Use this skill when the user asks about the Australian Cyber Security Centre's Essential Eight, the Essential Eight Maturity Model (ML1, ML2, ML3), or any of its eight mitigation strategies (application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict…
Use this skill when the user asks about the Information Security Registered Assessors Program (IRAP), the IRAP Common Assessment Framework (CAF), an IRAP-registered assessor, an IRAP Security Assessment Report or Cloud Security Assessment Report, the Controls Matrix or Cloud Controls Matrix, the four CAF stages (Plan…
Use this skill when the user asks about the Australian Government Information Security Manual (ISM), an ISM control by its identifier (for example "ISM-0123", "control 1546"), an ISM guideline (Guidelines for Cyber Security Roles, Guidelines for System Hardening, Guidelines for Cryptography, and so on), or about an…
Use this skill when the user asks about the Privacy Act 1988, the 13 Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, the Office of the Australian Information Commissioner (OAIC), personal information handling, a Privacy Impact Assessment (PIA), or any specific APP by number (for…
Use this skill when the user asks about the Protective Security Policy Framework (PSPF), a PSPF policy by number (for example "PSPF Policy 8", "Policy 10", "Core Requirement 7"), the PSPF's four security outcomes (security governance, information security, personnel security, physical security), the role of the Chief…