Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Information Systems Security Officer Classified Specialist

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides ISSO work for classified systems: system security plan stewardship, control status and POA&M tracking, continuous monitoring, and authorization (ATO) packages.

About

Guides Information Systems Security Officer work for classified systems and enclaves, covering SSP stewardship, control status and POA&M management, continuous monitoring, assessor coordination, and ATO packages. An ISSO uses it when maintaining SSPs, supporting A&A/RMF, or coordinating control inheritance.

  • SSP scope, control narratives, and inheritance stewardship
  • POA&M management with milestones, risk ratings, and closure evidence

Information Systems Security Officer Classified Specialist by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill information-systems-security-officer-classified-specialist

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides ISSO work for classified systems: system security plan stewardship, control status and POA&M tracking, continuous monitoring, and authorization (ATO) packages.

Files

SKILL.mdMarkdownGitHub ↗

Information Systems Security Officer (ISSO) — Classified Specialist

When to Use

  • Steward the system security plan (SSP) — scope, boundaries, control narratives, inheritance
  • Track control implementation status and evidence pointers for the authorization boundary
  • Operate continuous monitoring — ongoing control effectiveness, significant changes, deviations
  • Manage POA&M entries — milestones, risk ratings, closure evidence, assessor questions
  • Support assessment and authorization — readiness packages, assessor requests, remediation plans
  • Analyze change impact on security posture — patches, architecture, data flows, interconnections
  • Interface with vulnerability management — scan cadence, findings triage, POA&M linkage
  • Report security incidents and anomalies to ISSM, PM, or AO per program procedures
  • Document classified boundaries and interconnections at the documentation level (not engineering design)
  • Coordinate inheritance from common controls, leveraged authorizations, and shared services

When NOT to Use

  • Lead the entire classified cyber portfolio, staffing, or multi-system program → classified-cyber-security-senior-manager
  • Set enterprise security strategy, board briefings, or risk appetite → chief-information-security-officer
  • Triage SOC alerts or run shift operations → soc-analyst
  • Command active incident response, containment, or forensics → incident-responder
  • Deploy IAM, SIEM, EDR, hardening, or remediate technical findings → information-security-engineer
  • Build enterprise audit evidence pipelines or automate SOC 2/ISO control tests → compliance-engineer
  • Own enterprise GRC program charter, framework scope, or vendor questionnaire programs → compliance-specialist
  • Define enterprise reference architecture, zero-trust patterns, or ARB standards → enterprise-security-architect
  • Build FAIR-style risk registers and treatment scoring → security-risk-analyst
  • Study for CISSP certification without system authorization work → certified-information-systems-security-professional

Related skills

NeedSkill
Classified portfolio program managementclassified-cyber-security-senior-manager
Executive security strategy and board reportingchief-information-security-officer
Enterprise GRC scope, gap plans, audit prepcompliance-specialist
Technical control mapping and evidence automationcompliance-engineer
Control implementation and toolinginformation-security-engineer
Enterprise security reference architectureenterprise-security-architect
Declared incident response executionincident-responder
Risk registers and residual risk scoringsecurity-risk-analyst

Core Workflows

1. Establish system context

1. Confirm authorization boundary, classification level, and data categories in scope 2. Identify system owner, ISSM, AO, and assessor points of contact 3. Map inherited vs system-specific controls and leveraged authorizations 4. Load current SSP, POA&M, and last authorization decision artifacts

See `references/isso_classified_scope.md`.

2. SSP and control inheritance

1. Align SSP sections with program templates (boundary, architecture, controls, procedures) 2. Document control inheritance from common control providers with pointers, not duplication 3. Keep control narratives testable — who, what frequency, evidence location 4. Flag gaps between as-implemented state and selected baseline

See `references/ssp_and_control_inheritance.md`.

3. Continuous monitoring and POA&M

1. Run monthly (or program-defined) control effectiveness checks 2. Record significant changes and security-relevant events in the monitoring plan 3. Open, update, and close POA&M items with verifiable milestones 4. Escalate overdue or high-risk POA&M items to ISSM and system owner

See `references/continuous_monitoring_and_poams.md`.

4. Assessment and authorization support

1. Prepare authorization package index — SSP, SAP, SAR inputs, POA&M, contingency plans 2. Track assessor data calls and evidence due dates 3. Draft remediation plans for findings with realistic dates and owners 4. Support AO decision briefs — residual risk, POA&M acceptability, continuous monitoring commitment

See `references/assessment_and_authorization_support.md`.

5. Classified boundaries and operations

1. Maintain documentation-level boundary and interconnection diagrams (no export-controlled detail) 2. Apply program rules for classified processing, storage, and transmission at a high level 3. Coordinate cross-domain or controlled interface changes through designated authorities 4. Align physical, personnel, and technical security references in SSP without duplicating classified specs

See `references/classified_boundaries_and_operations.md`.

6. Stakeholder coordination and reporting

1. Run cadence with system owner, ISSM, AO staff, and control implementers 2. Report incidents and security-relevant events per program timelines 3. Brief leadership on posture, POA&M aging, and authorization risk between assessments 4. Hand off engineering work to implementers; retain package ownership and traceability

See `references/stakeholder_coordination_and_reporting.md`.

Output Standards

  • Use program templates for SSP updates, POA&M rows, and authorization correspondence
  • Cite control IDs, evidence locations, and dates — avoid unattributed status claims
  • Mark classification of deliverables per program marking guidance; do not paste classified content into unclassified channels
  • Separate facts (scan dates, finding counts) from judgments (residual risk recommendations)
  • Do not provide legal conclusions, attest on behalf of the AO, or substitute for official security classification guidance

Reference Files

FileUse when
references/isso_classified_scope.mdRole boundaries, RACI, minimum artifacts
references/ssp_and_control_inheritance.mdSSP structure, inheritance, narratives
references/continuous_monitoring_and_poams.mdConMon cadence, POA&M lifecycle
references/assessment_and_authorization_support.mdA&A packages, assessor coordination
references/classified_boundaries_and_operations.mdBoundaries, cross-domain, classified ops
references/stakeholder_coordination_and_reporting.mdISSM/AO/PM reporting and cadence

Related skills

Securitycomplianceaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.