
Classified Cyber Security Senior Manager
- 29 installs
- 7 repo stars
- Updated May 20, 2026
- daemon-blockint-tech/agentic-enteprises-skill
Govern classified and high-side cyber programs: authorization milestones, cleared workforce alignment, insider risk, and government incident escalation.
About
Guides senior management of classified and high-side cyber programs covering cleared workforce alignment, RMF/ATO authorization interfaces, insider risk, government escalation, and inspection readiness. A developer or manager uses it to govern classified cyber posture.
- Governs classified cyber programs, milestones, and RACI
- RMF/ATO authorization interfaces and government incident escalation
Classified Cyber Security Senior Manager by the numbers
- 29 all-time installs (skills.sh)
- Ranked #1,502 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill classified-cyber-security-senior-managerAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 29 |
|---|---|
| repo stars | ★ 7 |
| Last updated | May 20, 2026 |
| Repository | daemon-blockint-tech/agentic-enteprises-skill ↗ |
What it does
Govern classified and high-side cyber programs: authorization milestones, cleared workforce alignment, insider risk, and government incident escalation.
Files
Classified Cyber Security Senior Manager
When to Use
- Govern classified or high-side cyber programs — scope, milestones, RACI, and interfaces to security, IT, and mission owners
- Align cleared workforce and facility posture with cyber requirements — access eligibility themes, visit coordination, high-level continuous evaluation interfaces (not adjudication)
- Coordinate program security plans and system security plans at manager depth — boundaries, inherited controls, plan of action themes, reauthorization cadence
- Interface with authorization officials, ISSOs, and assessors — package status, significant changes, risk acceptance themes (delegate SSP/POA&M maintenance to
information-systems-security-officer-classified-specialist) - Coordinate insider risk with HR, security, and legal — policy alignment, case routing, need-to-know and privileged access themes
- Oversee classified network operations interfaces — change windows, maintenance, cross-domain policy themes, operations center escalation paths
- Escalate incidents to government stakeholders — classification of facts, clock management interfaces, coordinated comms with legal and contracts
- Prepare for audits, inspections, and continuous monitoring — evidence themes, corrective action plans, recurring findings
- Manage classified IT supply chain — approved products, configuration baselines, vendor and subcontractor cyber flow-down
- Brief senior leadership and authorizing officials — posture narrative, top risks, decisions, and resource asks
When NOT to Use
- Triage and close routine SOC alerts →
soc-analyst - Run CSIRT containment, forensics collection, or technical IR playbooks →
incident-responder - Board-level enterprise security strategy, risk appetite, and cyber insurance →
chief-information-security-officer - Deploy controls, SIEM rules, IAM, or remediate findings →
information-security-engineer - Commercial-only cloud compliance mapping and audit packs →
cloud-compliance-specialist - Enterprise reference architecture, zero-trust patterns, ARB standards →
enterprise-security-architect - Build risk registers, FAIR models, or treatment scoring →
security-risk-analyst - GRC program scope, framework mapping, commercial audit prep →
compliance-specialist - SSP maintenance, control status, assessor coordination, POA&M ownership →
information-systems-security-officer-classified-specialist - M&A or investment diligence cyber packs →
cyber-diligence-governance - Legal classification, export, or jurisdiction decisions → route legal/compliance; do not decide in this skill
- CISSP study or certification exam prep →
certified-information-systems-security-professional
Related skills
| Need | Skill |
|---|---|
| Enterprise board strategy, appetite, budget narrative | chief-information-security-officer |
| Control implementation, tooling, hardening | information-security-engineer |
| GRC program, frameworks, commercial audit coordination | compliance-specialist |
| ISSO SSP, POA&M, assessor coordination (system level) | information-systems-security-officer-classified-specialist |
| Enterprise security reference architecture | enterprise-security-architect |
| Declared incident response execution | incident-responder |
| SOC alert triage and shift operations | soc-analyst |
| Risk registers, inherent/residual, treatment | security-risk-analyst |
| M&A/investment diligence and IC cyber packs | cyber-diligence-governance |
| Security certification study prep | certified-information-systems-security-professional |
Core Workflows
1. Scope and program boundary
Clarify authority, classified enclave boundaries, and handoffs to engineering, GRC, IR, and mission owners.
See `references/classified_cyber_senior_manager_scope.md`.
2. Cleared program and personnel security interfaces
Workforce eligibility themes, facility alignment, visit coordination, and personnel security case routing.
See `references/cleared_program_and_personnel_security.md`.
3. Accreditation and authorization interfaces
RMF/ATO-style lifecycle at manager depth — boundaries, inherited controls, significant changes, reauthorization.
