 control groups
GDPR Privacy Data protection, rights
NIS2 Critical infra Supply chain, incident reporting

Security Metrics

  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • Vulnerability remediation SLA compliance
  • Security training completion rate
  • Audit finding closure rate

Continuous Improvement

  • Regular policy reviews (annual minimum)
  • Lessons learned from incidents
  • Benchmark against industry standards
  • Security awareness program updates
  • Technology evolution tracking

Related Policies

Weekly Installs
9
GitHub Stars
2
First Seen
12 days ago
Installed on
opencode9
claude-code9
github-copilot9
codex9
amp9
cline9