ワンクリックで
arckit-mod-secure
Generate a MOD Secure by Design assessment for UK Ministry of Defence projects using CAAT and continuous assurance
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Generate a MOD Secure by Design assessment for UK Ministry of Defence projects using CAAT and continuous assurance
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
[COMMUNITY] Generate a NHS DCB0129 manufacturer Clinical Safety Case Report and Hazard Log (Marcus Baw SAFETY.md 3-file spec) for a digital health product placed on the NHS market.
[COMMUNITY] Generate a NHS DCB0160 deployer Clinical Safety Case Report and deployment Hazard Log for an NHS organisation deploying or significantly configuring a health IT product into a specific clinical setting.
Document architectural decisions with options analysis and traceability
Design AI agent architecture — patterns, tool contracts, memory, orchestration, guardrails
Design AI agent governance — oversight models, approval workflows, audit requirements, compliance mapping
Assess AI agent program maturity across design, governance, security, integration, and operations
| name | arckit-mod-secure |
| description | Generate a MOD Secure by Design assessment for UK Ministry of Defence projects using CAAT and continuous assurance |
You are helping to conduct a Secure by Design (SbD) assessment for a UK Ministry of Defence (MOD) technology project, programme, or capability.
$ARGUMENTS
Since August 2023, ALL Defence capabilities, technology infrastructure, and digital services MUST follow the Secure by Design (SbD) approach mandated in JSP 440 Leaflet 5C. This represents a fundamental shift from legacy RMADS (Risk Management and Accreditation Documentation Set) to continuous risk management throughout the capability lifecycle.
Key MOD Security References:
SbD is now mandatory:
Read the template (with user override support):
.arckit/templates-custom/mod-secure-by-design-template.md exists in the project root.arckit/templates/mod-secure-by-design-template.md (default)Tip: Users can customize templates with
$arckit-customize mod-secure
Generate a comprehensive Secure by Design assessment document using the continuous risk management approach by:
Understanding the project context:
Read Available Documents:
Note: Before generating, scan
projects/for existing project directories. For each project, list allARC-*.mdartifacts, checkexternal/for reference documents, and check000-global/for cross-project policies. If no external docs exist but they would improve output, ask the user.
MANDATORY (warn if missing):
$arckit-requirements first$arckit-principles firstRECOMMENDED (read if available, note if missing):
OPTIONAL (read if available, skip silently if missing):
Assess against the 7 MOD Secure by Design Principles (ISN 2023/09):
Principle 1: Understand and Define Context
Principle 2: Apply Security from the Start
Principle 3: Apply Defence in Depth
Principle 4: Follow Secure Design Patterns
Principle 5: Continuously Manage Risk
Principle 6: Secure the Supply Chain
Principle 7: Enable Through-Life Assurance
Read external documents and policies:
external/ files) — extract CAAT assessment results, security clearance requirements, JSP 440 compliance status, IAMM maturity scoresprojects/{project-dir}/vendors/{vendor}/ — extract supplier security clearances, List X status, DEFCON compliance, SC/DV clearance evidence000-global/policies/) — extract MOD security standards, classification requirements, ITAR restrictionsprojects/000-global/external/ — extract enterprise MOD security baselines, accreditation templates, cross-project security assurance evidenceprojects/{project-dir}/external/ and re-run, or skip.".arckit/references/citation-instructions.md. Place inline citation markers (e.g., [PP-C1]) next to findings informed by source documents and populate the "External References" section in the template.Assess using NIST Cybersecurity Framework (as mandated by SbD):
Identify:
Protect:
Detect:
Respond:
Recover:
Assess Three Lines of Defence:
First Line: Delivery team owns security
Second Line: Assurance and oversight
Third Line: Independent audit
For each domain:
Determine overall security posture:
Generate actionable recommendations:
CRITICAL - Auto-Populate Document Control Fields:
Before completing the document, populate ALL document control fields in the header:
Construct Document ID:
ARC-{PROJECT_ID}-SECD-MOD-v{VERSION} (e.g., ARC-001-SECD-MOD-v1.0)Populate Required Fields:
Auto-populated fields (populate these automatically):
[PROJECT_ID] → Extract from project path (e.g., "001" from "projects/001-project-name")[VERSION] → "1.0" (or increment if previous version exists)[DATE] / [YYYY-MM-DD] → Current date in YYYY-MM-DD format[DOCUMENT_TYPE_NAME] → "MOD Secure by Design Assessment"ARC-[PROJECT_ID]-SECD-MOD-v[VERSION] → Construct using format above[COMMAND] → "arckit.mod-secure"User-provided fields (extract from project metadata or user input):
[PROJECT_NAME] → Full project name from project metadata or user input[OWNER_NAME_AND_ROLE] → Document owner (prompt user if not in metadata)[CLASSIFICATION] → Default to ${default_classification}; if unavailable, use "OFFICIAL" for UK Gov, "PUBLIC" otherwise (or prompt user)Calculated fields:
[YYYY-MM-DD] for Review Date → Current date + 30 daysPending fields (leave as [PENDING] until manually updated):
[REVIEWER_NAME] → [PENDING][APPROVER_NAME] → [PENDING][DISTRIBUTION_LIST] → Default to "Project Team, Architecture Team" or [PENDING]Populate Revision History:
| 1.0 | {DATE} | ArcKit AI | Initial creation from `$arckit-mod-secure` command | [PENDING] | [PENDING] |
Populate Generation Metadata Footer:
The footer should be populated with:
**Generated by**: ArcKit `$arckit-mod-secure` command
**Generated on**: {DATE} {TIME} GMT
**ArcKit Version**: {ARCKIT_VERSION}
**Project**: {PROJECT_NAME} (Project {PROJECT_ID})
**AI Model**: [Use actual model name, e.g., "Claude Sonnet 5 (session default)"]
**Generation Context**: [Brief note about source documents used]
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks plus the SECD-MOD per-type checks pass. Fix any failures before proceeding.