See `references/accreditation_and_authorization_interfaces.md`.
4. Classified operations and incident escalation
Operations interfaces, maintenance governance, cross-domain themes, and government stakeholder escalation.
See `references/classified_operations_and_incident_escalation.md`.
5. Audit, inspection, and continuous monitoring
Inspection readiness, POA&M themes, recurring findings, and continuous monitoring interfaces.
See `references/audit_inspection_and_continuous_monitoring.md`.
6. Stakeholder briefings and governance
Authorizing official briefings, leadership dashboards, committee cadence, and decision records.
See `references/stakeholder_briefings_and_governance.md`.
Outputs
- Program governance charter — scope, RACI, committees, escalation paths
- Authorization status brief — boundary, milestones, open risks, significant changes pending
- Inspection readiness pack — evidence themes, gaps, POA&M summary, owners and dates
- Incident escalation brief — facts (classified handling per policy), clocks, government interfaces, decisions needed
- Classified supply chain memo — approved products, vendor flow-down, open supply-chain risks
- Leadership briefing — posture, top 5 risks, resource asks, decisions for authorizing officials
Principles
- Manager lens — set direction, interfaces, and accountability; delegate technical execution
- Boundary discipline — enclave scope, data flows, and inherited controls explicit in every narrative
- Government alignment — early engagement on incidents, changes, and inspection themes
- Need-to-know in artifacts — minimum necessary detail; route legal/classification questions out of band
- Evidence over assertion — tie briefings to authorization status, monitoring, and POA&M facts
- Complement, not duplicate — pair with CISO for enterprise strategy; with IR for technical response
When to load references
- Role boundary and handoffs →
references/classified_cyber_senior_manager_scope.md - Cleared workforce and personnel security →
references/cleared_program_and_personnel_security.md - Accreditation and authorization →
references/accreditation_and_authorization_interfaces.md - Operations and incident escalation →
references/classified_operations_and_incident_escalation.md - Audit and continuous monitoring →
references/audit_inspection_and_continuous_monitoring.md - Briefings and governance →
references/stakeholder_briefings_and_governance.md
Accreditation and authorization interfaces
Table of contents
1. Manager-level RMF/ATO lens 2. Authorization boundary 3. Lifecycle milestones 4. Inherited controls and dependencies 5. Significant change and continuous monitoring 6. Assessor and ISSO interfaces
Manager-level RMF/ATO lens
At senior manager depth, focus on:
- Authorization boundary — what is in vs out of the package
- Status — authorized, interim, denied, or in progress
- Top risks — POA&M themes, not every control ID
- Decisions — risk acceptance, resources, schedule
Defer control-by-control assessment to ISSOs, assessors, and engineers—summarize impact for leadership.
Authorization boundary
Document for each system or enclave:
| Element | Question |
|---|---|
| System name and mission | What business/mission outcome does it support? |
| Boundary diagram (reference) | Where is the authorization boundary drawn? |
| Data types | Classification per org policy; aggregation rules |
| Interconnections | Other systems, cross-domain, remote admin paths |
| Common controls | Inherited from org provider or parent system? |
Significant change candidates: new interconnection, major version, cloud shift, privileged path change, new data category.
Lifecycle milestones
Typical phases (labels vary by organization):
| Phase | Manager deliverable |
|---|---|
| Categorize | Confirm impact level aligns with mission and data |
| Select | Control baseline agreed; tailoring documented at summary |
| Implement | POA&M burn-down; resource plan for gaps |
| Assess | Entry/exit criteria for assessment; open finding triage |
| Authorize | Decision brief for authorizing official |
| Monitor | ConMon metrics, recurring findings, reauth date |
Track reauthorization date and interim authorization conditions explicitly in status reports.
Inherited controls and dependencies
| Type | Risk if weak |
|---|---|
| Identity provider | Account lifecycle gaps affect all systems |
| Enterprise logging | Cannot support incident or inspection evidence |
| Vulnerability management | Inherited scan coverage holes |
| Physical / personnel | Inherited PS controls out of date |
For each dependency: owner, last assessment date, open POA&M count, and escalation path.
Significant change and continuous monitoring
Significant change board (concept):
1. Change description and mission impact 2. Security impact analysis summary (from ISSO/engineering) 3. Updated boundary or data flow if needed 4. Authorizing official notification if required 5. POA&M updates before production
Continuous monitoring themes: vulnerability scan cadence, configuration drift, privileged access review, contingency test dates.
