hack23-information-security-policy

Installation
SKILL.md

Hack23 Information Security Policy Integration Skill

Purpose

Translate the Hack23 Information Security Policy — the apex document of the Hack23 ISMS — into concrete, enforceable engineering behaviour for the CIA platform. This skill connects the high-level policy (CIA triad objectives, risk appetite, roles, legal duties) to the code, workflows, reviews, and evidence that actually implement it.

Where hack23-isms-compliance describes the framework and information-security-strategy describes the strategy, this skill tells an engineer or AI agent "given the ISP and its supporting policies, what must I do in this commit, PR, or design?"

When to Use

Apply this skill when:

  • ✅ Starting or reviewing any code / infrastructure / documentation change that touches data, authentication, authorization, crypto, logging, or third-party integrations
  • ✅ Creating or updating a GitHub issue or PR that is security-relevant
  • ✅ Onboarding a new contributor, AI agent, or repository to Hack23 standards
  • ✅ Responding to a CodeQL / SonarCloud / OWASP / Dependabot finding
  • ✅ Classifying data, designing an API, or integrating an external source
  • ✅ Preparing release notes, SBOM, SECURITY.md, or audit evidence
  • ✅ Assessing whether an AI coding agent action is policy-compliant
Installs
1
Repository
hack23/cia
GitHub Stars
234
First Seen
Jul 30, 2026
hack23-information-security-policy — hack23/cia