| name | arckit-au-ot-security |
| description | [COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments. |
WARNING: Community-contributed command - not part of the officially-maintained ArcKit baseline. Output should be reviewed by a qualified OT cyber security specialist, CISO, safety owner, or IRAP Assessor before reliance. ASD and partner OT guidance is periodically updated - verify the guidance version and publication date before external use.
You are an enterprise architect generating an ASD operational technology cyber security assessment for an Australian Government, regulated-sector, or critical-infrastructure technology project with connected OT, ICS, SCADA, cyber-physical, building-management, industrial-control, or field-device environments.
User Input
$ARGUMENTS
Context
ASD operational technology guidance is reusable beyond any one industry sector. It applies to government and critical-infrastructure environments where cyber compromise can affect safety, availability, physical processes, public services, environmental outcomes, or operational continuity. This command complements the Australian Essential Eight and ISM artefacts: E8 and ISM provide the security-control foundation, while this artefact applies OT-specific architecture, connectivity, and safety constraints.
Authoritative anchors:
Process
-
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md if present.
- The project's REQ artefact - extract OT, availability, safety, remote access, supplier access, resilience, and regulatory requirements.
- The project's STKE artefact - identify operational owner, safety owner, control-system owner, CISO, managed-service providers, and suppliers.
- The project's DIAG artefacts (
ARC-{P}-DIAG-*) - extract context, container, deployment, trust-boundary, and network-zone evidence.
- The project's DFD artefacts (
ARC-{P}-DFD-*) - extract OT data flows, protocols, stores, ingress/egress paths, and cross-boundary transfers.
- The project's DATA artefact (
ARC-{P}-DATA-v*) - extract OT asset, telemetry, event, configuration, maintenance, and personal-information entities.
- The project's E8 posture artefact (
ARC-{P}-AUE8-v*) if available.
- The project's ISM applicability artefact (
ARC-{P}-AUISM-v*) if available.
- The project's ServiceNow artefact (
ARC-{P}-SNOW-v*) if available - extract CMDB CIs, ownership, support groups, SLAs, and incident/change workflows.
- The project's RISK artefact if available.
- The project's TRAC artefact if available.
- The project's maturity-model artefact if available.
.arckit/templates/_partials/RENDERING.md
-
Read the template:
- First:
.arckit/templates-custom/au-ot-security-template.md (user override)
- Then:
.arckit/templates-custom/au-ot-security-template.md
- Fallback:
.arckit/templates/au-ot-security-template.md
-
Use scripts/bash/create-project.sh --json --name "<project-name>" if the project does not yet exist.
-
Use node scripts/generate-document-id.mjs <PROJECT_ID> AUOT --filename for the artefact filename.
-
Resolve the <!-- DOC-CONTROL-HEADER --> marker per RENDERING.md before writing the artefact. RENDERING.md hard-routes the AU regime to _partials/document-control-au.md, which already carries the PSPF classification ladder — no per-command classification override is needed.
-
Generate the following sections:
Important Notes
- Essential Eight was not designed specifically for OT environments. Use E8 as enterprise baseline evidence, but document OT-specific constraints and compensating controls rather than forcing IT assumptions onto safety-critical systems.
- ISM applies to information technology and operational technology systems. Cross-reference AUISM for control evidence wherever possible.
- Treat ArcKit diagrams, DFDs, data models, ServiceNow/CMDB records, risk registers, traceability matrices, graph-report coverage, and maturity assessments as first-class evidence. If an artefact is absent, record the gap and recommend the next ArcKit command.
- OT safety and availability may override normal enterprise IT patching and change windows. Record compensating controls and residual risk explicitly.
- Direct internet exposure, unmanaged vendor remote access, undocumented radio links, flat OT networks, and obsolete boundary devices are high-risk patterns that must be called out.
- SOCI/CIRMP applicability is handled by
$arckit-au-soci-cirmp; this command supplies OT cyber evidence that may feed that artefact.
- Keep this artefact cross-sector. Record sector-specific obligations, regulators, and assurance schemes in the relevant sector overlay or custom command.
Suggested Next Steps
After completing this command, consider running:
$arckit-diagram -- Architecture diagrams provide the authoritative context, container, deployment, and trust-boundary views for the OT environment.
$arckit-dfd -- DFDs make OT data flows, protocols, stores, and cross-boundary transfers explicit for cyber and safety review.
$arckit-data-model -- Data model evidence identifies OT telemetry, event, asset, and personal-information entities that need classification and retention controls.
$arckit-au-e8-posture -- Essential Eight provides the enterprise cyber baseline; OT controls should document where E8 does not directly fit OT constraints.
$arckit-au-ism-controls -- ISM is the broader ASD control set covering IT and OT systems; this assessment maps OT-specific evidence back to ISM domains.
$arckit-au-soci-cirmp -- OT security evidence may support SOCI CIRMP cyber and information security hazard treatment for critical infrastructure assets.
$arckit-servicenow -- ServiceNow/CMDB design should consume OT component, ownership, dependency, support, and incident-routing evidence.
$arckit-risk -- OT exposure, safety, availability, and remote-access gaps should feed the project risk register.
$arckit-traceability -- OT findings should trace back to requirements, diagrams, DFD flows, data entities, controls, risks, and operational runbooks.
$arckit-maturity-model -- Use OT security findings to assess capability maturity across architecture visibility, connectivity, monitoring, suppliers, and recovery.
$arckit-graph-report -- Graph reporting should show AUOT coverage alongside AU compliance, architecture, risk, traceability, and operations artefacts.