本文へ移動
cccskills

「risk」の検索結果

2,244 件 ・ 関連度順

概要と使いどころ

Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis, threat sources, vulnerabilities, risk determination, qualitative risk, risk matrix, residual risk, risk treatment.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Anthropic-Cybersecurity-Skills3.4万2026年8月31日 更新

Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likelihood and impact, compute risk, and communicate results as a prioritized risk register. Use when an organization needs an actual risk *assessment* (not a maturity score), when a control framework (CSF, ISO 27001, RMF, SOC 2, PCI) requires a documented risk analysis as input, when leadership asks "what are our top risks and how bad are they", when assessing risk for a new system or major change, or when building a risk register from scratch. This is the methodology that feeds framework selection, ATO packages, and treatment decisions. Keywords: risk assessment, NIST 800-30, threat modeling, likelihood and impact, risk register, risk analysis, threat sources, vulnerabilities, risk determination, qualitative risk, risk matrix, residual risk, risk treatment.

日本語の概要は準備中です。原文の説明を表示しています。

andycungkrinx91/konoha92026年10月9日 更新

Guides privacy audit risk assessment including risk universe development, inherent and residual risk scoring, control effectiveness evaluation, risk-based audit planning, heat map generation, risk appetite alignment, and audit prioritization by risk exposure. Covers the full audit risk assessment cycle from scoping through ongoing monitoring. Keywords: audit risk assessment, risk universe, inherent risk, residual risk, control effectiveness, risk-based audit planning.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

World-Class Risk Management Playbook. Use for: business continuity planning (BCP), disaster recovery (DR), scenario planning, fraud prevention & detection, reputational risk management, geopolitical risk assessment, insurance & risk transfer, crisis communication, enterprise risk management (ERM), risk registers, BIA, RTO/RPO, ISO 22301, ISO 31000, COSO ERM, NIST CSF, DORA, operational resilience, three lines of defence, risk appetite, internal controls, segregation of duties, synthetic identity fraud, deepfake fraud, AML/CFT, KYC, sanctions screening, social listening, vendor risk, geopolitical exposure mapping, parametric insurance, cyber insurance, D&O, KRIs, risk dashboards. Trigger when discussing ANY risk management, business continuity, disaster recovery, fraud prevention, reputational risk, geopolitical risk, insurance strategy, crisis management, operational resilience, or enterprise risk topic. If in doubt, use this skill.

日本語の概要は準備中です。原文の説明を表示しています。

aAAaqwq/openclaw-team22026年6月18日 更新

Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis. Use when user mentions risk management, ISO 14971, risk analysis, FMEA, fault tree analysis, hazard identification, risk control, risk matrix, benefit-risk analysis, residual risk, risk acceptability, or post-market risk.

日本語の概要は準備中です。原文の説明を表示しています。

alirezarezvani/claude-skills2.8万2026年8月30日 更新

Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

risk

無料

Risk analysis, regulatory risk assessment, competitive risk, macro risk, technology risk, litigation risk, financial risk assessment, enterprise risk, operational risk, geopolitical risk exposure

日本語の概要は準備中です。原文の説明を表示しています。

agentii-ai/agentii-investment-intelligence2072026年9月29日 更新

"biz-erm"

無料

"Enterprise risk management (ERM) framework layer — integrates COSO ERM 2017 (five components, 20 principles), ISO 31000, three-lines model, risk appetite, risk heatmap, and key risk indicators (KRI) into a complete governance playbook covering structure through culture. Use for ERM implementation, risk-system build, risk mapping, risk-appetite statement drafting, three-lines setup, CRO role design, or Taiwan FSC corporate-governance evaluation response. Triggers: 『ERM 導入』『風險管理框架』『COSO』『風險地圖』『風險胃納』『KRI』『CRO 職責』『三道防線』『風險委員會』『ISO 31000』『風險熱圖』『風險治理』. For 師大/政大/陽交 EMBA risk-management/governance/audit cases. Complements Asgard `algo-risk-*` (Altman Z, Benford, credit, VaR) with the framework/governance layer. 獨董挑選/董事會組成/IPO 治理: use `biz-corporate-governance`.".

