Skill 詳細
classified-cyber-security-senior-manager
Relevant cybersecurity leadership specialization, but restricted to classified environments.
使用前に確認
自動レビューは関連性のみを確認し、安全性や推奨を保証しません。使用前に出典の説明を読んでください。
SKILL.md
これはレビュー時に保存された抜粋です。完全で最新の内容は外部ソースを確認してください。
--- name: classified-cyber-security-senior-manager description: | Guides senior management of classified and high-side cyber programs—cleared workforce/facility alignment, program security plans, RMF/ATO-style authorization interfaces (manager depth), insider risk coordination, classified ops interfaces, government incident escalation, inspection readiness, personnel security interfaces, classified IT supply chain, and authorizing-official briefings. Use when governing classified cyber, defense industrial base posture, authorization milestones, classified ops governance, government escalation, or inspection prep—not SOC triage (soc-analyst), CSIRT execution (incident-responder), board CISO strategy (chief-information-security-officer), control implementation (information-security-engineer), cloud-only compliance (cloud-compliance-specialist), legal classification decisions, or CISSP prep (certified-information-systems-security-professional). --- # Classified Cyber Security Senior Manager ## When to Use - **Govern** classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners - **Align** cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication) - **Coordinate** program security plans and system security plans at **manager** depth — boundaries, inherited controls, plan of action themes, reauthorization cadence - **Interface** with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to `information-systems-security-officer-classified-specialist`) - **Coordinate** insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes - **Oversee** classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths - **Escalate** incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts - **Prepare** for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings - **Manage** classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down - **Brief** senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks ## When NOT to Use - Triage and close routine SOC alerts → `soc-analyst` - Run CSIRT containment, forensics collection, or technical IR playbooks → `incident-responder` - Board-level enterprise security strategy, risk appetite, and cyber insurance → `chief-information-security-officer` - Deploy controls, SIEM rules, IAM, or remediate findings → `information-security-engineer` - Commercial-only cloud compliance mapping and audit packs → `cloud-compliance-specialist` - Enterprise reference architecture, zero-trust patterns, ARB standards → `enterprise-security-architect` - Build risk registers, FAIR models, or treatment scoring → `security-risk-analyst` - GRC program scope, framework mapping, commercial audit prep → `compliance-specialist` - SSP maintenance, control status, assessor coordination, POA&M ownership → `information-systems-security-officer-classified-specialist` - M&A or investment diligence cyber packs → `cyber-diligence-governance` - Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill - CISSP study or certification exam prep → `certified-information-systems-security-professional` ## Related skills | Need | Skill | |---|---| | Enterprise board strategy, appetite, budget narrative | `chief-information-security-officer` | | Control implementation, tooling, hardening | `information-security-engineer` | | GRC program, frameworks, commercial audit cooGitHub で全文を読む (外部ページ)