-
Critical Asset and Responsible Entity Context - identify the asset, sector, responsible entity, operator, direct interest holders, regulator, and whether the asset is declared or suspected in scope.
-
SOCI Applicability Assessment - assess sector, asset class, thresholds, responsible entity obligations, register obligations, incident reporting, government assistance implications, and any uncertainty requiring legal confirmation.
-
ArcKit Architecture and Data Evidence Map - cross-reference /skill:arckit-diagram, /skill:arckit-dfd, and /skill:arckit-data-model artefacts to asset scope, protected-information handling, operational dependencies, and hazard evidence. Call out missing or stale evidence explicitly.
-
CIRMP Governance Model - document accountable owner, board/council/governing body oversight, annual report owner, risk committee, review cadence, and evidence repository.
-
CIRMP Hazard Domain Assessment - assess cyber and information security, personnel, supply chain, physical security, and natural hazards. Include material risk, relevant impact, current controls, evidence, gaps, and risk owner.
-
Cyber and Information Security Evidence - consolidate evidence from AUE8, AUISM, AUOT where applicable, AUPIA, AUNDB, monitoring, incident response, supplier access, and protected-information handling.
-
Personnel, Supply Chain, Physical Security, and Natural Hazard Evidence - capture responsible controls, suppliers, critical workers, physical critical components, facility controls, dependencies, and business continuity evidence.
-
Incident Reporting and Notification Pathways - document cyber incident escalation, responsible reporting roles, 12-hour / 72-hour pathways where applicable, regulator contact points, and record-keeping.
-
Annual Report and Attestation Readiness - assess whether the entity can produce the annual CIRMP report within required timeframes, with board/council/governing body approval.
-
Operations, CMDB, and Traceability Integration - map critical components and support processes to /skill:arckit-servicenow CMDB CIs; map obligations and material risks to /skill:arckit-risk, /skill:arckit-traceability, /skill:arckit-graph-report, and /skill:arckit-maturity-model outputs.
-
Cross-Sector vs Sector-Specific Obligations - record general SOCI obligations here and explicitly defer sector-specific requirements such as AESCSF, AER ring-fencing, NER/NGR, or AEMO obligations to sector recipes.
-
Recommendations - prioritised actions grouped by Immediate, 30-90 days, 90-180 days, and strategic uplift.