agentsclimarketplace

Nist sse

Skill jgsystemsconsulting/jgs-se-knowledge-packs/packs/nist-sse

46 agent knowledge packs distilling vetted, licence-clean systems-engineering standards (NASA, DoD, FAA, NIST, GAO, SEBoK) into on-demand Claude skills.

Install
npx -y skills add jgsystemsconsulting/jgs-se-knowledge-packs --skill nist-sse

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Knowledge base from NIST SP 800-160 Vol 1 (Engineering Trustworthy Secure Systems) and Vol 2 (Developing Cyber-Resilient Systems). Use for systems security engineering (SSE): the three SSE framework contexts (problem/solution/trustworthiness), the 30+ design principles for trustworthy secure design, trustworthiness and assurance/assurance cases, security across the ISO/IEC/IEEE 15288 life-cycle process groups, and the Vol 2 cyber-resiliency engineering framework — 4 goals (anticipate/withstand/recover/adapt), objectives, 14 techniques, implementation approaches, and design principles for the APT/adverse-conditions threat model. Bridges systems engineering and the NIST security cluster (CSF/SSDF/RMF). Does not reproduce ISO/IEC/IEEE 15288 process text, nor cover SP 800-53 control catalogs in depth.

SKILL.md

14.0 KB, as published. Nobody here has run it

<!-- argument-hint: [SSE context, design principle, trustworthiness/assurance, life-cycle process, cyber-resiliency goal/objective/technique/approach, APT, chapter number] -->

NIST SP 800-160 — Systems Security Engineering (Vol 1 + Vol 2)

Source: NIST (US Government work, public domain) | Chapters: 8

When to use

Use this skill to engineer security into a system rather than bolt it on: framing the security problem/solution/trustworthiness, applying the design principles for trustworthy secure design, building a defensible assurance case, integrating security across the system life cycle, and — for systems that must survive a capable adversary — applying cyber-resiliency goals, objectives, techniques, and approaches. This is the security-engineering bridge between systems engineering (15288/NASA/DoD SE) and the NIST security frameworks (nist-csf, nist-ssdf, RMF).

Prerequisites: none — plain Markdown; no MCP server, API key, or licence tier needed at runtime.

How to Use This Skill

  • Without arguments — load the core frameworks below: the SSE three-context framework, design principles, trustworthiness/assurance, and the cyber-resiliency framework.
  • With a topic — ask about a design principle (e.g. "least privilege", "minimal trusted elements"), trustworthiness/assurance cases, a life-cycle process, or a cyber-resiliency goal/objective/technique (e.g. "analytic monitoring", "non-persistence").
  • With a chapterch02 (SSE framework), ch03 (design principles), ch05 (cyber-resiliency framework), ch06 (techniques).

Supporting files: glossary.md, patterns.md, cheatsheet.md.

Two volumes, one discipline. Vol 1 = Engineering Trustworthy Secure Systems (the SSE foundation). Vol 2 = Developing Cyber-Resilient Systems (a specialty SSE approach for surviving the advanced persistent threat). Chapters 1–4 here cover Vol 1; chapters 5–8 cover Vol 2.

Core Frameworks & Mental Models

Systems Security Engineering (SSE) — what it is

SSE is a specialty engineering discipline applying scientific, engineering, and assurance principles to deliver systems that are trustworthy and adequately secure for their stakeholders, within cost/schedule/risk. Two anchoring ideas:

  • Security is a property of the whole system, engineered in across the life cycle — not a feature added late.
  • Adequately secure: security is asymmetric (you can observe insecurity but never prove arbitrary security), so the goal is adequate security justified by evidence, not absolute security.

The SSE Framework — Three Contexts (Vol 1)

The SSE framework organizes all security activity into three interacting contexts (not strictly sequential — they iterate and share a common base of system security analyses):

  1. Problem Context — define the security problem: stakeholder security needs, the protection needs, the adversity to be addressed, security requirements, and the security aspects of the operational environment. "What must be protected, from what, and why?"
  2. Solution Context — define and realize the security solution: security architecture and design, the security aspects of every system element, and the security-relevant decisions and trade-offs. "How is protection achieved?"
  3. Trustworthiness Context — produce the evidence that the solution is trustworthy: assurance, the assurance case, and the demonstration that claims are substantiated. "Why should anyone believe it?"

