Agent skill

Information Security Strategy

by Hack23 in Hack23/cia

AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model

Apache-2.0Auto-check passedSecurity

Install Information Security Strategy

skills CLI
$ npx skills add Hack23/cia --skill information-security-strategy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia information-security-strategy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/information-security-strategy .claude/skills/information-security-strategy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
information-security-strategy
GitHub stars
239
Token cost
~4.1k tokens
SKILL.md length
733 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model

  • Works in 5 steps: Business Context → Security Architecture → Defense-in-Depth → …
  • Tasks that involve Secure coding
  • SKILL.md covers Purpose, When to Use This Skill, AI-First Security Operations… and Product Security Architecture…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Information Security Strategy is an agent skill from Hack23/cia. AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Secure coding, Product strategy and Startup and business strategy. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secure coding
  • Tasks that involve Product strategy
  • Tasks that involve Startup and business strategy

Example prompts

  • “/information-security-strategy”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Business Context
  2. Security Architecture
  3. Defense-in-Depth
  4. Evidence & Transparency
  5. AI Operations Integration

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml and mermaid).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Information Security Strategy loads about 4.1k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 733 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~44
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 733 words, ~4,115 tokens.

Download SKILL.mdSave it as .claude/skills/information-security-strategy/SKILL.md (or your agent's skills folder).
name
information-security-strategy
description
AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model
license
Apache-2.0

Information Security Strategy Skill

Purpose

This skill provides strategic security planning guidance aligned with Hack23 AB's AI-augmented operating model and transparent ISMS implementation. It enables security architects and business leaders to align security controls with business impact classifications, demonstrate security excellence through public transparency, and leverage ISMS as competitive advantage for cybersecurity consulting services.

When to Use This Skill

Apply this skill when:

  • ✅ Developing security strategies for new products or services
  • ✅ Aligning security controls with business impact classifications
  • ✅ Designing defense-in-depth architectures
  • ✅ Evaluating risk-based security control selection
  • ✅ Planning AI-augmented security operations
  • ✅ Preparing security posture demonstrations for clients
  • ✅ Integrating security with Porter's Five Forces strategic analysis
  • ✅ Documenting security architecture decisions
  • ✅ Balancing transparency with confidentiality requirements

Do NOT use for:

  • ❌ Tactical incident response (use incident-response skill)
  • ❌ Specific vulnerability remediation (use vulnerability-management skill)
  • ❌ Code-level security reviews (use secure-code-review skill)

AI-First Security Operations Model

mermaid
graph TB
    CEO["👨💼 CEO/Founder<br/>Strategic Oversight"]
    
    subgraph AI_AGENTS["🤖 Specialist AI Agent Ecosystem"]
        SEC_ARCH["🔐 Security Architect Agent<br/>Architecture design & review"]
        DEV_SEC["💻 DevSecOps Agent<br/>CI/CD security integration"]
        TEST_SEC["🧪 Security Testing Agent<br/>SAST/DAST/Fuzzing"]
        DOC_SEC["📚 Documentation Agent<br/>Policy & procedure creation"]
        BIZ_SEC["💼 Business Agent<br/>Risk/value alignment"]
        MARKET_SEC["📢 Marketing Agent<br/>Security posture communication"]
    end
    
    CEO --> SEC_ARCH
    CEO --> DEV_SEC
    CEO --> TEST_SEC
    CEO --> DOC_SEC
    CEO --> BIZ_SEC
    CEO --> MARKET_SEC
    
    SEC_ARCH --> ARCH_OUT["📋 SECURITY_ARCHITECTURE.md<br/>THREAT_MODEL.md"]
    DEV_SEC --> CICD_OUT["⚙️ GitHub Actions Workflows<br/>Security Gates"]
    TEST_SEC --> TEST_OUT["🧪 CodeQL / OWASP ZAP<br/>Vulnerability Reports"]
    DOC_SEC --> DOC_OUT["📖 ISMS Policies<br/>Compliance Evidence"]
    BIZ_SEC --> BIZ_OUT["💰 Risk Register<br/>Business Impact Analysis"]
    MARKET_SEC --> MARKET_OUT["🏆 Security Badges<br/>Public Metrics"]
    
