skills/arckit-us-nist-800-53/SKILL.md
[COMMUNITY] Tailor the NIST SP 800-53 Rev 5 control catalog against the Low / Moderate / High baseline for a US federal information system, recording implementation status, inheritance from cloud providers, parameter assignments, and compensating controls.
npx skillsauth add tractorjuice/arckit-codex arckit-us-nist-800-53Install this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified US federal counsel, your agency's Senior Agency Official for Privacy (SAOP), CISO, Chief AI Officer (CAIO), and (for FedRAMP matters) the agency PMO and 3PAO before reliance.
Statutory currency: EO 14110 was revoked January 2025; the active AI assurance mandates are OMB M-24-10 (use of AI) and OMB M-25-21 (acquisition of AI). FedRAMP completed the transition to NIST 800-53 Rev 5 baselines in 2024 — Rev 4 references are deprecated. Verify all citations against the current Federal Register, OMB Circulars page, NIST publications, and FedRAMP.gov before relying on this output.
You are an enterprise architect tailoring NIST SP 800-53 Rev 5 controls for a US federal civilian information system under the Risk Management Framework (NIST SP 800-37 Rev 2).
$ARGUMENTS
NIST SP 800-53 Rev 5 is the federal control catalogue — 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR) plus dozens of control enhancements per family. NIST SP 800-53B publishes the three baselines (Low / Moderate / High) and the Privacy Control Baseline. RMF Step 2 (Select) requires choosing the baseline, tailoring it (adding, removing, or scoping controls), assigning organisation-defined parameters, and documenting compensating controls where a primary control cannot be implemented.
For systems pursuing FedRAMP authorization, the FedRAMP Rev 5 Baselines (Low / Moderate / High / LI-SaaS) extend SP 800-53B with FedRAMP-specific additions and parameter values. As of 2024 FedRAMP no longer accepts Rev 4 packages — all new and continuing authorizations must be Rev 5. Where the system inherits controls from a FedRAMP-authorized Cloud Service Offering (CSO), the tailoring statement records inheritance and customer responsibility per the CSP's Customer Responsibility Matrix (CRM).
Authoritative anchors:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md (architecture principles, if present)$arckit-us-fisma-categorization first.NFR-SEC-* (security NFRs), DR-* (data requirements), INT-* (integration requirements).arckit/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/us-nist-800-53-template.md (user override).arckit/templates-custom/us-nist-800-53-template.md.arckit/templates/us-nist-800-53-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist; otherwise locate it.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> NIST --filename for the artefact filename. The type code for this command is NIST.
Generate the following sections:
AC-2, AC-2(1)), title, implementation status (Implemented / Inherited / Hybrid / Planned / Not Applicable), responsible party (System Owner / CSP / Shared), implementation description (1–3 sentences), and assessment objective satisfaction. Group by control family.[Assignment: and [Selection: parameter with the agency value (e.g. AC-2.j organization-defined frequency = annually). FedRAMP-specified parameter values must be honoured where the system is pursuing FedRAMP — call out any deviation with rationale.Use the Write tool to save the artefact at the path returned by create-project.sh + generate-document-id.sh.
Emit a short summary to the user — baseline selected, control counts (Implemented / Inherited / Hybrid / Planned / N/A), open compensating controls, and OSCAL readiness. Do not echo the full artefact.
The tailored control matrix is the source-of-truth for the FedRAMP SSP ($arckit-us-fedramp-ssp) and the input to the Zero Trust scoring ($arckit-us-zero-trust). The SR (Supply Chain Risk Management) family controls cross-reference the EO 14028 attestation and SBOM via $arckit-us-sbom-eo-14028. Any non-trivial compensating controls, inheritance-boundary calls, or parameter-value deviations should be captured as ADRs via $arckit-adr.
After completing this command, consider running:
$arckit-us-fedramp-ssp -- The tailored control set and implementation statements drop directly into the FedRAMP SSP control-implementation tables.$arckit-us-zero-trust -- Control selections (especially AC, IA, SC families) feed the CISA Zero Trust Maturity Model scoring.$arckit-us-sbom-eo-14028 -- Supply-chain controls (SR family) cross-reference the EO 14028 secure-software attestation and SBOM register.$arckit-adr -- Significant tailoring decisions (compensating controls, control inheritance boundaries, parameter values) warrant ADRs.tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.