Walk NIST SSDF Phase 1 (Plan & Requirements) and file GitHub epics for the five "Prepare the Organization" practices — PO.1 security requirements, PO.2 roles and responsibilities, PO.3 supporting toolchains, PO.4 criteria for security checks, PO.5 secure development environments. Use when starting a new product or a major feature planning cycle, when setting up secure-SDLC governance for a repo, or when the user mentions NIST SSDF, SP 800-218, SSDF phase 1, or the PO practices.