What problem does it solve? Organizations often lack a structured, repeatable approach to managing security and privacy risk across the system lifecycle. This Skill guides you through the NIST Risk Management Framework (SP 800-37 Rev 2) so you can build a risk management program tailored to your organization's size, sector, and risk tolerance without needing deep technical expertise. ## Core Features & Use Cases - Seven-Step RMF Guidance: Walks through Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor as a continuous cycle rather than a one-time activity. - Compliance Preparation: Maps RMF activities to requirements such as FISMA, OMB, PCI-DSS, SOX, and FedRAMP, and helps document each step for third-party audits. - Continuous Authorization Readiness: Helps organizations move toward continuous Authority to Operate (cATO) through ongoing monitoring instead of periodic re-authorization. - Use Case: A security architect launching a new system uses this Skill to categorize information impact levels, select baseline controls, and prepare an authorization package for leadership sign-off. ## Quick Start Ask the agent to guide your organization through the seven steps of the NIST Risk Management Framework for a new system, starting with the Prepare phase.