원클릭으로
arckit-secure
Generate a Secure by Design assessment for UK Government projects (civilian departments)
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Generate a Secure by Design assessment for UK Government projects (civilian departments)
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
[COMMUNITY] Generate a NHS DCB0129 manufacturer Clinical Safety Case Report and Hazard Log (Marcus Baw SAFETY.md 3-file spec) for a digital health product placed on the NHS market.
[COMMUNITY] Generate a NHS DCB0160 deployer Clinical Safety Case Report and deployment Hazard Log for an NHS organisation deploying or significantly configuring a health IT product into a specific clinical setting.
Document architectural decisions with options analysis and traceability
Design AI agent architecture — patterns, tool contracts, memory, orchestration, guardrails
Design AI agent governance — oversight models, approval workflows, audit requirements, compliance mapping
Assess AI agent program maturity across design, governance, security, integration, and operations
| name | arckit-secure |
| description | Generate a Secure by Design assessment for UK Government projects (civilian departments) |
You are helping to conduct a Secure by Design assessment for a UK Government technology project (civilian/non-MOD).
$ARGUMENTS
UK Government departments must follow NCSC (National Cyber Security Centre) guidance and achieve appropriate security certifications before deploying systems. This assessment evaluates security controls using the NCSC Cyber Assessment Framework (CAF).
Key UK Government Security References:
Note: Before generating, scan
projects/for existing project directories. For each project, list allARC-*.mdartifacts, checkexternal/for reference documents, and check000-global/for cross-project policies. If no external docs exist but they would improve output, ask the user.
Generate a comprehensive Secure by Design assessment document by:
Loading the template (with user override support):
.arckit/templates-custom/ukgov-secure-by-design-template.md exists in the project root.arckit/templates/ukgov-secure-by-design-template.md (default)Tip: Users can customize templates with
$arckit-customize secure
Understanding the project context:
Read existing artifacts from the project context:
MANDATORY (warn if missing):
projects/{project-name}/
$arckit-requirements firstprojects/000-global/)
$arckit-principles firstRECOMMENDED (read if available, note if missing):
projects/{project-name}/
projects/{project-name}/
projects/{project-name}/diagrams/
OPTIONAL (read if available, skip silently if missing):
projects/{project-name}/
projects/{project-name}/
projects/{project-name}/
Read external documents and policies:
external/ files) — extract vulnerability findings, risk ratings, remediation recommendations, threat actors, attack vectors, existing mitigations000-global/policies/) — extract security requirements, acceptable risk levels, mandatory controls, certification scope, validity datesprojects/000-global/external/ — extract enterprise security baselines, penetration test reports, cross-project security assessment patternsprojects/{project-dir}/external/ and re-run, or skip.".arckit/references/citation-instructions.md. Place inline citation markers (e.g., [PP-C1]) next to findings informed by source documents and populate the "External References" section in the template.Assess security using NCSC CAF (14 principles across 4 objectives):
Objective A: Managing Security Risk (4 principles)
Objective B: Protecting Against Cyber Attack (6 principles)
Objective C: Detecting Cyber Security Events (2 principles)
Objective D: Minimising the Impact of Incidents (2 principles)
Assess Cyber Essentials compliance (5 controls):
Assess UK GDPR compliance (if processing personal data):
For each CAF principle and control:
Calculate overall CAF score: X/14 principles achieved
Assess UK Government Cyber Security Standard compliance:
9.1 GovAssure Status — For critical systems subject to GovAssure assurance:
9.2 Secure by Design Confidence Rating — Self-assessment against SbD high-confidence profile:
9.3 Cyber Security Standard Exception Register — Per CSS clauses 4.3/4.4:
9.4 Cyber Action Plan Alignment — Assess alignment with the £210m cross-government Cyber Action Plan (February 2026):
Assess Government Cyber Security Profession alignment:
Map GovS 007: Security alignment:
Identify critical security issues:
Generate actionable recommendations:
Detect version: Before generating the document ID, check if a previous version exists:
ARC-{PROJECT_ID}-SECD-v*.md files in the project directorySave the document:
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks plus the SECD per-type checks pass. Fix any failures before proceeding.
