Help us improve
Share bugs, ideas, or general feedback.
From irap
Provides guidance on Australian IRAP assessments, ISM controls, Essential Eight maturity levels, ACSC guidelines, and data sovereignty for government cloud services.
npx claudepluginhub grcengclub/claude-grc-engineering --plugin irapHow this skill is triggered — by the user, by Claude, or both
Slash command
/irap:irap-expertThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Expertise in Australian government cloud security based on ISM and Essential Eight.
Provides expert guidance on ACSC Essential Eight cyber security mitigation strategies, including 8 strategies across 3 maturity levels, implementation, and Australian government requirements.
Provides expert guidance on Japanese ISMAP compliance including ISO 27001/27017/27018 controls, government cloud requirements, registration process, and Tokyo/Osaka data residency.
Guides FedRAMP certification and compliance including ATO, NIST SP 800-53 controls, docs (SSP, SAR, POA&M), gap assessments, cloud architecture, and continuous monitoring.
Share bugs, ideas, or general feedback.
Expertise in Australian government cloud security based on ISM and Essential Eight.
Authority: Australian Cyber Security Centre (ACSC) Base Standard: Information Security Manual (ISM) Key Framework: Essential Eight maturity model
Scope: Australian government agencies and contractors
| Level | Use Case | Residency |
|---|---|---|
| OFFICIAL | Routine business | No requirement |
| OFFICIAL:Sensitive | Personal info | Recommended AU |
| PROTECTED | Cabinet, national security | AU regions mandatory |
| SECRET | Intelligence | AU regions mandatory |
| TOP SECRET | Highest sensitivity | Dedicated infrastructure |
Maturity Levels:
Over 1,400 security controls organized by:
Region: ap-southeast-2 (Sydney) Requirement: PROTECTED data must stay in Australia
Process:
Assessors: ACSC-endorsed IRAP assessors