irap

Identify and index IRAP CAF artefacts for ISM-aligned assessments.

2|Updated May 13, 2026
One-click install
npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill irap
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: irap
Source: https://github.com/jusso-dev/awesome-Australian-compliance/tree/main/skills/irap
Command: npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill irap

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps government entities, assessors, and security teams plan, prepare, and manage IRAP CAF-based assessments by organizing the required artefacts (SSP, SoA, risk management plans, boundary definitions) and aligning activities to the CAF stages.

Core Features & Use Cases

  • Provides CAF-stage guidance, artefact templates, and cross-reference to ASD sources.
  • Helps define assessment boundaries, data sovereignty considerations, and layered assessments for cloud providers.
  • Supports engagement planning and reporting with templates that map to IRAP-AR requirements.

Quick Start

Provide the required CAF Stage 1 inputs and templates to begin an IRAP assessment.

Frequently Asked Questions about irap

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare artefacts for an IRAP CAF assessment?

To prepare for an IRAP CAF assessment, identify and index required artefacts like SSP, SoA, and risk management plans to ensure they conform to ASD CAF templates and IRAP-AR requirements.

What is the IRAP CAF process for Australian government systems?

The IRAP CAF process for Australian government systems involves planning, scoping, evidence gathering, and reporting across defined CAF stages to align security assessments with ISM requirements.

Can I use this to define assessment boundaries for cloud providers?

Yes, you can define assessment boundaries for cloud providers, including data sovereignty considerations and layered assessments, to support comprehensive ISM-aligned security evaluations.

How do I map security documentation to IRAP-AR requirements?

Map security documentation to IRAP-AR requirements by using provided CAF-stage guidance and engagement reporting templates that cross-reference ASD sources for artefact conformity.

Do I need CAF Stage 1 inputs to start an ISM-aligned assessment?

Yes, you need to provide the required CAF Stage 1 inputs and templates to begin scoping, planning, and gathering evidence for an ISM-aligned IRAP assessment.

What is the best way to manage data sovereignty considerations during CAF scoping?

The best way to manage data sovereignty considerations during CAF scoping is to define clear assessment boundaries and apply layered assessments tailored to your specific cloud providers.