enterprise-security-exception-review
Installation
SKILL.md
Enterprise Security Exception Review
Use this skill to convert enterprise security exception, compensating control, customer requirement, risk acceptance, expiry, and remediation questions into a concrete artifact with owners, gates, metrics, and recovery paths.
Workflow
- Identify customer request, control requirement, current standard, gap, affected data, contract impact, compensating controls, owner, expiry need, and remediation feasibility.
- Read
references/enterprise-security-exception-patterns.md. - Classify exception as no-exception-needed, documentation gap, customer-specific config, compensating control, risk acceptance, roadmap request, contract redline, or non-acceptable risk.
- Define approval owner, evidence, compensating control, customer communication, expiry, renewal review, remediation plan, and support/runbook impact.
- Produce exception review, state machine, decision table, event schema, risk checklist, and customer response plan.
When not to use
- Do not use for generic advice the base model already handles without this skill's specific artifact contract.