arckit-mod-secure

Generate Secure by Design assessments for UK MOD projects against JSP 440 Leaflet 5C.

2.1k|266|Updated Oct 14, 2025
One-click install
npx skills add https://github.com/tractorjuice/arc-kit --skill arckit-mod-secure
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: arckit-mod-secure
Source: https://github.com/tractorjuice/arc-kit/tree/main/arckit-codex/skills/arckit-mod-secure
Command: npx skills add https://github.com/tractorjuice/arc-kit --skill arckit-mod-secure

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps UK Ministry of Defence projects conduct mandatory Secure by Design (SbD) assessments, ensuring compliance with new continuous risk management mandates and improving cyber security posture.

Core Features & Use Cases

  • Mandatory Compliance: Ensures adherence to JSP 440 Leaflet 5C for all new Defence capabilities.
  • Continuous Risk Management: Facilitates ongoing security assessment throughout the capability lifecycle, replacing legacy accreditation.
  • Use Case: A project manager for a new MOD naval communication system can use this Skill to generate a comprehensive SbD assessment, identifying critical security gaps and providing actionable remediation steps aligned with MOD policy.

Quick Start

Generate a MOD Secure by Design assessment for the 'Project Chimera' initiative.

Frequently Asked Questions about arckit-mod-secure

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a Secure by Design assessment for a UK MOD technology project?

Secure by Design replaces legacy accreditation with continuous risk management mandated by JSP 440 Leaflet 5C since August 2023. It requires assessing new Defence capabilities against the 7 MOD SbD Principles and NIST Cybersecurity Framework throughout the capability lifecycle, rather than relying on point-in-time accreditation.

How does continuous risk management work under JSP 440 Leaflet 5C?

Continuous risk management under JSP 440 Leaflet 5C replaces legacy accreditation with ongoing security assessment throughout the capability lifecycle. It enforces adherence to the 7 MOD SbD Principles and NIST Cybersecurity Framework for all new Defence capabilities, ensuring persistent cyber security posture evaluation.

Can I use this to assess compliance against both MOD SbD Principles and NIST Cybersecurity Framework?

Use this assessment for any new MOD Defence capability, technology project, or program requiring JSP 440 Leaflet 5C compliance. It evaluates capabilities against the 7 MOD SbD Principles and NIST Cybersecurity Framework, making it suitable for diverse applications like naval communication systems throughout their lifecycle.

What do I need to conduct a Secure by Design assessment for a Defence capability?

To conduct a Secure by Design assessment, you need the details of your MOD technology project, program, or capability. The assessment enforces JSP 440 Leaflet 5C compliance, evaluating your project against the 7 MOD SbD Principles and NIST Cybersecurity Framework to generate actionable remediation steps.

When do I need a Secure by Design assessment instead of legacy accreditation for MOD projects?

You need a Secure by Design assessment for all new MOD Defence capabilities to comply with the continuous risk management mandate effective August 2023. This replaces legacy accreditation by enforcing JSP 440 Leaflet 5C and assessing against the 7 MOD SbD Principles throughout the capability lifecycle.

Does the MOD Secure by Design assessment identify security gaps and remediation steps?

The MOD Secure by Design assessment identifies critical security gaps and provides actionable remediation steps aligned with MOD policy. It enforces JSP 440 Leaflet 5C compliance by evaluating projects against the 7 MOD SbD Principles and NIST Cybersecurity Framework to improve overall cyber security posture.