byadriannoes· 58 skills
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis, threat sources, vulnerabilities, risk determination, qualitative risk, risk matrix, residual risk, risk treatment.
$npx -y skills add adriannoes/awesome-agentic-ai --skill conducting-cyber-risk-assessment-with-nist-800-30Installs into the current project.
Run `npx skills use "https://github.com/adriannoes/awesome-agentic-ai" --skill "adriannoes/awesome-agentic-ai/conducting-cyber-risk-assessment-with-nist-800-30"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/adriannoes/awesome-agentic-ai" that are relevant to the current task. Run `npx skills add "https://github.com/adriannoes/awesome-agentic-ai"` and select the relevant skills, then follow their instructions.