Assessor and ISSO interfaces
| Meeting | Manager prepares |
|---|---|
| Weekly ISSO sync | POA&M velocity, blockers, resource asks |
| Pre-assessment | Evidence plan; known gaps with dates |
| Assessment exit | Finding severity rollup; accept/mitigate plan |
| Authorizing official read-ahead | One-page decision memo |
Escalate conflicting assessor positions early—do not let findings accumulate without owner.
Audit, inspection, and continuous monitoring
Table of contents
1. Inspection types 2. Readiness framework 3. POA&M governance 4. Evidence themes 5. Recurring findings 6. Continuous monitoring interfaces
Inspection types
| Type | Manager focus |
|---|---|
| Authorization assessment | Coordinate with ISSO; resource evidence owners |
| Customer / government oversight | Single narrative; no contradictory status across teams |
| Supply chain / vendor review | Flow-down artifacts, approved product list |
| Physical / personnel cross-walk | Close gaps between facility and cyber access lists |
| Tabletop / contingency exercise | After-action POA&M entries |
Distinguish findings (assessment) from observations (lower severity)—track both with owners.
Readiness framework
90-day inspection prep (example cadence):
| Week block | Activity |
|---|---|
| T-90 | Gap assessment against last assessment letter |
| T-60 | POA&M realism review; stop impossible dates |
| T-30 | Mock interviews; evidence spot-check |
| T-14 | Executive read-ahead; open risk acceptances |
| T-0 | Single control room for assessor questions |
Assign evidence stewards per control family; avoid heroics the week of visit.
POA&M governance
| Field | Manager scrutiny |
|---|---|
| Weakness description | Tied to control and mission impact |
| Milestones | Dated; resourced |
| Risk level | Aligns with authorizing official thresholds |
| Dependencies | Blocked items escalated weekly |
| Closure evidence | ISSO validates before manager signs rollup |
Report velocity (opened vs closed) and aged items over 180 days.
Evidence themes
Organize evidence by theme, not file dump:
- Access control (provisioning, review, termination samples)
- Audit logging (retention, review cadence)
- Configuration management (baseline, drift response)
- Contingency (test dates, results summary)
- Identification and authentication (MFA, privileged access)
- System and communications protection (boundary, encryption themes per policy)
- Supply chain (approved products, vendor attestations)
Use compliance-specialist for commercial framework mapping; keep classified evidence in approved repositories per policy.
Recurring findings
For repeat issues:
1. Root cause category (people, process, tool, funding) 2. Systemic fix vs local fix 3. Metric to prove sustained closure (e.g., % accounts recertified on time) 4. Executive sponsor if cross-organization
Escalate third recurrence to authorizing official briefing.
Continuous monitoring interfaces
| Feed | Manager question |
|---|---|
| Vulnerability management | Mean time to remediate for high/critical on classified assets |
| Configuration compliance | Drift count trend |
| Privileged access | Quarterly review completion rate |
| Log review | SOC coverage of classified enclave (interface with soc-analyst) |
| Threat intelligence | Applicable notices acted upon |
Summarize monthly for leadership; tie spikes to POA&M and resource asks.
Classified cyber security senior manager scope
Table of contents
1. Role boundary 2. Program types 3. Questions this role answers 4. Handoffs
Role boundary
| classified-cyber-security-senior-manager | Partner |
|---|---|
| Classified program governance, authorization interfaces, inspection readiness | information-security-engineer — control implementation, SIEM, hardening |
| Government stakeholder escalation themes, ops interfaces | incident-responder — CSIRT execution, containment, forensics |
| Cleared workforce/facility cyber alignment (high level) | soc-analyst — alert triage, shift operations |
| Authorization package status, significant changes | information-systems-security-officer-classified-specialist — SSP, POA&M, assessor coordination |
| Reference architecture, patterns, ARB exceptions | enterprise-security-architect — standards and design authority |
| Classified supply chain and vendor flow-down | compliance-specialist — commercial GRC, framework mapping |
| Enterprise board strategy, appetite, insurance | chief-information-security-officer — exec program and board narrative |
| Risk registers and quantitative treatment | security-risk-analyst — scoring, FAIR, registers |
This role governs classified cyber programs and interfaces with authorizing officials; it does not operate consoles, write detection rules, or perform assessor-level control testing.
Program types
Typical environments (generic labels only):
| Environment | Manager focus |
|---|---|
| Classified enclave / high-side network | Boundary, operations interfaces, change governance |
| Defense industrial base program | Contract flow-down, visitor/access themes, subcontractor cyber |
| Multi-level security or compartmented workloads | Data flow policy, cross-domain governance themes |
| Shared services into classified mission systems | Inherited controls, dependency risk, SLA for security services |
Document: system name, classification level (per org policy), authorization status, and owning mission.
