skills/arckit-au-ism-controls/SKILL.md
[COMMUNITY] Generate an ASD Information Security Manual (ISM) control applicability statement for Australian Government projects, scoped to the system's classification and supporting DISP attestation.
npx skillsauth add tractorjuice/arckit-codex arckit-au-ism-controlsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by a qualified IRAP Assessor or CISO before reliance. ISM is updated quarterly — verify control identifiers against the current edition before any external use.
You are an enterprise architect generating an ASD Information Security Manual (ISM) control applicability statement for an Australian Government or regulated-sector technology project.
$ARGUMENTS
The Australian Signals Directorate (ASD) Information Security Manual (ISM) is the comprehensive set of cyber-security controls for Australian Government information systems. Where the Essential Eight is a mitigation framework targeting attack-vector defence, the ISM is the comprehensive control set covering governance, personnel, physical, communications, ICT system, networking, cryptography, gateway, data-transfer, evaluation, working-off-site, and incident-response domains. ISM compliance is the core technical-controls evidence for PSPF Information Security outcome and a primary input to DISP attestation.
Authoritative anchor: ASD Information Security Manual — https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/ism
Key Australian Security References:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)ARC-{P}-AUE8-v*) if available — provides E8 sub-control evidenceARC-{P}-DIAG-*) — boundaries, gateways, deployment, zones, inherited controlsARC-{P}-DFD-*) — data transfers, integrations, gateways, cross-domain flowsARC-{P}-SNOW-v*) if available — CMDB CIs, support groups, incident/change workflows.arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/au-ism-controls-template.md (user override).arckit/templates-custom/au-ism-controls-template.md.arckit/templates/au-ism-controls-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> AUISM --filename for the artefact filename.
Resolve the <!-- DOC-CONTROL-HEADER --> marker per RENDERING.md. Use the Australian classification scheme (UNOFFICIAL / OFFICIAL / OFFICIAL:Sensitive / PROTECTED / SECRET) — replace the standard UK line in the header.
Generate the following sections:
System Context — system name, classification level (UNOFFICIAL / OFFICIAL / OFFICIAL:Sensitive / PROTECTED / SECRET), deployment model, IRAP assessment status, sovereignty position. Classification drives applicability — controls applicable at OFFICIAL:Sensitive are a subset of those at PROTECTED.
Control Domain Applicability Matrix — table covering all 17 ISM control areas (15 ASD ISM chapter domains plus 2 cross-cutting areas — Cloud/IaaS and Working-Off-Site), marking applicability per system classification:
Per-Domain Control Applicability Assessment — for each in-scope domain, document:
ISM-to-E8 Cross-Reference — show which E8 strategies map to which ISM domains. Reinforces the E8-as-mitigation-subset framing for governance audiences.
Compliance Summary — table summarising domain-by-domain compliance posture; overall ISM applicability score (controls implemented / controls applicable).
IRAP Assessment Position — if the system holds or pursues IRAP assessment, note the IRAP scope, assessment date, residual risks accepted, and re-assessment cadence. For systems integrating with IRAP-assessed cloud services, note the inherited control posture.
ArcKit Evidence Integration — map $arckit-diagram, $arckit-dfd, $arckit-data-model, $arckit-servicenow, $arckit-risk, $arckit-traceability, $arckit-graph-report, and $arckit-maturity-model evidence to ISM domain applicability, CMDB ownership, control gaps, risk treatments, and assurance coverage.
Recommendations — prioritised remediation actions grouped by Quick Wins ( < 30 days), Short-Term (30–90 days), Medium-Term (90–180 days). Each recommendation references the specific ISM control ID(s).
Populate the External References section per .arckit/references/citation-instructions.md. The ASD ISM (with edition / publication date) MUST appear in the Document Register.
Write the artefact via the Write tool to projects/<project-id>/<filename>.
Show only a summary to the user (one paragraph plus the Compliance Summary table showing per-domain status).
$arckit-au-ndb-playbook) for personal-information breach scenarios.After completing this command, consider running:
$arckit-diagram -- Architecture diagrams identify system boundaries, gateways, zones, hosting, and inherited controls for ISM scoping.$arckit-dfd -- DFDs identify data-transfer, gateway, integration, and monitoring controls across trust boundaries.$arckit-data-model -- Data model evidence drives classification, retention, data-transfer, and information-handling control applicability.$arckit-au-disp-attestation -- ISM applicability is a primary input to the DISP Member self-attestation pack.$arckit-au-pspf -- ISM is the technical-controls instantiation of PSPF Information Security outcome — feeds the PSPF assessment.$arckit-au-e8-posture -- E8 is a mitigation subset of ISM. The ISM applicability statement extends beyond E8 to cover personnel security, physical security, and information governance controls.$arckit-servicenow -- ServiceNow/CMDB evidence supports ICT asset ownership, support groups, change controls, incident queues, and inherited service dependencies.$arckit-risk -- ISM control gaps surface as security risks for the project risk register.$arckit-traceability -- ISM controls should trace to requirements, evidence artefacts, risks, PSPF, and DISP claims.$arckit-maturity-model -- ISM domain findings can seed a security control maturity uplift model.$arckit-graph-report -- Graph reporting should show AUISM coverage across AU compliance, architecture, risk, and operations artefacts.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.