Design Principles for Trustworthy Secure Design (Vol 1, ~30+)

A catalog of principles to apply when designing for security. Key examples (not exhaustive):

PrincipleEssence
Clear AbstractionsClean, understandable interfaces; no needless complexity
Least PrivilegeEach element gets only the privileges it needs
Least Functionality / Least Persistence / Least SharingMinimize functions, lifetime, and shared resources
Minimal Trusted ElementsShrink the trusted computing base; less to trust, less to verify
Reduced ComplexitySimpler systems are more analyzable and more secure
Defense in DepthLayered, diverse protections so no single failure is fatal
Domain Separation / Hierarchical ProtectionIsolate and order protection domains
Mediated Access / Protective DefaultsControl every access; fail to a safe default
Protective Failure / Protective RecoveryFail securely; recover to a secure state
Distributed Privilege / Diversity / RedundancyNo single point of compromise; vary and duplicate
Anomaly Detection / Minimize DetectabilitySee adversary activity; deny the adversary visibility
Loss Margins / Substantiated TrustEngineer margin against loss; trust only what's evidenced

Principles split broadly into security architecture & design principles (how to structure the system) and security capability/trust principles (what protection and assurance to provide).

Trustworthiness & Assurance (Vol 1)

  • Trustworthiness = worthy of being trusted to meet defined expectations (security, plus safety, reliability, etc.); it is claimed, then substantiated, never assumed.
  • Assurance = the grounds for justified confidence that the system satisfies its security claims.
  • Assurance case = a structured argument (claims → arguments → evidence) that the security claims hold; the central artifact of the trustworthiness context. (See nasa-system-safety for the parallel claim-argument-evidence "safety case".)

Security Across the Life Cycle (Vol 1)

Vol 1 augments the ISO/IEC/IEEE 15288 system life-cycle process groups with security considerations, outcomes, and tasks. The four process groups it addresses:

  • Technical Processes — security in business/mission analysis, stakeholder needs, requirements, architecture, design, implementation, integration, V&V, transition, operation, maintenance, disposal.
  • Technical Management Processes — security in planning, assessment/control, decision, risk, configuration, information, measurement, quality.
  • Organizational Project-Enabling Processes — security in life-cycle model management, infrastructure, portfolio, human-resource, quality, knowledge management.
  • Agreement Processes — security in acquisition and supply.

(This pack names these groups and describes NIST's security augmentation in original words; it does not reproduce the ISO/IEC/IEEE 15288 process text — that's third-party copyrighted material.)

Cyber-Resiliency Engineering Framework (Vol 2)

Vol 2 is a specialty SSE approach for systems that must keep operating through compromise by an advanced persistent threat (APT) — assume the adversary is already (or will get) inside. The framework is a hierarchy:

  • 4 Goals — the highest level, from the definition of cyber resiliency:
    • Anticipate — maintain informed preparedness for adversity.
    • Withstand — continue essential mission/business functions despite adversity.
    • Recover — restore functions during and after adversity.
    • Adapt — change functions/supporting capabilities in response to predicted or actual change.
  • Objectives — more specific, assessable statements (e.g. Prevent/Avoid, Prepare, Continue, Constrain, Reconstitute, Understand, Transform, Re-Architect) that support the goals.
  • 14 Techniques — categories of capability that achieve objectives (see ch06): Adaptive Response, Analytic Monitoring, Contextual Awareness, Coordinated Protection, Deception, Diversity, Dynamic Positioning, Non-Persistence, Privilege Restriction, Realignment, Redundancy, Segmentation, Substantiated Integrity, Unpredictability.
  • Implementation Approaches — specific methods within each technique.
  • Design Principles — strategic (cross-cutting) and structural (apply to architecture/design) principles guiding selection and placement.

How it all connects to risk

Cyber resiliency reduces the mission/business risk of depending on cyber resources. It plugs into the NIST risk ecosystem — RMF (SP 800-37), controls (SP 800-53), and the organizational risk strategy — and is selected/tailored against the adversary (the APT and its attack vectors), not applied wholesale.


