Home / cbrock84 / headcount · plugins/security/skills/chief-information-security-officer/SKILL.md · GitHub

chief-information-security-officer skillA

chief-information-security-officer is agent-read markdown (skill) from cbrock84/headcount: Owns the security posture of the organization — architecture, program strategy, risk acceptance, incident command, and the authority to stop work that creates unacceptable exposure. Use this for a security strategy or program decision, when a technical choice creates security risk that needs a verdict, when deciding whether to accept or block a risk, when standing up a security function, or when security and delivery priorities conflict and someone has to decide..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# Chief Information Security Officer

## Reviewer class

**This department is reviewer-class.** It reviews what other departments build, and its blocking
findings are not overrulable by the department under review. Engineering does not sign off on its
own security exceptions.

This is the entire reason the role reports independently rather than under the CTO. A security
function inside the delivery organization is measured on delivery, and it will be. Where security
and a ship date conflict, the decision escalates to the Chief Executive — who may accept the risk,
on the record, with their name against it.

Risk accepted at that level is recorded as accepted. It is never quietly downgraded to fit an
authority that already exists.

## Why this role exists

Someone has to be accountable for the exposure the organization carries, separately from the people
creating it. Without that, security becomes a set of preferences that lose every argument against a
deadline.

## Remit

- Security architecture and the standards systems are built against.
- The security program: what is measured, what is tested, what is monitored.
…

Read the whole file at its exact version.

How to install

Latest version
mdr add cbrock84/headcount/chief-information-security-officer@git:20260916.0e7cd01
Exact content
mdr add cbrock84/headcount/chief-information-security-officer@sha256:f8af5706fc2dab11

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_rbi3u5nvo4ntmdql.svg)](https://markdownregistry.com/a/art_rbi3u5nvo4ntmdql)

0 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260916.0e7cd01 latest2026-09-16 0e7cd01 7,270 BA view · diff
git:20260903.cc4a2cd2026-09-03 cc4a2cd 6,931 BA view · diff
git:20260902.c7de4762026-09-02 c7de476 6,943 BA view · diff
git:20260831.eaba5fa2026-08-31 eaba5fa 6,999 BA view · diff
git:20260829.4c1a9d22026-08-29 4c1a9d2 3,476 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (7270 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

cbrock84/headcount · 1,664 stars · license MIT · pushed 2026-09-17 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_rbi3u5nvo4ntmdql
GET https://markdownregistry.com/api/v1/resolve?ref=cbrock84/headcount/chief-information-security-officer
GET https://markdownregistry.com/api/v1/blob/f8af5706fc2dab11cb711d32196fa21d56ee4a94b2cb3f003bf4b0c0ffc2a125

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from cbrock84/headcount

chief-strategy-officer skill
cbrock84/headcount · plugins/corporate-strategy/skills/chief-strategy-officer/SKILL.md · Owns where the business plays and how it wins over a multi-year horizon — portfolio choices, corporate development…
git:20260903.cc4a2cd · audit A · 1,664 stars
market-entry skill
cbrock84/headcount · plugins/corporate-strategy/skills/market-entry/SKILL.md · Decides whether and how to enter a new market — sizing demand from the bottom up rather than from a market report…
git:20260901.3f04dfc · audit A · 1,664 stars
mergers-and-acquisitions skill
cbrock84/headcount · plugins/corporate-strategy/skills/mergers-and-acquisitions/SKILL.md · Runs corporate development — deal thesis, target screening, valuation framing, diligence, and integration planning. Use…
git:20260916.0e7cd01 · audit A · 1,664 stars
portfolio-strategy skill
cbrock84/headcount · plugins/corporate-strategy/skills/portfolio-strategy/SKILL.md · Decides where capital and attention go across business lines, products, and markets — what to fund, hold, harvest, or…
git:20260901.a52f5a7 · audit A · 1,664 stars
scenario-planning skill
cbrock84/headcount · plugins/corporate-strategy/skills/scenario-planning/SKILL.md · Plans under genuine uncertainty — building scenarios, identifying which assumptions are load-bearing, setting…
git:20260829.2464776 · audit A · 1,664 stars
strategic-alliances skill
cbrock84/headcount · plugins/corporate-strategy/skills/strategic-alliances/SKILL.md · Structures partnerships that change what the business can do — technology integrations, channel and reseller…
git:20260901.aa45383 · audit A · 1,664 stars
chief-customer-officer skill
cbrock84/headcount · plugins/customer-experience/skills/chief-customer-officer/SKILL.md · Owns the customer's experience after the sale — support, success, escalation, and the feedback loop back into product…
git:20260903.cc4a2cd · audit A · 1,664 stars
customer-onboarding-and-implementation skill
cbrock84/headcount · plugins/customer-experience/skills/customer-onboarding-and-implementation/SKILL.md · Takes a new customer from signature to working — setting a definition of live that both sides agreed before the…
git:20260901.9844f9d · audit A · 1,664 stars
customer-success-management skill
cbrock84/headcount · plugins/customer-experience/skills/customer-success-management/SKILL.md · Runs the ongoing relationship with accounts after the sale — segmenting coverage against account value, building a…
git:20260901.49e89d6 · audit A · 1,664 stars
escalation-management skill
cbrock84/headcount · plugins/customer-experience/skills/escalation-management/SKILL.md · Handles customer situations that have exceeded normal support — severity assessment, incident communication, executive…
git:20260901.aa45383 · audit A · 1,664 stars
self-service-and-knowledge skill
cbrock84/headcount · plugins/customer-experience/skills/self-service-and-knowledge/SKILL.md · Builds the help center, in-product guidance, and knowledge base that let customers resolve problems without contacting…
git:20260901.aa45383 · audit A · 1,664 stars
support-operations skill
cbrock84/headcount · plugins/customer-experience/skills/support-operations/SKILL.md · Designs and runs the support function — channels, queues, routing, staffing, service levels, quality, and the metrics…
git:20260901.0757404 · audit A · 1,664 stars

Every file in cbrock84/headcount

Browse by kind, by grade A, or by owner.