本文へ移動
cccskills
無料GitHub で公開

mcsb

Microsoft Cloud Security Benchmark (MCSB v2) control-domain taxonomy and NIST 800-53 / CIS Controls crosswalk for planning and reviewing Azure cloud resources.

インストール方法を見る

含まれるファイル(15)

  • SKILL.md3.9 KB
  • references/00-control-index.md6.3 KB
  • references/01-network-security.md2.2 KB
  • references/02-identity-management.md2.1 KB
  • references/03-privileged-access.md2.0 KB
  • references/04-data-protection.md1.9 KB
  • references/05-asset-management.md1.9 KB
  • references/06-logging-threat-detection.md2.0 KB
  • references/07-incident-response.md1.8 KB
  • references/08-posture-vulnerability-management.md1.9 KB
  • references/09-endpoint-security.md1.8 KB
  • references/10-backup-recovery.md1.8 KB
  • references/11-devops-security.md2.0 KB
  • references/12-ai-security.md2.3 KB
  • references/lookup-playbook.md2.5 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Microsoft Cloud Security Benchmark — Skill Entry

This SKILL.md is the entrypoint for the Microsoft Cloud Security Benchmark (MCSB) skill.

The skill encodes the durable, structurally stable layer of MCSB — the control-domain taxonomy and a domain-grain crosswalk to NIST SP 800-53 and CIS Controls — so the Security Planner and Security Reviewer can map and assess Azure cloud resources against a consistent control vocabulary.

The skill deliberately does not embed the volatile layer of MCSB (per-Azure-service security baselines, per-service control IDs, Azure Policy mappings, and Defender for Cloud assessment specifics). That content changes on Microsoft's release cadence and is retrieved at runtime through the Researcher Subagent per references/lookup-playbook.md.

Version and stability

This skill targets MCSB v2, which Microsoft marks as preview and which supersedes MCSB v1. Content is version-pinned and retrieval-dated (2026-07-21). MCSB v2 replaces v1's Governance and Strategy (GS) domain with an Artificial Intelligence Security (AI) domain, and maps to NIST SP 800-53 Rev. 5 and CIS Controls v8.1 (v1 mapped to Rev. 4 and CIS v8). Re-verify the taxonomy and mappings against the official source before relying on them for a compliance decision.

Normative references

  1. 00 Control Index
  2. 01 Network Security
  3. 02 Identity Management
  4. 03 Privileged Access
  5. 04 Data Protection
  6. 05 Asset Management
  7. 06 Logging and Threat Detection
  8. 07 Incident Response
  9. 08 Posture and Vulnerability Management
  10. 09 Endpoint Security
  11. 10 Backup and Recovery
  12. 11 DevOps Security
  13. 12 Artificial Intelligence Security
  14. Lookup Playbook — delegation guardrail for volatile per-service lookups.

Skill layout

  • SKILL.md — this file (skill entrypoint).
  • references/ — the MCSB durable reference documents.
    • 00-control-index.md — control-domain catalog, consolidated crosswalk, and attribution.
    • 01 through 12 — one document per MCSB v2 control domain with assessment checklists.
    • lookup-playbook.md — delegation guardrail for volatile per-service content.

Attribution

Reference content in this skill is original prose that paraphrases publicly documented MCSB structure. The MCSB v2 (preview) documentation this skill cites is published on Microsoft Learn from a non-public source repository and is governed by the Microsoft Learn Terms of Use, not a public Creative Commons license. The separate, older MicrosoftDocs/SecurityBenchmarks repository is CC BY 4.0, but its benchmark spreadsheets stop at Azure Security Benchmark v3 (the pre-rename lineage) and Microsoft Cloud Security Benchmark v1; it does not contain the MCSB v2 (preview) content this skill cites. Because this skill paraphrases rather than reproduces upstream text, no verbatim-reproduction license grant applies; it cites the canonical source in each reference file. See references/00-control-index.md for the consolidated attribution.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Consolidated accessibility skill entrypoint for WCAG 2.2, ARIA Authoring Practices, cognitive accessibility, Section 508, EN 301 549, design intent verification, and the Accessibility Planner workflow.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

Build, refresh, report, or probe an accessibility coverage matrix across criteria, surfaces, and evidence methods. Use when assessing coverage with the accessibility runtime harness and generated evidence bundle.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

Authoring skill for Architecture Decision Records (ADRs) supporting capture, from-planner-handoff, and adopt-template entry modes with selectable Y-Statement or MADR v4.0.0 output templates, supersession lineage, and ASR trigger evaluation.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

Authoring conventions for exploratory data analysis notebooks and analytical dashboards, covering section sequence, visualization selection, scale thresholds, caching and state, and dashboard validation budgets. Use when composing or reviewing an EDA notebook, an analytical dashboard, or a dashboard test pass.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

Architecture diagram authoring for cloud infrastructure and declared data catalogs. Use when rendering Azure IaC or DS_CATALOG_V1 relationships as caller-selected ASCII or Mermaid diagrams.

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

Create a durable Architecture Review Record from a confirmed System Architecture Reviewer scope, evidence, pillar analysis, trade-offs, and dispositions

日本語の概要は準備中です。原文の説明を表示しています。

microsoft/hve-core1,5192026年10月11日 更新

microsoft のスキルをすべて見る

このスキルの問題を報告する