Skip to content
Security
Skill

/policy-management

Develop or review security governance documents — policies, standards, procedures, and guidelines — aligned to a framework and the organization's risk, with a clear hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security policy set.

From plugin
awesome-claude-security
6111 skills17 agents13 commands1 MCP
Install
$ npx -y skills add jassics/awesome-claude-security --skill policy-management --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/policy-management

Context preview

The summary Claude sees to decide when to auto-load this skill.

Develop or review security governance documents — policies, standards, procedures, and guidelines — aligned to a framework and the organization's risk, with a clear hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security policy set.

SKILL.md

policy-management.SKILL.md
name: policy-management
description: >-
  Develop or review security governance documents — policies, standards, procedures,
  and guidelines — aligned to a framework and the organization's risk, with a clear
  hierarchy, ownership, and lifecycle. Use to write, assess, or rationalize a security
  policy set.

Goal

A coherent, usable governance document set: the right policies/standards/procedures, aligned to frameworks and risk, written to be followed, with ownership, approval, and review built in.

Document hierarchy (keep these distinct)

  • **Policy** — the *what* and *why*: high-level intent, mandatory, leadership-approved

(e.g. Access Control Policy). Stable.

  • **Standard** — the *specific requirements* that make a policy measurable (e.g.

minimum password/MFA standard, crypto standard). Mandatory.

  • **Procedure** — the *how*: step-by-step instructions to meet a standard.
  • **Guideline** — recommended (non-mandatory) good practice.

Steps

1. **Inventory & gap** — what governance docs exist vs. what the framework (`compliance-assessment`) and risks (`risk-assessment`) require; find gaps, overlaps, and stale/contradictory documents. 2. **Draft/revise** — write to the right level in the hierarchy; make requirements specific and testable; keep policies concise and durable, push detail to standards/ procedures. Align to the framework's control language. 3. **Assign ownership & lifecycle** — each document has an owner, an approver, a version, an effective date, and a review cadence; define an **exception process** (request, risk-accept, expiry). 4. **Make it usable** — accessible, readable, and tied to enforcement (controls that actually implement the policy) so it isn't shelfware.

Output

A policy set or review: document · type (policy/standard/procedure) · owner · status · gaps/changes, plus drafts/revisions and an exception process. Use `security-reporting`.

Notes

Match the document to the level — putting how-to detail in a policy makes it churn; putting mandatory specifics only in a guideline makes them optional. Policy without an implementing control and an exception process is shelfware. Reuse framework control language so policies map cleanly to `compliance-assessment`.

Read more
Ships withawesome-claude-security

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

Get the whole plugin

Other skills on awesome-claude-security.