Questions this role answers
- What is in scope for this classified cyber program, and who owns each interface?
- Are we on track for authorization milestones, and what decisions do authorizing officials need?
- What must we tell government stakeholders after a suspected or confirmed incident?
- Are we inspection-ready, and what POA&M items block a clean assessment?
- Is cleared workforce and facility posture aligned with cyber access requirements?
- Is classified IT supply chain controlled (approved products, config baselines, vendor attestations)?
Handoffs
| After decision | Owner |
|---|---|
| Implement control or remediate finding | information-security-engineer |
| Maintain SSP, POA&M, assessor evidence | information-systems-security-officer-classified-specialist |
| Execute incident containment and timeline | incident-responder |
| Draft commercial audit evidence packs | compliance-specialist |
| Board-level enterprise risk narrative | chief-information-security-officer |
| Architecture standard or pattern exception | enterprise-security-architect |
| Legal classification or export question | Legal/compliance (out of band) |
Classified operations and incident escalation
Table of contents
1. Operations interfaces 2. Change and maintenance governance 3. Cross-domain and data flow themes 4. Incident classification and escalation 5. Government stakeholder communication 6. Handoff to incident-responder
Operations interfaces
| Interface | Senior manager role |
|---|---|
| Classified NOC / ops center | Define escalation tiers; approve maintenance windows affecting security controls |
| Mission owners | Align outage vs security control downtime |
| Engineering / platform | Change advisory for security-relevant releases |
| Help desk | Route classified incidents to CSIRT path; no ad-hoc admin passwords |
Maintain an operations calendar overlay: patches, cert renewals, DR tests, assessor visits.
Change and maintenance governance
Change categories (example):
| Category | Approval theme |
|---|---|
| Routine patch | Pre-approved window; rollback plan |
| Control-affecting | ISSO review; may trigger significant change |
| Emergency | Document after-action; government notify if contract requires |
Require: maintenance notice, backout, security control validation checklist (summary), and comms to mission.
Cross-domain and data flow themes
At manager depth—do not design technical guards here:
- Approved transfer mechanisms only (organization policy names only)
- No ad-hoc removable media without policy exception
- Remote administration paths documented in authorization package
- Wireless and mobile excluded unless explicitly authorized
Escalate policy exceptions with risk memo and authorizing official awareness.
Incident classification and escalation
| Stage | Manager action |
|---|---|
| Suspected event | Confirm classified handling; activate program incident cell |
| Declaration | Align severity with mission and data impact; assign executive sponsor |
| Containment direction | Authorize account isolation themes; delegate execution to IR |
| Evidence | Legal hold and log preservation themes; chain of custody to IR/forensics |
| Recovery | Prioritize mission restoration vs forensic needs—document trade-off |
Clocks: contract notification windows, government reporting interfaces, internal exec cadence—coordinate with legal and contracts; do not invent deadlines.
Government stakeholder communication
Prepare fact packs (minimum necessary):
- What happened (unclassified summary if allowed; otherwise per classification guide)
- Systems and data in scope (boundary reference)
- Current status: contained / investigating / recovered
- Preliminary root cause themes (not final until validated)
- Actions taken and next 24–72 hours
- Decisions needed from government (access, inspection deferral, additional resources)
Route wording through legal and contracts before external send.
Handoff to incident-responder
| classified-cyber-security-senior-manager | incident-responder |
|---|---|
| Stakeholder map, government interfaces | Timeline, containment playbooks |
| Resource and priority decisions | Technical investigation |
| Briefings to leadership and AO | Evidence preservation execution |
| POA&M linkage for systemic fixes | Post-incident review facilitation support |
After stabilization, manager owns inspection and authorization impact (new POA&M, significant change, reauth timing).
Cleared program and personnel security interfaces
Table of contents
1. Purpose 2. Workforce eligibility themes 3. Facility and physical alignment 4. Access and visit coordination 5. Insider risk coordination 6. Interfaces and RACI
Purpose
Cyber senior managers align classified IT access with personnel security outcomes—they do not adjudicate clearances or conduct background investigations.
Workforce eligibility themes
| Theme | Manager action |
|---|---|
| Access eligibility vs need-to-know | Confirm role-based access matches mission need; challenge standing access |
| Continuous evaluation signals | Route anomalies to personnel security; suspend access per policy pending review |
| Foreign travel / contact reporting | Ensure cyber accounts reflect HR/security holds; no technical bypass |
| Termination and transfer | Same-day disable themes; recertify privileged access after role change |
| Contractor vs employee | Flow-down clauses; verify sponsor and contract scope before account provisioning |
Maintain a role-to-system matrix at summary level; detail lives with identity and personnel security teams.
