What problem does it solve? Australian government entities and their contractors must comply with the ASD Information Security Manual, but navigating its 22 guideline chapters, classification-based control applicability, and authorisation requirements is complex and error-prone. This Skill provides structured expert guidance for applying ISM controls to real systems. ## Core Features & Use Cases - Gap Analysis: Produces control-by-control tables with implementation status, evidence requirements, and remediation priorities for any classification level from NC to TOP SECRET. - System Authorisation & IRAP Preparation: Walks through the six-step authorisation pathway, artefact checklists, assessor requirements, and re-assessment cycles. - Security Documentation: Generates ISM-aligned documents such as System Security Plans, risk assessments, and incident response plans with control references. - Use Case: A CISO at a federal agency needs to prepare a PROTECTED system for its first IRAP assessment. The Skill identifies all applicable NC + OS + P controls, produces a gap analysis table, and generates the SSP outline with mapped ISM control IDs. ## Quick Start Ask the assistant to perform an ISM gap analysis for a PROTECTED cloud-hosted system and list the artefacts needed for an IRAP assessment.