ism

Guides Australian government ISM compliance, gap analysis, and IRAP assessment preparation.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill ism-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ism
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/ism
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill ism-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Australian government entities and their contractors must comply with the ASD Information Security Manual, but navigating its 22 guideline chapters, classification-based control applicability, and authorisation requirements is complex and error-prone. This Skill provides structured expert guidance for applying ISM controls to real systems. ## Core Features & Use Cases - Gap Analysis: Produces control-by-control tables with implementation status, evidence requirements, and remediation priorities for any classification level from NC to TOP SECRET. - System Authorisation & IRAP Preparation: Walks through the six-step authorisation pathway, artefact checklists, assessor requirements, and re-assessment cycles. - Security Documentation: Generates ISM-aligned documents such as System Security Plans, risk assessments, and incident response plans with control references. - Use Case: A CISO at a federal agency needs to prepare a PROTECTED system for its first IRAP assessment. The Skill identifies all applicable NC + OS + P controls, produces a gap analysis table, and generates the SSP outline with mapped ISM control IDs. ## Quick Start Ask the assistant to perform an ISM gap analysis for a PROTECTED cloud-hosted system and list the artefacts needed for an IRAP assessment.

Frequently Asked Questions about ism

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an ISM gap analysis for a government system?

Confirm the system's classification level and operating environment, then assess every applicable control for status, evidence, and gaps. The Skill produces a table with Control ID, chapter, applicability, status, evidence needed, and gap notes, plus remediation priorities.

What is the difference between Essential Eight and ISM compliance?

The Essential Eight is a prioritised subset of eight mitigation strategies drawn from the broader ISM control set. Essential Eight compliance does not equal full ISM compliance; government systems must satisfy both ISM controls and Essential Eight maturity targets.

Which ISM controls apply to a PROTECTED system?

PROTECTED systems must implement all controls marked NC, OS, and P, since higher classifications stack lower-level controls. The Skill's control applicability reference details the full stacking rules and scoping process.

When is an IRAP assessment required for a system?

IRAP assessment is mandatory for systems handling PROTECTED and above, and strongly recommended for OFFICIAL: Sensitive systems. Re-assessment occurs at least every 24 months or after significant change, performed by an assessor on the ASD IRAP register.

What documents are needed for Australian government system authorisation?

The authorisation pathway requires a System Security Plan, security risk assessment, IRAP assessment report, Plan of Action and Milestones, and an Authorisation to Operate signed by the Authorising Official. Continuous monitoring follows authorisation.

Does this Skill replace an accredited IRAP assessor or legal advice?

No. The Skill provides general compliance information and guidance only, not legal advice or formal assessment. Final authorisation decisions require an ASD-certified IRAP assessor and the designated Authorising Official.