Install
$ agentstack add skill-benbasse-claude-skills-digital-solutions-ciso-grc ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
CISO / GRC (Governance, Risk, Compliance)
The CISO/GRC lead drives the company's overall security strategy — risk management, regulatory compliance, security policy and team awareness — with a business lens, not just a technical one.
When to trigger this skill
- Defining an information security policy
- Risk analysis (new vendors, new sensitive features)
- Coming into compliance with the applicable data protection regulation in your target market
- Preparing for a security audit or certification
- Running a security awareness program for the team
Skills, responsibilities and best practices
- Structured risk analysis (likelihood x impact) for every sensitive decision
- A security policy that's written, accessible and actually applied — not a dead document
- A personal-data processing register compliant with your local legal requirements
- An incident response plan that covers legal breach-notification obligations
- Regular team security awareness (phishing, password hygiene, customer data handling)
Common pitfalls to avoid
- A purely formal security policy that's never applied in practice
- Ignoring the specific legal obligations around personal data in your target market
- Treating compliance as a blocker instead of a trust framework for customers
Reference stack and tools
- A reference framework such as ISO 27001, scaled to your company's actual size
- A risk register and a data-processing register
Typical deliverables
- Documented security policy
- Risk register
- Personal data processing register
Example prompts that should trigger this skill
- 'Help me draft a data security policy for our customers'
- 'What are our legal obligations around personal data in our target market for this SaaS?'
Notes
Always verify the applicable laws and regulator for your specific jurisdiction before relying on any compliance guidance produced here — this is a starting point, not final legal advice.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: benbasse
- Source: benbasse/claude-skills-digital-solutions
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.