skills/arckit-us-icam/SKILL.md
[COMMUNITY] Design a US federal Identity, Credential, and Access Management architecture per OMB M-19-17 and NIST SP 800-63-3, determining IAL/AAL/FAL levels per use case and selecting PIV / login.gov / agency-specific identity providers.
npx skillsauth add tractorjuice/arckit-codex arckit-us-icamInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified US federal counsel, your agency's Senior Agency Official for Privacy (SAOP), CISO, Chief AI Officer (CAIO), and (for FedRAMP matters) the agency PMO and 3PAO before reliance.
Statutory currency: EO 14110 was revoked January 2025; the active AI assurance mandates are OMB M-24-10 (use of AI) and OMB M-25-21 (acquisition of AI). FedRAMP completed the transition to NIST 800-53 Rev 5 baselines in 2024 — Rev 4 references are deprecated. Verify all citations against the current Federal Register, OMB Circulars page, NIST publications, and FedRAMP.gov before relying on this output.
You are an enterprise architect designing the Identity, Credential, and Access Management (ICAM) architecture for a US federal civilian system under OMB M-19-17.
$ARGUMENTS
OMB M-19-17 ("Enabling Mission Delivery through Improved Identity, Credential, and Access Management") sets the federal ICAM policy framework. It directs agencies to adopt a risk-based approach to identity assurance using NIST SP 800-63-3 Digital Identity Guidelines, which decompose identity assurance into three orthogonal levels:
Federal employees and contractors authenticate using PIV (Personal Identity Verification) credentials per FIPS 201-3. Public-facing federal services predominantly federate to login.gov (operated by GSA / Technology Transformation Services) which provides IAL1, IAL2, and AAL2 services. Agencies may operate additional federated identity providers (e.g. HHS IAM, VA.gov).
Authoritative anchors:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)NFR-SEC-* (security NFRs), INT-* (integration requirements), DR-* (data requirements).arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/us-icam-template.md (user override).arckit/templates-custom/us-icam-template.md.arckit/templates/us-icam-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> ICAM --filename for the artefact filename. The type code for this command is ICAM.
Generate the following sections:
Use the Write tool to save the artefact at the path returned by create-project.sh + generate-document-id.sh.
Emit a short summary to the user — user-population count, highest IAL/AAL/FAL required, selected identity providers (login.gov, PIV, agency IdP), and any open architecture decisions. Do not echo the full artefact.
ICAM is the foundation of the Zero Trust Identity pillar — feed IAL/AAL/FAL outputs into $arckit-us-zero-trust scoring. The proofing data flows (especially at IAL2/IAL3) collect significant PII, so trigger $arckit-us-privacy-pia. Identity-provider selection and federation pattern decisions should be captured as ADRs via $arckit-adr.
After completing this command, consider running:
$arckit-us-zero-trust -- ICAM is the foundation of the Zero Trust Identity pillar; IAL/AAL/FAL selections directly score ZTMM Identity functions.$arckit-us-privacy-pia -- Identity proofing collects and processes PII (especially IAL2/IAL3); the ICAM data flows feed the PIA personal-information inventory.$arckit-adr -- Identity provider selection (PIV vs login.gov vs agency-specific) and federation pattern decisions warrant ADRs.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.