Project overview
risk-register-csf builds a compact security program from an asset inventory, a NIST CSF 2.0 self-assessment, a living risk register, and a lightweight incident-response plan. It scores likelihood and impact deterministically, assigns owners, treatments, target states, and review dates, and keeps required runbooks for data exposure and account compromise. Re-assessment diffs prior artifacts and forces overdue open risks back to an explicit decision.
Repository facts
- Primary language
- Python
- License
- MIT
- Repository updated
- Jun 23, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacyFinance, legal and compliance
Platforms
Claude Code, Codex, and more
Capabilities
Verification and evals
Audience
DevelopersOperations teams