    ARCH_OUT --> EVIDENCE["🎖️ Public Evidence<br/>OpenSSF Scorecard<br/>CII Best Practices<br/>SLSA Level 3"]
    CICD_OUT --> EVIDENCE
    TEST_OUT --> EVIDENCE
    DOC_OUT --> EVIDENCE
    BIZ_OUT --> EVIDENCE
    MARKET_OUT --> EVIDENCE
    
    EVIDENCE --> CLIENTS["🤝 Client Demonstration<br/>Competitive Advantage"]
    
    style CEO fill:#1565C0,stroke:#0D47A1,stroke-width:3px,color:#fff
    style AI_AGENTS fill:#4CAF50,stroke:#2E7D32,stroke-width:2px
    style EVIDENCE fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style CLIENTS fill:#9C27B0,stroke:#6A1B9A,stroke-width:2px

Key Strategic Principles:

  • <1 FTE Operations: AI agents handle 80%+ security tasks under CEO oversight
  • Transparent by Default: 70% of ISMS publicly visible (only credentials/pricing redacted)
  • Evidence-Based: All security claims backed by public badges and metrics
  • Business Alignment: ISMS is not separate from business—it IS the business model

Product Security Architecture Decision Framework

Use this decision tree when designing security controls for new products:

mermaid
flowchart TD
    START["🎯 New Product/Service"] --> CLASS{What is the<br/>Confidentiality<br/>Classification?}
    
    CLASS -->|Low| LOW_CONF["⚪ Low Confidentiality<br/>Public data only"]
    CLASS -->|Moderate| MOD_CONF["🟡 Moderate Confidentiality<br/>User accounts/data"]
    CLASS -->|High/Very High| HIGH_CONF["🔴 High/Very High<br/>Sensitive operations"]
    
    LOW_CONF --> AUTH_LOW{Does app process<br/>user-specific data?}
    AUTH_LOW -->|No| NO_AUTH["❌ No Authentication<br/>✅ TLS 1.3 Required<br/>Example: CIA CM, Black Trigram"]
    AUTH_LOW -->|Yes| BASIC_AUTH["🔐 Basic Authentication<br/>Username/Password"]
    
    MOD_CONF --> AUTH_MOD["🔐 Full Authentication Stack"]
    AUTH_MOD --> MFA["✅ MFA Required<br/>✅ RBAC<br/>✅ Session Management<br/>✅ Audit Logging"]
    
    HIGH_CONF --> AUTH_HIGH["🔐 Enhanced Security"]
    AUTH_HIGH --> ENHANCED["✅ MFA Mandatory<br/>✅ Fine-grained RBAC<br/>✅ Comprehensive Audit<br/>✅ Encryption at Rest<br/>Example: CIA Platform"]
    
    NO_AUTH --> RATIONALE_LOW["📋 Document Risk Acceptance<br/>Update Risk Register<br/>Reference Classification Framework"]
    BASIC_AUTH --> RATIONALE_MOD["📋 Document Control Selection<br/>Map to Classification Framework"]
    MFA --> RATIONALE_HIGH["📋 Full Security Architecture<br/>SECURITY_ARCHITECTURE.md"]
    ENHANCED --> RATIONALE_HIGH
    
    RATIONALE_LOW --> VERIFY["🧪 Verification Required"]
    RATIONALE_MOD --> VERIFY
    RATIONALE_HIGH --> VERIFY
    
    VERIFY --> V1["✅ SECURITY_ARCHITECTURE.md created"]
    VERIFY --> V2["✅ THREAT_MODEL.md completed"]
    VERIFY --> V3["✅ Risk Register updated"]
    VERIFY --> V4["✅ Classification badges in README"]
    
    style START fill:#1565C0,stroke:#0D47A1,stroke-width:2px,color:#fff
    style LOW_CONF fill:#9E9E9E,stroke:#616161,stroke-width:2px
    style MOD_CONF fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style HIGH_CONF fill:#D32F2F,stroke:#B71C1C,stroke-width:3px,color:#fff
    style NO_AUTH fill:#4CAF50,stroke:#2E7D32,stroke-width:2px,color:#fff
    style ENHANCED fill:#B71C1C,stroke:#880E4F,stroke-width:3px,color:#fff
    style VERIFY fill:#7B1FA2,stroke:#4A148C,stroke-width:2px,color:#fff

