feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,18 +1,32 @@
---
name: conducting-cloud-incident-response
description: >
Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing
identity-based containment, cloud-native log analysis, resource isolation, and forensic
evidence acquisition adapted for ephemeral cloud infrastructure. Activates for requests
involving cloud incident response, AWS security incident, Azure compromise, GCP breach,
cloud forensics, or cloud identity compromise.
description: 'Responds to security incidents in cloud environments (AWS, Azure, GCP) by performing identity-based containment,
cloud-native log analysis, resource isolation, and forensic evidence acquisition adapted for ephemeral cloud infrastructure.
Activates for requests involving cloud incident response, AWS security incident, Azure compromise, GCP breach, cloud forensics,
or cloud identity compromise.
'
domain: cybersecurity
subdomain: incident-response
tags: [cloud-IR, AWS-forensics, Azure-incident-response, GCP-security, identity-containment]
mitre_attack: ["T1078", "T1537", "T1580", "T1525"]
tags:
- cloud-IR
- AWS-forensics
- Azure-incident-response
- GCP-security
- identity-containment
mitre_attack:
- T1078
- T1537
- T1580
- T1525
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- RS.MA-01
- RS.MA-02
- RS.AN-03
- RC.RP-01
---
# Conducting Cloud Incident Response