日本語の概要は準備中です。原文の説明を表示しています。

charlieviettq/awesome-agent-skill262026年7月20日 更新

dod-rio

無料

Knowledge base from the DoD Risk, Issue, and Opportunity (RIO) Management Guide for Defense Acquisition Programs (OUSD R&E, Sep 2023 incl. Change 2.2). Use for the defense-acquisition mechanics of program risk management: the RIO definitions (risk/issue/opportunity), the five-step risk process (plan-identify-analyze-mitigate-monitor), 1-5 likelihood/consequence scoring and the 5x5 risk matrix, the four mitigation options (accept/avoid/transfer/control), burn-down plans, issue management (probability=1), opportunity management toward should-cost, cross-program/interface risk, tailoring RIO to the six AAF acquisition pathways (UCA/MTA/MCA/Software/DBS/Services), specialized methods (RMF, MBCRA/Cyber Table Top, Agile metrics, FMECA, ITRA/DTRAM), and institutionalizing RIO via the PRMP, boards (RMB/JRMB/ROMB/RWG), tools, tiered roles, and WBS/IMP/IMS/EVM/TPM integration. This is the DoD-acquisition complement to nasa-risk (general CRM/RIDM theory) and dau-se-guidebook (the SE process frame). Does NOT teach general risk theory from scratch, and defers specialized risk regimes (system safety/ESOH, HSI, detailed cyber/RMF, spectrum) to their own DoD instructions and the relevant packs.

日本語の概要は準備中です。原文の説明を表示しています。

jgsystemsconsulting/jgs-se-knowledge-packs82026年10月9日 更新

Defensive threat modeling and risk management for your own estate — map where sensitive data lives across your asset graph, run compromise scenarios (what a hacked asset exposes, its blast radius, how you'd respond), and maintain a persistent risk register with likelihood×impact scoring, owners, mitigations, and review cadence via a deterministic CLI. All real data stays in your private USER tree; this skill is code only. USE WHEN threat model, threat modeling, risk register, risk assessment, what if X got hacked, compromise scenario, blast radius, sensitive data map, where is our sensitive data, data classification, risk review, add a risk, accept a risk, security risk posture. NOT FOR active pentesting or exploitation (use an offensive-security skill), world-scale futures stress-testing of ideas (use WorldThreatModel), or executing incident response (use your incident-response runbooks — this skill plans them).

日本語の概要は準備中です。原文の説明を表示しています。

danielmiessler/LifeOS1.9万2026年9月4日 更新

Structured legal risk assessment with 5x5 Severity x Likelihood matrix. Use for risk scoring, risk registers, escalation decisions, and risk memos.

日本語の概要は準備中です。原文の説明を表示しています。

borghei/Claude-Skills8942026年10月7日 更新

Determines whether a technology qualifies as an AI system under Art. 3(1) of the EU AI Act and classifies its risk tier (prohibited, high-risk, GPAI with systemic risk, limited risk, minimal risk). This skill should be used when the user asks to "classify an AI system under the AI Act", "determine the AI Act risk tier", "check if something is an AI system", "assess prohibited practices", "check high-risk classification", "determine Art. 6 exception applicability", or mentions "KI-Verordnung", "Risikoklassifizierung", Art. 5, Annex III, or GPAI systemic risk.

日本語の概要は準備中です。原文の説明を表示しています。

lawve-ai/awesome-legal-skills8512026年10月3日 更新

Check the current status of the Strait of Hormuz — shipping transit data, oil price impact, stranded vessels, insurance risk levels, diplomatic developments, and global trade impact. Use this skill whenever the user asks about the Strait of Hormuz, Hormuz chokepoint, Persian Gulf shipping risk, oil transit disruption, war risk premium in the Gulf, Middle East shipping routes, tanker traffic through Hormuz, oil supply chain risk, or geopolitical risk affecting energy markets. Triggers include: "Hormuz status", "Strait of Hormuz", "is Hormuz open", "shipping through the Gulf", "oil chokepoint", "Persian Gulf tanker traffic", "war risk premium", "Hormuz crisis", "energy supply chain risk", "oil transit disruption", "Middle East shipping", any mention of Hormuz or Persian Gulf in context of oil, shipping, or geopolitical risk.

日本語の概要は準備中です。原文の説明を表示しています。

FDU-INS/Insurance-Skills762026年7月12日 更新

Cyber Risk Quantification engineer for CyberRadar. Implements FAIR (Factor Analysis of Information Risk) methodology, Monte Carlo simulation for loss distribution modeling, financial impact quantification in multi-currency (SAR, USD, EUR, GBP), loss exceedance curves, risk treatment ROI calculation, insurance premium optimization, and board-ready financial risk reporting. Transforms qualitative risk assessments into monetary terms for executive decision-making. Triggers on: CRQ, FAIR, Monte Carlo, financial impact, loss modeling, risk quantification, cyber insurance, risk treatment ROI, financial risk.

日本語の概要は準備中です。原文の説明を表示しています。

FDU-INS/Insurance-Skills762026年7月12日 更新

Decomposes portfolio risk with factor attribution, idiosyncratic risk, and marginal contribution to risk analysis. Use when decomposing portfolio risk, attributing risk sources, or analyzing factor risk contribution.