Security Control Selection by Business Impact

Map security controls to Classification Framework business impact levels:

High Business Impact Products

CIA Platform - Moderate Confidentiality, High Integrity, Moderate Availability

Required Controls:

yaml
authentication:
  type: "Multi-factor with RBAC"
  implementation: "Spring Security + JWT + MFA"
  session: "Server-side with Redis"
  
audit_logging:
  framework: "Javers + AWS CloudTrail"
  retention: "7 years (regulatory compliance)"
  monitoring: "Real-time with CloudWatch alarms"
  
encryption:
  in_transit: "TLS 1.3 enforced"
  at_rest: "PostgreSQL encryption + AWS KMS"
  
access_control:
  model: "Role-Based Access Control (RBAC)"
  segregation: "Admin/User/Anonymous roles"

Architecture Documentation:

Low Business Impact Products

CIA Compliance Manager, Black Trigram - Low Confidentiality, Moderate Integrity

Required Controls:

yaml
authentication:
  type: "None (intentional risk acceptance)"
  rationale: "Public data only, no user-specific operations"
  risk_documentation: "Risk_Register.md entry with annual review"
  
encryption:
  in_transit: "TLS 1.3 enforced via CDN"
  at_rest: "Not applicable (no backend database)"
  
session_management:
  type: "Browser-only (localStorage/sessionStorage)"
  scope: "UI state persistence only"
  
monitoring:
  application: "None (frontend-only, stateless)"
  infrastructure: "CDN access logs only"

Risk Acceptance Documentation:

The absence of authentication is an intentional architectural decision based on Low confidentiality classification. All data processed is public compliance framework information with no sensitive user data. This risk is documented in the Risk Register with periodic review triggers if feature requirements change.

Architecture Documentation:

Defense-in-Depth Layered Security Model

Implement security controls across multiple layers aligned with product classification:

mermaid
graph TB
    subgraph LAYER7["🎯 Layer 7: Policies & Governance"]
        POLICY[Information Security Policy<br/>Classification Framework<br/>Risk Register]
    end
    
    subgraph LAYER6["👥 Layer 6: Application Security"]
        APP["Authentication & Authorization<br/>Input Validation<br/>Session Management"]
    end
    
    subgraph LAYER5["🔐 Layer 5: Data Security"]
        DATA[Encryption at Rest<br/>Encryption in Transit<br/>Data Classification]
    end
    
    subgraph LAYER4["🌐 Layer 4: Network Security"]
        NETWORK[TLS 1.3 Enforcement<br/>CDN Protection<br/>DDoS Mitigation]
    end
    
    subgraph LAYER3["🖥️ Layer 3: Infrastructure Security"]
        INFRA[AWS Security Groups<br/>IAM Policies<br/>VPC Configuration]
    end
    
    subgraph LAYER2["🛠️ Layer 2: CI/CD Security"]
        CICD[SAST: CodeQL/SonarCloud<br/>SCA: Dependabot/FOSSA<br/>DAST: OWASP ZAP]
    end
    
    subgraph LAYER1["📊 Layer 1: Monitoring & Response"]
        MONITOR[CloudWatch Alarms<br/>Security Hub<br/>Incident Response]
    end
    
    POLICY --> APP
    APP --> DATA
    DATA --> NETWORK
    NETWORK --> INFRA
    INFRA --> CICD
    CICD --> MONITOR
    MONITOR -->|Feedback Loop| POLICY
    
    style LAYER7 fill:#D32F2F,stroke:#B71C1C,stroke-width:2px,color:#fff
    style LAYER6 fill:#FF5722,stroke:#D84315,stroke-width:2px,color:#fff
    style LAYER5 fill:#FF9800,stroke:#F57C00,stroke-width:2px
    style LAYER4 fill:#FFC107,stroke:#FFA000,stroke-width:2px
    style LAYER3 fill:#4CAF50,stroke:#388E3C,stroke-width:2px,color:#fff
    style LAYER2 fill:#2196F3,stroke:#1976D2,stroke-width:2px,color:#fff
    style LAYER1 fill:#9C27B0,stroke:#7B1FA2,stroke-width:2px,color:#fff

Porter's Five Forces Security Integration

Align security strategy with competitive advantage:

