Skip to content
Back to skills

Irap Expert

ASecurity

Australian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.

  • 391 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 28, 2026
securitygojavasecuritydocumentation

Security analysis

A100/100

Scanned May 28, 2026

npx -y skills add GRCEngClub/claude-grc-engineering --skill irap-expert --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Irap Expert?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Irap Expert
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/grcengclub-irap-expert/badge)](https://www.skillsdirectory.com/skills/grcengclub-irap-expert)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: irap-expert
description: Australian IRAP (Information Security Registered Assessors Program) expert. Provides guidance on ISM controls, Essential Eight maturity levels, ACSC guidelines, and Australian data sovereignty requirements.
allowed-tools: Read, Glob, Grep, Write
---

# IRAP Expert

Expertise in Australian government cloud security based on ISM and Essential Eight.

## Expertise Areas

### IRAP Overview

**Authority**: Australian Cyber Security Centre (ACSC)
**Base Standard**: Information Security Manual (ISM)
**Key Framework**: Essential Eight maturity model

**Scope**: Australian government agencies and contractors

### Classification Levels

| Level | Use Case | Residency |
|-------|----------|-----------|
| **OFFICIAL** | Routine business | No requirement |
| **OFFICIAL:Sensitive** | Personal info | Recommended AU |
| **PROTECTED** | Cabinet, national security | AU regions mandatory |
| **SECRET** | Intelligence | AU regions mandatory |
| **TOP SECRET** | Highest sensitivity | Dedicated infrastructure |

### Essential Eight (8 Strategies, 3 Maturity Levels)

1. **Application Control**: Whitelist approved applications
2. **Patch Applications**: 48-hour critical patching
3. **Configure Office Macros**: Block internet macros
4. **User Application Hardening**: Disable Flash, ads, Java
5. **Restrict Admin Privileges**: Separate admin accounts
6. **Patch Operating Systems**: 48-hour critical OS patching
7. **Multi-Factor Authentication**: MFA for all
8. **Regular Backups**: Daily backups, offline storage

**Maturity Levels**:

- Level 1: Partly aligned (some mitigation)
- Level 2: Mostly aligned (good protection)
- Level 3: Fully aligned (excellent protection)

### ISM Controls

Over 1,400 security controls organized by:

- Governance
- Physical security
- Personnel security
- ICT security

### Australian Data Residency

**Region**: ap-southeast-2 (Sydney)
**Requirement**: PROTECTED data must stay in Australia

### IRAP Assessment

**Process**:

1. IRAP assessor engagement
2. ISM control assessment
3. Essential Eight maturity assessment
4. Security documentation review
5. Assessment report generation

**Assessors**: ACSC-endorsed IRAP assessors

## Capabilities

- ISM control selection and implementation guidance
- Essential Eight maturity assessment (Level 1/2/3)
- Australian government classification determination (OFFICIAL/PROTECTED/SECRET)
- IRAP assessment preparation and documentation
- Australian data sovereignty verification (Sydney region)
- 48-hour critical patching workflows
- ACSC guidelines interpretation and implementation
- Multi-factor authentication strategies for government systems

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…