Write to projects/[project-folder]/ARC-{PROJECT_ID}-SECD-v${VERSION}.md
CRITICAL - Auto-Populate Document Control Fields:
Before completing the document, populate ALL document control fields in the header:
ARC-{PROJECT_ID}-SECD-v{VERSION} (e.g., ARC-001-SECD-v1.0)Auto-populated fields (populate these automatically):
[PROJECT_ID] → Extract from project path (e.g., "001" from "projects/001-project-name")[VERSION] → Determined version from step 11[DATE] / [YYYY-MM-DD] → Current date in YYYY-MM-DD format[DOCUMENT_TYPE_NAME] → "Secure by Design Assessment"ARC-[PROJECT_ID]-SECD-v[VERSION] → Construct using format from Step 1[COMMAND] → "arckit.secure"User-provided fields (extract from project metadata or user input):
[PROJECT_NAME] → Full project name from project metadata or user input[OWNER_NAME_AND_ROLE] → Document owner (prompt user if not in metadata)[CLASSIFICATION] → Default to ${default_classification}; if unavailable, use "OFFICIAL" for UK Gov, "PUBLIC" otherwise (or prompt user)Calculated fields:
[YYYY-MM-DD] for Review Date → Current date + 30 days (requirements, research, risks)[YYYY-MM-DD] for Review Date → Phase gate dates (Alpha/Beta/Live for compliance docs)Pending fields (leave as [PENDING] until manually updated):
[REVIEWER_NAME] → [PENDING][APPROVER_NAME] → [PENDING][DISTRIBUTION_LIST] → Default to "Project Team, Architecture Team" or [PENDING]| 1.0 | {DATE} | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |
The footer should be populated with:
**Generated by**: ArcKit `$arckit-secure` command
**Generated on**: {DATE} {TIME} GMT
**ArcKit Version**: {ARCKIT_VERSION}
**Project**: {PROJECT_NAME} (Project {PROJECT_ID})
**AI Model**: [Use actual model name, e.g., "Claude Sonnet 5 (session default)"]
**Generation Context**: [Brief note about source documents used]
## Document Control
| Field | Value |
|-------|-------|
| **Document ID** | ARC-001-SECD-v1.0 |
| **Document Type** | {Document purpose} |
| **Project** | Windows 10 to Windows 11 Migration (Project 001) |
| **Classification** | OFFICIAL-SENSITIVE |
| **Status** | DRAFT |
| **Version** | 1.0 |
| **Created Date** | 2025-10-29 |
| **Last Modified** | 2025-10-29 |
| **Review Date** | 2025-11-30 |
| **Owner** | John Smith (Business Analyst) |
| **Reviewed By** | [PENDING] |
| **Approved By** | [PENDING] |
| **Distribution** | PM Team, Architecture Team, Dev Team |
## Revision History
| Version | Date | Author | Changes | Approved By | Approval Date |
|---------|------|--------|---------|-------------|---------------|
| 1.0 | 2025-10-29 | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |
Mark as CRITICAL if:
PUBLIC:
OFFICIAL:
OFFICIAL-SENSITIVE:
Discovery/Alpha:
Beta:
Live:
Basic Cyber Essentials: Self-assessment questionnaire Cyber Essentials Plus: External technical verification
Required for:
Required if:
Responsibilities:
Cyber Essentials Controls:
Cloud Hosting:
Network Security:
# UK Government Secure by Design Assessment
**Project**: HMRC Tax Credits Modernization
**Department**: HMRC
**Data Classification**: OFFICIAL-SENSITIVE
**NCSC CAF Score**: 11/14 Achieved
## NCSC CAF Assessment
### Objective A: Managing Security Risk
#### A1: Governance
**Status**: ✅ Achieved
**Evidence**: SIRO appointed (Director of Digital Services), security policies approved, quarterly security reviews...
#### A2: Risk Management
**Status**: ⚠️ Partially Achieved
**Evidence**: Risk register exists, but threat modeling incomplete...
**Gaps**:
- Complete threat modeling for payment processing (HIGH - 30 days)
- Update risk register with emerging threats (MEDIUM - 60 days)
### Objective B: Protecting Against Cyber Attack
#### B3: Data Security
**Status**: ⚠️ Partially Achieved
**Evidence**: TLS 1.3 in transit, AES-256 at rest, but DPIA not completed...
**Gaps**:
- Complete DPIA before Beta (CRITICAL - blocker for Beta phase)
- Implement Data Loss Prevention (HIGH - 90 days)
## Cyber Essentials
**Status**: Certified Basic (expires 2024-06-30)
**Target**: Cyber Essentials Plus by Beta
**Gaps**:
- External vulnerability scan required for Plus certification
## UK GDPR Compliance
**Status**: ⚠️ Partially Compliant
**DPO**: Appointed ([Data Protection Officer Name])
**DPIA**: Not completed (REQUIRED before Beta)
**Critical Issues**:
1. DPIA not completed for tax credit processing (CRITICAL)
2. Data retention policy not documented (HIGH)
## Critical Issues
1. DPIA incomplete (CAF B3, UK GDPR) - Blocks Beta phase
2. Threat modeling incomplete (CAF A2) - Significant risk gap
## Recommendations
**Critical** (0-30 days):
- Complete DPIA - DPO - 15 days
- Complete threat model - Security Architect - 30 days
NCSC CAF is the standard framework for UK Government security assessment
Cyber Essentials is mandatory for most government contracts
UK GDPR compliance is legally required for personal data processing
SIRO sign-off required for security risk acceptance
Data classification drives security controls - OFFICIAL-SENSITIVE requires stronger controls
Penetration testing recommended annually minimum
Incident response - 72-hour reporting to ICO for personal data breaches
Cloud First - prefer cloud hosting, assess against NCSC Cloud Security Principles
Markdown escaping: When writing less-than or greater-than comparisons, always include a space after < or > (e.g., < 3 seconds, > 99.9% uptime) to prevent markdown renderers from interpreting them as HTML tags or emoji
Generate the UK Government Secure by Design assessment now based on the project information provided.