ForceSecurity ImplicationStrategic Response
Buyer PowerCustomers demand security evidencePublic badges: OpenSSF Scorecard ≥7.0, CII Best Practices, SLSA Level 3
Supplier PowerCloud/SaaS vendor dependenciesMulti-vendor flexibility, open source preference, SBOM transparency
Entry BarriersExpertise required for ISMSTransparent ISMS creates moat—competitors lack documentation maturity
Substitute ThreatIn-house security teamsDemonstrate AI-augmented efficiency (<1 FTE overhead vs 3-5 FTE teams)
RivalryCybersecurity consulting competitionISMS transparency differentiates—"eat our own dog food" credibility

Reference: Information Security Strategy § Porter's Five Forces

Compliance Mapping Quick Reference

Map strategic security decisions to compliance frameworks:

Security DecisionISO 27001:2022NIST CSF 2.0CIS Controls v8
Authentication modelA.5.15, A.5.16PR.AC-015.2, 6.3
Encryption requirementsA.8.24PR.DS-013.10
Risk acceptance processA.5.7, A.8.3GV.RM-014.1
Security architectureA.8.1PR.IP-0116.1
Monitoring & loggingA.8.15, A.8.16DE.AE-018.2, 8.5
Show full SKILL.md (270 more words)Show less

Strategic Planning Checklist

Use this checklist when developing security strategy for new initiatives:

Phase 1: Business Context
  • Classify product using Classification Framework
  • Identify CIA triad requirements (Confidentiality/Integrity/Availability)
  • Assess Porter's Five Forces strategic positioning
  • Determine business impact levels (Financial/Operational/Reputational)
  • Document RTO/RPO requirements
Phase 2: Security Architecture
  • Select authentication model based on confidentiality classification
  • Design authorization model (RBAC/ABAC/None)
  • Plan encryption requirements (TLS/at-rest/key management)
  • Define audit logging scope and retention
  • Document risk acceptance for deviations from standards
Phase 3: Defense-in-Depth
  • Map controls to all 7 layers (Governance → Monitoring)
  • Implement least privilege access
  • Configure security boundaries (network/application/data)
  • Enable automated security testing (SAST/SCA/DAST)
  • Set up monitoring and alerting
Phase 4: Evidence & Transparency
  • Create SECURITY_ARCHITECTURE.md with Mermaid diagrams
  • Complete THREAT_MODEL.md with STRIDE analysis
  • Update Risk Register with risk acceptance decisions
  • Configure security badges (OpenSSF/CII/SLSA/SonarCloud)
  • Publish architecture documentation
Phase 5: AI Operations Integration
  • Configure GitHub Copilot security agents
  • Enable automated security reviews
  • Set up dependency scanning (Dependabot)
  • Configure secret scanning
  • Implement SBOM generation

Practical Implementation Examples

Example 1: Frontend-Only Application (Low Confidentiality)

Scenario: Educational gaming platform with no user accounts

Security Architecture:

yaml
product_name: "Black Trigram Educational Gaming"
classification:
  confidentiality: "Low"
  integrity: "Moderate"
  availability: "Moderate"

security_controls:
  authentication: "None (risk accepted)"
  authorization: "None (public content)"
  encryption_in_transit: "TLS 1.3 via CDN"
  encryption_at_rest: "N/A (no backend)"
  session_management: "Browser localStorage only"
  audit_logging: "None (frontend-only)"
  
risk_acceptance:
  rationale: "All game content is public educational material"
  risk_register_entry: "RSK-2025-001"
  review_cycle: "Annual"
  trigger_conditions:
    - "Introduction of user accounts"
    - "Addition of user-generated content"
    - "Processing of personal data"

Required Documentation:

  • SECURITY_ARCHITECTURE.md describing intentional architecture
  • THREAT_MODEL.md with frontend-specific threats
  • Risk Register entry documenting risk acceptance
  • README.md with Classification badges
Example 2: Multi-Tenant SaaS Platform (Moderate Confidentiality)