日本語の概要は準備中です。原文の説明を表示しています。

CaseMark/skills442026年9月9日 更新

Identify, score, and mitigate delivery risks for a program or release. Use when the user says "risk review", "what could go wrong", "risk register", "delivery risks for this release", "program risk assessment", "identify blockers before they hit", or wants to pressure-test a plan before committing - even if they don't say "risk review". Based on "The Phoenix Project" by Kim, Behr & Spafford (unplanned work, fragile systems, single points of failure) and "The Art of Project Management" by Scott Berkun (scoping risk, milestone pressure, hidden assumptions).

日本語の概要は準備中です。原文の説明を表示しています。

qa-aman/claude-skills202026年9月10日 更新

Work a primary-prevention patient through the 2026 ACC/AHA multisociety dyslipidaemia guideline CPR framework — Calculate (10-year and 30-year PREVENT-ASCVD), Classify (low / borderline / intermediate / high), Personalize (demographic, clinical, biomarker, and reproductive risk enhancers), and Reclassify (coronary artery calcium scoring where appropriate). Use when a clinician asks how to assess ASCVD risk for primary prevention, who needs a statin, borderline risk patient what to do, intermediate risk should I start a statin, risk enhancers to look for, premature family history of ASCVD how does it change risk, pregnancy-related risk factors, PCOS and cardiovascular risk. Grounded in the 2026 ACC/AHA multisociety dyslipidaemia guideline.

日本語の概要は準備中です。原文の説明を表示しています。

dromlakhani/MD2SKILL122026年10月5日 更新

Calculate and interpret the PREVENT-ASCVD risk score (10-year and 30-year) for primary prevention of atherosclerotic cardiovascular disease per the 2026 ACC/AHA multisociety dyslipidaemia guideline. Covers inputs required, risk-category thresholds (low <3%, borderline 3–<5%, intermediate 5–<10%, high ≥10%), when to use the 30-year calculation (adults 30–59), and how PREVENT differs from the older Pooled Cohort Equations (lower risk estimates by 40–50%, race-agnostic). Use when a clinician asks what the 10-year ASCVD risk is, how to calculate PREVENT, PCE vs PREVENT, risk category for this patient, does my patient need a statin, 30-year risk calculation, primary prevention risk assessment. Grounded in the 2026 ACC/AHA multisociety dyslipidaemia guideline.

日本語の概要は準備中です。原文の説明を表示しています。

dromlakhani/MD2SKILL122026年10月5日 更新

nasa-risk

無料

Knowledge base from NASA Risk Management Handbook (NASA/SP-2011-3422). Use for risk-informed decision making, continuous risk management, performance commitments, risk scenario diagrams, risk disposition types, risk burn-down schedules, objectives hierarchies, deliberation and alternative selection, risk driver identification, and RM planning for space and safety-critical programmes. Does not cover domain-specific PRA methods (fault trees, event trees) in procedural depth — see NASA PRA Procedures Guide for those.

日本語の概要は準備中です。原文の説明を表示しています。

jgsystemsconsulting/jgs-se-knowledge-packs82026年10月9日 更新

Identifies, assesses, and tracks organizational risk — building and maintaining a risk register, scoring exposure, assigning owners and treatments, and preparing for audit. Use this to stand up a risk program, assess the risk in a decision or initiative, prepare for a certification or audit, decide whether a risk should be accepted, mitigated, transferred, or avoided, or report risk posture to leadership.

日本語の概要は準備中です。原文の説明を表示しています。

cbrock84/headcount2,0312026年9月18日 更新

Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and post-production information analysis.

日本語の概要は準備中です。原文の説明を表示しています。

borghei/Claude-Skills8942026年10月7日 更新

RAID log methodology with decision extraction from emails and meeting notes. Use when asked to identify risks, log assumptions, track issues, extract decisions from correspondence, create or update a RAID log, escalate a risk to an issue, assess project risks, validate or challenge assumptions, or capture scope-relevant decisions. Also triggers when the user pastes email chains and asks what decisions were made, or needs to find buried decisions and untested assumptions in correspondence. Trigger on: 'risk report', 'RAID log', 'what are the risks', 'what decisions were made', 'update the risk register', 'what assumptions are we making', 'what could go wrong', 'flag any issues', 'extract decisions from these emails'.

日本語の概要は準備中です。原文の説明を表示しています。

lawve-ai/awesome-legal-skills8512026年10月3日 更新

Conducts HIPAA risk analysis per 45 CFR §164.308(a)(1) following OCR guidance methodology. Covers threat identification, vulnerability assessment, likelihood and impact determination, risk scoring, and mitigation planning for electronic protected health information. Keywords: HIPAA risk analysis, OCR guidance, threat assessment, vulnerability, risk management, ePHI.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d). Covers mitigation measure identification, implementation tracking, residual risk acceptance, and Art. 36 prior consultation triggers. Keywords: DPIA mitigation, risk treatment, residual risk, Art. 35(7)(d), safeguards, mitigation tracking, prior consultation.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新