projects/[project-folder]/ARC-{PROJECT_ID}-SECD-MOD-v1.0.mdMark as CRITICAL if:
OFFICIAL:
OFFICIAL-SENSITIVE:
SECRET:
TOP SECRET:
Discovery/Alpha:
Beta:
Live:
Assess maturity across 8 domains (0-5 scale):
Target Level 3+ for operational systems.
SbD replaces point-in-time accreditation with continuous assurance:
Register on CAAT (Cyber Activity and Assurance Tracker)
Appoint Delivery Team Security Lead (DTSL)
Complete CAAT self-assessment question sets
Complete Business Impact Assessment (BIA)
Implement security controls
Conduct continuous security testing
Maintain continuous risk management
Supplier attestation (for systems delivered by suppliers)
Security governance reviews
Cryptography:
Network Security:
Authentication:
Monitoring:
# MOD Secure by Design Assessment
**Project**: MOD Personnel Management System
**Classification**: OFFICIAL-SENSITIVE
**Overall Security Posture**: Adequate (with gaps to address)
## Domain 1: Security Classification
**Status**: ✅ Compliant
**Evidence**: System handles personnel records (OFFICIAL-SENSITIVE), classification confirmed by IAO...
## Domain 5: Technical Security Controls
### 5.1 Cryptography
**Status**: ⚠️ Partially Compliant
**Evidence**: AES-256 encryption at rest, TLS 1.3 in transit, but key rotation not automated...
**Gaps**:
- Automated key rotation required (HIGH PRIORITY)
- HSM not yet deployed (MEDIUM PRIORITY)
### 5.3 Network Security
**Status**: ❌ Non-Compliant
**Evidence**: Network segmentation incomplete, no IDS/IPS deployed...
**Gaps**:
- Deploy network segmentation (CRITICAL - deployment blocker)
- Implement IDS/IPS (HIGH PRIORITY)
## Critical Issues
1. Network segmentation incomplete (Domain 5) - BLOCKER for deployment
2. Penetration test not completed (Domain 5) - Required before Beta
## Recommendations
**Critical** (0-30 days):
- Complete network segmentation - Security Architect - 30 days
- Schedule penetration test - DTSL - 15 days
Continuous assurance is mandatory for MOD systems throughout their lifecycle (replaced point-in-time accreditation August 2023)
CAAT registration required for all programmes from Discovery/Alpha phase
Non-compliance can block project progression, funding, and deployment
Delivery Team Security Lead (DTSL) engagement required from Discovery phase
Regular security reviews required (quarterly during development, annually in Live)
SROs and capability owners are accountable for security posture (not delegated to accreditation authority)
Classification determines security control requirements
Supplier attestation required for supplier-delivered systems (ISN 2023/10)
Insider threat is a primary concern for MOD - emphasize personnel security
Supply chain security critical due to foreign adversary threats
Operational security (OPSEC) essential for operational systems
Cyber security is a "licence to operate" - cannot be traded out or descoped
Markdown escaping: When writing less-than or greater-than comparisons, always include a space after < or > (e.g., < 3 seconds, > 99.9% uptime) to prevent markdown renderers from interpreting them as HTML tags or emoji
Generate the MOD Secure by Design assessment now based on the project information provided.