Scenario: Political transparency platform with user accounts

Security Architecture:

yaml
product_name: "Citizen Intelligence Agency"
classification:
  confidentiality: "Moderate"
  integrity: "High"
  availability: "Moderate"

security_controls:
  authentication: "Multi-factor (TOTP/SMS)"
  authorization: "RBAC (Admin/User/Anonymous)"
  encryption_in_transit: "TLS 1.3"
  encryption_at_rest: "PostgreSQL + AWS KMS"
  session_management: "Server-side JWT with Redis"
  audit_logging: "Javers + CloudWatch (7-year retention)"
  
defense_in_depth:
  layer_7_governance: "Information Security Policy"
  layer_6_application: "Spring Security + MFA"
  layer_5_data: "Field-level encryption for PII"
  layer_4_network: "VPC + Security Groups"
  layer_3_infrastructure: "AWS IAM + GuardDuty"
  layer_2_cicd: "CodeQL + SonarCloud + ZAP"
  layer_1_monitoring: "CloudWatch + Security Hub"

Required Documentation:

  • Comprehensive SECURITY_ARCHITECTURE.md
  • Detailed THREAT_MODEL.md with attack trees
  • Regular risk assessments in Risk Register
  • Full compliance mapping in README.md

Standards & Policy References

Core Hack23 ISMS Policies:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. 1 hidden character (zero-width or bidirectional) removed. Raw file

Files

Just SKILL.md in .github/skills/information-security-strategy of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Information Security Strategy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Information Security Strategy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Information Security Strategy this skillHack23/cia239—~4.1kAutomated safety check: PassApache-2.0
Zhang Yiming Perspectivealchaincyf/zhang-yiming-skill1732 repos~3.2kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Humble Header Report Analystrfc-st/humble379—~3.7kAutomated safety check: PassMIT
Startup Designferdinandobons/startup-skill1.2k—~8.1kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT

Similar skills

  • Zhang Yiming Perspective

    alchaincyf/zhang-yiming-skill

    Answers product, organization, globalization, talent and growth questions in the voice of ByteDance founder Zhang Yiming, using a framework built from public material.

    173 GitHub starsUsed in 2 repos~3.2k tokens
    Business, Finance & HRAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.

    379 GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check passed
  • Startup Design

    ferdinandobons/startup-skill

    Design, validate, and plan a startup from scratch. An agent skill from ferdinandobons/startup-skill.

    1.2k GitHub stars~8.1k tokensUpdated 3 mo ago
    Marketing & SEOAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • Defense In Depth

    sandgardenhq/sgai

    A skill your agent uses when invalid data causes failures deep in execution, requiring validation at multiple system layers - validates at every layer data passes through to make bugs structurally…

    137 GitHub starsUsed in 3 repos~970 tokens
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Information Security Strategy

What does Information Security Strategy do?

AI-enabled security excellence through transparent ISMS implementation, defense-in-depth, and strategic planning aligned with Hack23 business model. Information Security Strategy is an agent skill from Hack23/cia.

When should I use Information Security Strategy?

Information Security Strategy fits situations like: tasks that involve Secure coding; tasks that involve Product strategy; tasks that involve Startup and business strategy.

How do I install Information Security Strategy in Claude Code?

Run `npx skills add Hack23/cia --skill information-security-strategy -a claude-code`. Or copy the skill folder (.github/skills/information-security-strategy in Hack23/cia) into .claude/skills/information-security-strategy in your project. Claude Code loads it when a task matches its description.

How do I install Information Security Strategy in Codex?

Run `npx skills add Hack23/cia --skill information-security-strategy -a codex`. Or copy the skill folder (.github/skills/information-security-strategy in Hack23/cia) into .agents/skills/information-security-strategy in your project. Codex loads it when a task matches its description.

Can I use Information Security Strategy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill information-security-strategy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/information-security-strategy, .gemini/skills/information-security-strategy, .github/skills/information-security-strategy and .opencode/skills/information-security-strategy in your project.

What does Information Security Strategy need to run?

SKILL.md names no scripts, command-line tools or credentials: Information Security Strategy is instructions for the agent only.

Does Information Security Strategy access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Information Security Strategy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Information Security Strategy use?

Information Security Strategy is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Information Security Strategy use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Information Security Strategy?

Skills that share tags, products or a category with Information Security Strategy: Zhang Yiming Perspective (alchaincyf/zhang-yiming-skill, 173 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Humble Header Report Analyst (rfc-st/humble, 379 stars) and Startup Design (ferdinandobons/startup-skill, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Information Security Strategy?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.