Facility and physical alignment
| Interface | Cyber manager concern |
|---|---|
| Open storage / SCIF adjacency | Network segmentation and wireless policy alignment |
| Visitor control | No ad-hoc network drops; guest wireless isolated or absent |
| Equipment accountability | Asset tags tied to configuration management |
| COMSEC / key material (if applicable) | Separate from general IT; document interfaces only |
Escalate physical-security gaps that imply cyber exposure (uncontrolled ports, unapproved wireless).
Access and visit coordination
Visit requests: confirm sponsor, dates, escort, and whether cyber access (accounts, VPN, lab) is in scope.
Remote access: dual control themes—MFA, managed device, session logging per policy; no consumer tools on classified paths.
Cross-program access: document data owner approval before granting cross-enclave read paths.
Insider risk coordination
Coordinate with insider-threat program, HR, legal, and security:
| Signal | Response theme |
|---|---|
| Policy violations on classified systems | Preserve logs per legal hold; route to insider program |
| Privileged misuse | Emergency access revocation; incident-responder if active attack |
| Data exfiltration indicators | Classified incident path; government notification interface |
| Workplace conduct + cyber access | Personnel security lead; cyber disables access per direction |
Do not run investigations alone—maintain need-to-know in briefings.
Interfaces and RACI
| Function | Typical owner | Cyber senior manager |
|---|---|---|
| Clearance adjudication | Personnel security | Informed; escalates misalignment |
| Account provisioning | Identity / IT | Approver for classified systems list |
| Insider case management | Insider threat / security | Contributor for technical facts |
| Facility security | Physical security | Coordinate on cyber-physical gaps |
| Legal / classification | Legal | Route questions; do not classify data in chat |
Stakeholder briefings and governance
Table of contents
1. Governance forums 2. Authorizing official briefing 3. Senior leadership narrative 4. Metrics and dashboards 5. Decision records 6. Complement to CISO
Governance forums
| Forum | Cadence | Cyber senior manager role |
|---|---|---|
| Classified program board | Monthly | Chair or co-chair; track milestones and risks |
| Authorization working group | Biweekly | Status rollup; significant change queue |
| Insider risk steering | Quarterly | Cyber access themes; case trends (aggregated) |
| Supply chain council | Quarterly | Classified IT product and vendor risks |
| Incident executive cell | As needed | Stakeholder map; government interface |
Document RACI for: risk acceptance, emergency change, external notification, and POA&M deferrals.
Authorizing official briefing
One-page structure:
1. Authorization status — system/enclave, date, interim conditions 2. Posture summary — green/amber/red themes with evidence pointer 3. Top risks (≤5) — mission impact; POA&M or risk acceptance status 4. Significant changes — in flight or recently deployed 5. Incidents — since last brief; government notifications complete/pending 6. Inspection — next event; readiness gaps 7. Decisions needed — resources, risk acceptance, schedule, scope
Attach appendix only when AO requests detail—default to minimum necessary classification.
Senior leadership narrative
Align with chief-information-security-officer when briefing enterprise execs:
| Topic | Classified program manager owns | CISO owns |
|---|---|---|
| Enclave authorization and inspection | Yes | Informed |
| Enterprise risk appetite | Input | Yes |
| Board-ready cyber insurance | Input | Yes |
| Cross-enclave incident with reputational impact | Co-brief | Lead external narrative |
Use plain language for non-cleared executives; separate classified annex per policy.
Metrics and dashboards
| Metric | Purpose |
|---|---|
| POA&M open / closed / aged | Inspection and authorization credibility |
| Authorization days to milestone | Program predictability |
| Privileged accounts without recent review | Access hygiene |
| Mean time to remediate (classified tier) | ConMon health |
| Significant changes pending AO | Decision backlog |
| Supply chain open risks | Classified IT integrity |
Avoid vanity metrics (ticket counts). Pair with security-risk-analyst for enterprise risk register linkage.
Decision records
Record for audit trail:
- Risk acceptance (owner, date, expiration, compensating controls summary)
- Significant change approval
- Emergency change authorization
- Government notification sent (reference number if applicable)
- Resource allocation shifts
Store in program repository per records management policy.
Complement to CISO
Use chief-information-security-officer for enterprise strategy, board cadence, and risk appetite.
Use classified-cyber-security-senior-manager for enclave authorization, cleared-program interfaces, government oversight, and classified supply chain.
Hand off technical execution to information-security-engineer and active IR to incident-responder in all cases.