Chapter Index

#VolSectionKey content
ch011SSE FoundationsWhat SSE is, systems/SE concepts, "adequately secure", asymmetry of security, audience, relationship to RMF/SE
ch021The SSE Framework (3 Contexts)Problem / Solution / Trustworthiness contexts; how they interact; the common base of security analyses
ch031Design Principles for Trustworthy Secure DesignThe ~30+ principles (least privilege, minimal trusted elements, reduced complexity, defense in depth, protective failure/recovery…) and how to apply them
ch041Trustworthiness, Assurance & the Life CycleTrustworthiness vs. assurance, assurance cases (claim-argument-evidence), security across the four 15288 process groups
ch052Cyber-Resiliency Engineering FrameworkThe 4 goals (anticipate/withstand/recover/adapt), objectives, and the hierarchy goals→objectives→techniques→approaches→principles
ch062Cyber-Resiliency Techniques & ApproachesThe 14 techniques and their implementation approaches; what each defends against
ch072Cyber-Resiliency Design PrinciplesStrategic vs. structural design principles; selecting and placing resiliency in the architecture
ch082Applying Cyber Resiliency & RiskThe APT/adversary model, tailoring to mission risk, integration with RMF/SP 800-53, analysis and trade-offs

Topic Index

  • Adequately secure / asymmetry of security → ch01
  • Advanced Persistent Threat (APT) / adversary model → ch08, ch05
  • Anticipate / Withstand / Recover / Adapt (goals) → ch05, cheatsheet
  • Assurance / assurance case (claim-argument-evidence) → ch04, cheatsheet
  • Cyber-resiliency framework (hierarchy) → ch05, cheatsheet
  • Cyber-resiliency objectives → ch05
  • Cyber-resiliency techniques (the 14) → ch06, cheatsheet
  • Defense in depth → ch03
  • Design principles (trustworthy secure design) → ch03, cheatsheet
  • Design principles (cyber-resiliency: strategic/structural) → ch07, cheatsheet
  • Domain separation / hierarchical protection → ch03
  • Implementation approaches → ch06
  • ISO/IEC/IEEE 15288 process groups (security augmentation) → ch04
  • Least privilege / least functionality / least persistence / least sharing → ch03
  • Life cycle (security across) → ch04
  • Minimal trusted elements / trusted computing base → ch03
  • Problem / Solution / Trustworthiness contexts → ch02, cheatsheet
  • Protective defaults / failure / recovery → ch03
  • Reduced complexity → ch03
  • Risk management / RMF / SP 800-53 linkage → ch08, ch01
  • Trustworthiness → ch04, ch01
  • Specific techniques (Adaptive Response, Analytic Monitoring, Contextual Awareness, Coordinated Protection, Deception, Diversity, Dynamic Positioning, Non-Persistence, Privilege Restriction, Realignment, Redundancy, Segmentation, Substantiated Integrity, Unpredictability) → ch06

Supporting Files

  • glossary.md — key SSE and cyber-resiliency terms, alphabetical, with chapter references
  • patterns.md — reusable patterns (framing via the 3 contexts, applying design principles, building an assurance case, selecting cyber-resiliency techniques against an APT) with When/How/Trade-offs
  • cheatsheet.md — the 3 contexts, design-principle list, cyber-resiliency goals→objectives→techniques table, design principles, tells & smells

Scope & Limits

Covers: systems security engineering per NIST SP 800-160 Vol 1 Rev 1 and the cyber-resiliency engineering approach per Vol 2 Rev 1 — the three SSE framework contexts; the design principles for trustworthy secure design; trustworthiness, assurance, and assurance cases; the security augmentation of the ISO/IEC/IEEE 15288 life-cycle process groups (named and described, not reproduced); and the full Vol 2 cyber-resiliency framework (goals, objectives, techniques, approaches, design principles) with its APT-centric risk model.

Does not cover in depth: the ISO/IEC/IEEE 15288 process definitions themselves (third-party copyrighted — see se-standards-signpost; for open SE process models use nasa-npr-7123 / dau-se-guidebook); the SP 800-53 control catalog (referenced, not reproduced); the Risk Management Framework steps (see SP 800-37 / RMF; complemented by nist-csf); privacy engineering; and domain-specific security (cryptographic standards, network security configs).

Jurisdiction: US Government public domain work (with third-party ISO/IEC/IEEE material not reproduced here). The guidance is voluntary for non-federal organizations and broadly adoptable.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.