risk-management-framework

Guides implementation of the NIST SP 800-37 Risk Management Framework across system lifecycles.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill risk-management-framework-yogiex
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: risk-management-framework
Source: https://github.com/yogiex/opencode-cyber-security-skills/tree/main/skills/risk-management-framework
Command: npx skills add https://github.com/yogiex/opencode-cyber-security-skills --skill risk-management-framework-yogiex

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Organizations often lack a structured, repeatable approach to managing security and privacy risk across the system lifecycle. This Skill guides you through the NIST Risk Management Framework (SP 800-37 Rev 2) so you can build a risk management program tailored to your organization's size, sector, and risk tolerance without needing deep technical expertise. ## Core Features & Use Cases - Seven-Step RMF Guidance: Walks through Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor as a continuous cycle rather than a one-time activity. - Compliance Preparation: Maps RMF activities to requirements such as FISMA, OMB, PCI-DSS, SOX, and FedRAMP, and helps document each step for third-party audits. - Continuous Authorization Readiness: Helps organizations move toward continuous Authority to Operate (cATO) through ongoing monitoring instead of periodic re-authorization. - Use Case: A security architect launching a new system uses this Skill to categorize information impact levels, select baseline controls, and prepare an authorization package for leadership sign-off. ## Quick Start Ask the agent to guide your organization through the seven steps of the NIST Risk Management Framework for a new system, starting with the Prepare phase.

Frequently Asked Questions about risk-management-framework

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement the NIST Risk Management Framework?▼

Implement the RMF by following its seven steps: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. The Skill walks you through each step, starting with identifying stakeholders, critical business functions, and your organization's risk tolerance.

What are the seven steps of NIST SP 800-37 RMF?▼

The seven steps are Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. They form a continuous cycle emphasizing ongoing monitoring and risk assessment rather than a one-time compliance check.

Does RMF help with FedRAMP or PCI-DSS compliance?▼

Yes, RMF satisfies FISMA and OMB requirements and can be tailored to support other compliance needs such as PCI-DSS, SOX, and FedRAMP. The Skill helps map the required controls and document each step for auditors.

When should I not use the RMF skill?▼

Do not use it if you only need a list of technical security controls, which is the scope of NIST SP 800-53, or if you need hands-on guidance for firewalls, encryption, or server configuration. RMF also requires executive commitment to risk management.

Can RMF be applied to small organizations?▼

Yes, RMF is flexible and scalable. Small organizations with simple systems can apply a proportionally lighter implementation, adjusting depth and breadth to match their risk profile and available resources.