irap

Identify and index IRAP CAF artefacts for ISM-aligned assessments.

2|Updated May 13, 2026
One-click install
npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill irap
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: irap
Source: https://github.com/jusso-dev/awesome-Australian-compliance/tree/main/skills/irap
Command: npx skills add https://github.com/jusso-dev/awesome-Australian-compliance --skill irap

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps government entities, assessors, and security teams plan, prepare, and manage IRAP CAF-based assessments by organizing the required artefacts (SSP, SoA, risk management plans, boundary definitions) and aligning activities to the CAF stages.

Core Features & Use Cases

  • Provides CAF-stage guidance, artefact templates, and cross-reference to ASD sources.
  • Helps define assessment boundaries, data sovereignty considerations, and layered assessments for cloud providers.
  • Supports engagement planning and reporting with templates that map to IRAP-AR requirements.

Quick Start

Provide the required CAF Stage 1 inputs and templates to begin an IRAP assessment.

Frequently Asked Questions about irap

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare artefacts for an IRAP CAF assessment?▼

To prepare for an IRAP CAF assessment, identify and index required artefacts like SSP, SoA, and risk management plans to ensure they conform to ASD CAF templates and IRAP-AR requirements.

What is the IRAP CAF process for Australian government systems?▼

The IRAP CAF process for Australian government systems involves planning, scoping, evidence gathering, and reporting across defined CAF stages to align security assessments with ISM requirements.

Can I use this to define assessment boundaries for cloud providers?▼

Yes, you can define assessment boundaries for cloud providers, including data sovereignty considerations and layered assessments, to support comprehensive ISM-aligned security evaluations.

How do I map security documentation to IRAP-AR requirements?▼

Map security documentation to IRAP-AR requirements by using provided CAF-stage guidance and engagement reporting templates that cross-reference ASD sources for artefact conformity.

Do I need CAF Stage 1 inputs to start an ISM-aligned assessment?▼

Yes, you need to provide the required CAF Stage 1 inputs and templates to begin scoping, planning, and gathering evidence for an ISM-aligned IRAP assessment.

What is the best way to manage data sovereignty considerations during CAF scoping?▼

The best way to manage data sovereignty considerations during CAF scoping is to define clear assessment boundaries and apply layered assessments tailored to your specific cloud providers.