← ClaudeAtlas

secure-design-speclisted

Use when writing a secure design specification for a new system or feature — defining security requirements, authentication, authorization, encryption, and trust assumptions at design time with OWASP Secure Design Principles/Microsoft SDL/NIST SSDF. Triggers on "secure design spec", "security requirements", "security by design", "least privilege", "data classification".
noctua84/nescio-ai · ★ 0 · Web & Frontend · score 73
Install: claude install-skill noctua84/nescio-ai
# Secure Design Spec ## Purpose Create a secure design specification that delivers actionable, measurable results. **Category**: Cybersecurity & Information Security ## Inputs ### Required - **Objective**: What you want to achieve with this deliverable - **Context**: Relevant background information (systems, scope, environment) ### Optional - **Constraints**: Any limitations or requirements to consider - **Existing Work**: Previous documents or data to build on ## Context Before starting, read the repo's `CLAUDE.md` and any relevant notes under `memory/` (e.g. `memory/repo/<repo>/`, `memory/feedback/`) for prior decisions and constraints. ## Process ### Step 1: Context & Research - Review any existing secure design specification documents in the project - Identify key stakeholders and their requirements - Select the most appropriate framework: OWASP Secure Design Principles, Microsoft SDL, NIST SSDF (SP 800-218) ### Step 2: Analysis & Framework Application - Apply the selected framework to structure the secure design specification - Identify gaps, opportunities, and risks - Define success metrics: Security Requirements Coverage, Threat Mitigation Coverage, Design Review Findings, Crypto Standard Compliance - Document assumptions and dependencies - Validate approach against industry best practices ### Step 3: Build the Deliverable - Structure the secure design specification using the output format below - Include specific, actionable recommendations — not generic a