agentsclimarketplace

Nist pf govern

Skill onfire7777/universal-ai-skills-library/skills/nist-pf-govern

Router-first AI skill system for Codex, Claude, Cursor, Hermes, Paperclip, OpenCode, and local AI stacks: search, preflight-route, and load 1,812 skills on demand without duplicating the corpus.

Install
npx -y skills add onfire7777/universal-ai-skills-library --skill nist-pf-govern

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 13 stars13 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Implement the NIST Privacy Framework GOVERN function covering GV.AT awareness and training, GV.MT monitoring and review, GV.PO policy development, and GV.RR roles and responsibilities. Provides governance structure templates, training programs, and accountability frameworks for privacy governance.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

8.5 KB, as published. Nobody here has run it

NIST Privacy Framework — GOVERN Function

Overview

The GOVERN function establishes and monitors the organization's privacy governance structure, including policies, processes, and procedures for managing privacy risk. It is the foundational function that enables all other NIST Privacy Framework functions.

GOVERN Function Subcategories

GV.AT — Awareness and Training

Building organizational awareness and capability for privacy risk management.

SubcategoryDescriptionImplementation Guidance
GV.AT-P1The workforce is informed and trained on its roles and responsibilitiesDevelop role-based privacy training curricula. New hire training within 30 days, annual refresher for all staff.
GV.AT-P2Senior executives understand their roles and responsibilitiesExecutive briefings quarterly. Board-level privacy risk reporting semi-annually.
GV.AT-P3Privacy personnel understand their roles and responsibilitiesSpecialized training for DPOs, privacy engineers, and legal counsel. Professional certification support (CIPP, CIPM, CIPT).
GV.AT-P4Third parties (service providers, customers, partners) understand their roles and responsibilitiesInclude privacy requirements in contracts. Provide vendor privacy guidelines. Verify third-party training compliance.

GV.MT — Monitoring and Review

Ongoing assessment of privacy governance effectiveness.

SubcategoryDescriptionImplementation Guidance
GV.MT-P1Privacy risk is re-assessed on an ongoing basis and as key factors changeTrigger-based reassessment: new processing activities, regulatory changes, incidents, organizational changes.
GV.MT-P2Privacy risk management activities are periodically reviewedConduct quarterly operational reviews and annual strategic reviews. Benchmark against industry peers.
GV.MT-P3Privacy policies, processes, and procedures are maintained and used to manage privacy riskVersion control for all privacy documentation. Annual policy review cycle with defined approval workflow.
GV.MT-P4Privacy risk assessment results are shared with stakeholdersDistribute risk dashboards to executive leadership monthly. Share relevant findings with operational teams weekly.

GV.PO — Policy

Privacy policies governing organizational approach to privacy risk management.

SubcategoryDescriptionImplementation Guidance
GV.PO-P1Organizational privacy values and policies are established and communicatedPublish a privacy mission statement. Develop comprehensive privacy policy suite aligned with organizational values.
GV.PO-P2Processes to instill organizational privacy values within data processing activities are establishedEmbed privacy requirements into SDLC. Require privacy review at design stage for all new data processing.
GV.PO-P3Roles and responsibilities for privacy workforce are establishedDefine RACI matrices for privacy functions. Document authority levels and escalation paths.
GV.PO-P4Privacy is integrated into organizational risk managementInclude privacy in enterprise risk register. Align privacy risk appetite with organizational risk tolerance.
GV.PO-P5Legal, regulatory, and contractual requirements regarding privacy are understood and managedMaintain regulatory tracking register. Map obligations to controls. Conduct annual compliance assessments.
GV.PO-P6Governance and risk management policies address privacy risksPrivacy risk addressed in board risk committee charter. Executive-level accountability for privacy.

GV.RR — Roles and Responsibilities

Establishing accountability structures for privacy risk management.

