skills/arckit-au-pspf/SKILL.md
[COMMUNITY] Generate a Protective Security Policy Framework (PSPF) compliance assessment for Australian Government entities and contractors against the four security outcomes and 16 core requirements.
npx skillsauth add tractorjuice/arckit-codex arckit-au-pspfInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by a PSPF-experienced security officer or government accreditation specialist. PSPF is updated via Attorney-General's Department releases — verify version against current AGD publication.
You are an enterprise architect generating a Protective Security Policy Framework (PSPF) compliance assessment for an Australian Government entity or contractor handling government information.
$ARGUMENTS
The Protective Security Policy Framework (PSPF) is the Australian Government's overarching security policy framework administered by the Attorney-General's Department. It establishes the security policy environment for all non-corporate Commonwealth entities and is increasingly cited in tender requirements for contractors, service providers, and panel members. PSPF compliance is a primary input to DISP attestation and to IRAP scope statements.
PSPF is structured around four security outcomes with 16 core requirements:
Authoritative anchor: Protective Security Policy Framework — https://www.protectivesecurity.gov.au/
Key references:
Read prerequisites:
ARC-{P}-AUE8-v*)ARC-{P}-AUISM-v*) — primary inputARC-{P}-AUPIA-v*)ARC-{P}-DIAG-*) — deployment, facility, boundary, and working-off-site evidenceARC-{P}-DATA-v*) — classification, sensitivity, retention, and information-owner evidenceARC-{P}-SNOW-v*) if available — CMDB ownership, support groups, supporting services, incident/change workflows.arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/au-pspf-template.md.arckit/templates-custom/au-pspf-template.md.arckit/templates/au-pspf-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> AUPSPF --filename for the artefact filename.
Resolve the <!-- DOC-CONTROL-HEADER --> marker per RENDERING.md. Use the Australian classification scheme (UNOFFICIAL / OFFICIAL / OFFICIAL:Sensitive / PROTECTED / SECRET) — replace the standard UK line in the header.
Generate the following sections:
Entity Profile — entity name, type (non-corporate Commonwealth / corporate Commonwealth / contractor / panel member / state-government with PSPF flow-down), PSPF applicability driver (direct / contractual flow-down), Chief Security Officer (CSO) designation, security maturity self-assessment level.
Outcome 1: Security Governance — assessment of the 4 core requirements:
Outcome 2: Information Security — assessment of 4 core requirements (ISM is the primary instantiation here):
Outcome 3: Personnel Security — assessment of 4 core requirements:
Outcome 4: Physical Security — assessment of 4 core requirements:
For each Core Requirement document:
PSPF Annual Self-Assessment — for non-corporate Commonwealth entities, document Annual Self-Assessment Report status, last submission to AGD, current self-assessed maturity level, gaps.
Compliance Summary — 16-row table covering all four outcomes; overall PSPF maturity statement.
ArcKit Evidence Integration — map $arckit-diagram, $arckit-data-model, $arckit-servicenow, $arckit-risk, $arckit-traceability, $arckit-graph-report, and $arckit-maturity-model outputs to PSPF outcomes, CMDB ownership, supporting services, annual self-assessment evidence, and remediation tracking.
Recommendations — prioritised remediations by Quick Wins / Short-Term / Medium-Term, each tagged to specific Core Requirement.
Populate the External References section per .arckit/references/citation-instructions.md. PSPF (with edition) MUST appear in the Document Register.
Write the artefact via the Write tool to projects/<project-id>/<filename>.
Show only a summary to the user (one paragraph plus the four-outcome compliance summary table).
ARC-{P}-AUISM-v*) for technical-controls evidence rather than duplicating it.After completing this command, consider running:
$arckit-diagram -- Architecture and deployment diagrams support PSPF information, physical, facility, and working-off-site evidence.$arckit-data-model -- Data model evidence identifies information classification, sensitivity, owners, retention, and handling requirements.$arckit-au-ism-controls -- ISM is the technical-controls instantiation of PSPF Information Security outcome — primary input to PSPF Outcome 2.$arckit-au-e8-posture -- E8 supports PSPF Information Security outcome.$arckit-au-pia -- APP 11 + PSPF Personnel Security overlap; PIA cross-reference.$arckit-au-disp-attestation -- DISP attestation pack draws on PSPF compliance evidence.$arckit-servicenow -- ServiceNow/CMDB evidence supports service ownership, supporting services, support groups, facilities dependencies, and incident/change evidence.$arckit-risk -- PSPF gaps and annual self-assessment findings should feed the project risk register.$arckit-traceability -- PSPF core requirements should trace to policies, controls, owners, evidence artefacts, and remediation actions.$arckit-maturity-model -- PSPF self-assessment results can seed security governance maturity uplift planning.$arckit-graph-report -- Graph reporting should show AUPSPF coverage alongside AU compliance, risk, traceability, and operations artefacts.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.