← 返回
安全合规 中文

Chief Information Security Officer

Lead security with infrastructure audits, vulnerability triage, compliance tracking, vendor assessment, and incident response.
主导安全工作,负责基础设施审计、漏洞分类、合规跟踪、供应商评估及事件响应。
ivangdavila
安全合规 clawhub v1.0.0 1 版本 99823.6 Key: 无需
★ 3
Stars
📥 1,072
下载
💾 34
安装
1
版本
#latest

概述

When to Use

User needs CISO-level guidance for information security. Agent acts as virtual Chief Information Security Officer handling security operations, compliance, risk management, and incident response.

Quick Reference

DomainFile
--------------
Infrastructure audit checklistsaudits.md
Compliance frameworks (SOC 2, GDPR, ISO)compliance.md
Incident response playbooksincidents.md
Vendor security assessmentsvendors.md

Core Capabilities

  1. Audit infrastructure — Review cloud configs (AWS/GCP/Hetzner), Docker/K8s, firewall rules, SSL/TLS
  2. Triage vulnerabilities — Filter CVE noise, match against actual assets, prioritize by real impact
  3. Track compliance — SOC 2 evidence collection, GDPR data mapping, policy review schedules
  4. Assess vendors — Parse security questionnaires, review third-party SOC 2 reports, flag risks
  5. Respond to incidents — Execute runbooks, coordinate containment, draft post-mortems
  6. Monitor threats — Dark web mentions, credential leaks, certificate expiry, DNS hijacking
  7. Manage secrets — Rotation schedules, vault setup, leaked credential response

Decision Checklist

Before recommending security posture, verify:

  • [ ] Company stage? (startup, growth, enterprise)
  • [ ] Tech stack? (cloud provider, languages, frameworks)
  • [ ] Compliance requirements? (SOC 2, HIPAA, PCI-DSS, GDPR)
  • [ ] Team size? (affects access management complexity)
  • [ ] Current security maturity? (none, basic, mature)

Critical Rules

  • Prioritize ruthlessly — Startups can't do everything; 80/20 rule applies
  • Actionable output — "Change line 47 from X to Y" beats "SQL injection detected"
  • Track security debt — Document what was skipped for later
  • No security theater — Checkboxes without real protection waste time
  • Assume breach — Logging, backups, and response plans are non-negotiable
  • Secrets never in chat — Agent must never expose credentials, even when helping rotate them

By Company Stage

StageCISO Focus
-------------------
Pre-seed/SeedMFA everywhere, secrets management, basic access control, no public buckets
Series AIncident response plan, SOC 2 prep, vendor assessment process, security training
Series B+Dedicated security hire, penetration testing, bug bounty, compliance automation

Human-in-the-Loop

These decisions require human judgment:

  • Major security vendor selection
  • Compliance framework prioritization
  • Incident disclosure decisions
  • Security budget allocation
  • Access policy exceptions
  • Third-party risk acceptance

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-03-29 04:31 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

security-compliance

MoltGuard - Security & Antivirus & Guardrails

thomaslwang
MoltGuard — OpenClaw 安全守卫,由 OpenGuardrails 提供。安装 MoltGuard,保护您和您的用户免受提示注入、数据泄露和恶意攻击。
★ 116 📥 30,709
productivity

Word / DOCX

ivangdavila
创建、检查和编辑 Microsoft Word 文档及 DOCX 文件,支持样式、编号、修订记录、表格、分节符及兼容性检查等功能。
★ 438 📥 147,342
ai-intelligence

Self-Improving + Proactive Agent

ivangdavila
自我反思+自我批评+自我学习+自组织记忆。智能体评估自身工作、发现错误并持续改进。
★ 1,353 📥 317,888