SubcategoryDescriptionImplementation Guidance
GV.RR-P1Organizational leadership is responsible and accountable for privacy riskC-suite privacy accountability documented. Chief Privacy Officer reports to CEO or General Counsel.
GV.RR-P2Adequate resources for privacy programs are allocatedAnnual privacy budget planning. Headcount planning for privacy team. Technology investment for privacy tools.
GV.RR-P3Processes are in place to determine, assess, and manage privacy risksFormal privacy risk management methodology adopted. Standard operating procedures for risk assessment.

Governance Structure Template

Organizational Hierarchy

Board of Directors / Audit Committee
    |
Chief Executive Officer
    |
Chief Privacy Officer (CPO) / Data Protection Officer (DPO)
    |
    +-- Privacy Legal Counsel
    +-- Privacy Engineering Lead
    +-- Privacy Operations Manager
    +-- Privacy Compliance Analyst
    |
Business Unit Privacy Champions (distributed model)

RACI Matrix for Key Privacy Activities

ActivityCPO/DPOLegalEngineeringBusiness UnitsExecutive
Privacy strategyACCIR
Policy developmentRRCCA
DPIA executionACRRI
Incident responseRRCCI
Training deliveryACIRI
Regulatory monitoringCRIIA
Vendor assessmentARCRI
Metrics reportingRICCA

R = Responsible, A = Accountable, C = Consulted, I = Informed

Training Program Framework

Tier 1 — General Awareness (All Staff)

  • Frequency: Annual, plus new hire onboarding
  • Duration: 45 minutes
  • Topics: Privacy principles, data handling basics, incident reporting, individual rights
  • Assessment: Quiz with 80% pass threshold

Tier 2 — Role-Specific (Data Handlers)

  • Frequency: Semi-annual
  • Duration: 2 hours
  • Topics: Data classification, access controls, secure processing, retention schedules
  • Assessment: Scenario-based exercises

Tier 3 — Specialist (Privacy Team)

  • Frequency: Quarterly
  • Duration: 4 hours
  • Topics: Regulatory updates, advanced risk assessment, PET implementation, incident management
  • Assessment: Practical exercises and case studies

Tier 4 — Executive (Leadership)

  • Frequency: Semi-annual
  • Duration: 1 hour
  • Topics: Privacy risk landscape, regulatory exposure, strategic alignment, board reporting
  • Assessment: N/A (discussion-based)

Policy Suite Inventory

PolicyOwnerReview CycleApproval Authority
Enterprise Privacy PolicyCPOAnnualCEO
Data Classification PolicyCISO/CPOAnnualCTO
Data Retention PolicyCPOAnnualGeneral Counsel
Data Subject Rights PolicyCPOAnnualGeneral Counsel
Privacy Incident Response PolicyCPOSemi-AnnualCISO
Third-Party Data Processing PolicyCPOAnnualProcurement Lead
Cross-Border Transfer PolicyLegalAnnualGeneral Counsel
Cookie and Tracking PolicyCPOSemi-AnnualCMO
Employee Privacy PolicyCPO/HRAnnualCHRO
Privacy-by-Design StandardsPrivacy EngineeringAnnualCTO

Control Mapping

NIST PF GOVERNISO 27701GDPR ArticleSOC 2 TSC
GV.AT-P17.2.2Art. 39(1)(b)CC1.4
GV.AT-P25.1Art. 38(3)CC1.2
GV.MT-P19.1Art. 24(1)CC4.1
GV.MT-P35.2Art. 24(2)CC1.3
GV.PO-P15.2Art. 5(1)CC1.1
GV.PO-P45.3.2Art. 24(1)CC3.1
GV.PO-P55.2.1Art. 5(1)(a)CC2.2
GV.RR-P15.3Art. 37-39CC1.2
GV.RR-P27.1Art. 38(2)CC1.1

References

  • NIST Privacy Framework Version 1.0 (January 16, 2020)
  • NIST SP 800-53 Rev. 5 — Security and Privacy Controls (PM family)
  • ISO/IEC 27701:2019 — Clause 5 (PIMS-specific requirements)
  • IAPP CIPM Body of Knowledge — Privacy Program Management

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.