UK Government Secure by Design Assessment
You are helping to conduct a Secure by Design assessment for a UK Government technology project (civilian/non-MOD).
User Input
$ARGUMENTS
Context
UK Government departments must follow NCSC (National Cyber Security Centre) guidance and achieve appropriate security certifications before deploying systems. This assessment evaluates security controls using the NCSC Cyber Assessment Framework (CAF).
Key UK Government Security References:
- NCSC Cyber Assessment Framework (CAF)
- UK Government Cyber Security Standard (July 2025, Cabinet Office)
- NCSC Vulnerability Monitoring Service (VMS)
- Government Cyber Security Profession & Cyber Academy
- Cyber Essentials / Cyber Essentials Plus
- UK GDPR and Data Protection Act 2018
- Government Security Classifications Policy
- Cloud Security Principles
Your Task
Note: Before generating, scan projects/ for existing project directories. For each project, list all ARC-*.md artifacts, check external/ for reference documents, and check 000-global/ for cross-project policies. If no external docs exist but they would improve output, ask the user.
Generate a comprehensive Secure by Design assessment document by:
Loading the template (with user override support):
- First, check if
.arckit/templates-custom/ukgov-secure-by-design-template.md exists in the project root
- If found: Read the user's customized template (user override takes precedence)
- If not found: Read
.arckit/templates/ukgov-secure-by-design-template.md (default)
- Then read
.arckit/templates/_partials/RENDERING.md and resolve the <!-- DOC-CONTROL-HEADER --> marker in the template before writing. Do not hand-write the Document Control table: the partial RENDERING.md selects is the only source of the 14 standard fields and of the classification ladder.
Tip: Users can customize templates with $arckit-customize secure
Understanding the project context:
- Department/organization (HMRC, DWP, Home Office, DEFRA, etc.)
- Data classification (PUBLIC, OFFICIAL, OFFICIAL-SENSITIVE)
- Project phase (Discovery, Alpha, Beta, Live)
- User base (public-facing, internal staff, both)
- Hosting approach (cloud, on-premise, hybrid)
Read existing artifacts from the project context:
MANDATORY (warn if missing):
- REQ (Requirements) in
projects/{project-name}/
- Extract: NFR-SEC (security), NFR-P (performance), NFR-A (availability), INT (integration), DR (data) requirements
- If missing: warn user to run
$arckit-requirements first
- PRIN (Architecture Principles, in
projects/000-global/)
- Extract: Security standards, approved platforms, compliance requirements, cloud policy
- If missing: warn user to run
$arckit-principles first
RECOMMENDED (read if available, note if missing):
- RISK (Risk Register) in
projects/{project-name}/
- Extract: Security risks, threat model, risk appetite, mitigations
- DPIA (DPIA) in
projects/{project-name}/
- Extract: Personal data processing, lawful basis, data protection risks
- DIAG (Architecture Diagrams) in
projects/{project-name}/diagrams/
- Extract: Deployment topology, network boundaries, data flows, integration points
OPTIONAL (read if available, skip silently if missing):
- TCOP (TCoP Assessment) in
projects/{project-name}/
- Extract: Technology governance compliance, Point 6 (Secure) findings
- AIPB (AI Playbook) in
projects/{project-name}/
- Extract: AI-specific security requirements (prompt injection, data poisoning)
- ATRS (ATRS record) in
projects/{project-name}/
- Extract: Algorithmic transparency security requirements
Read external documents and policies:
- Read any external documents listed in the project context (
external/ files) — extract vulnerability findings, risk ratings, remediation recommendations, threat actors, attack vectors, existing mitigations
- Read any global policies listed in the project context (
000-global/policies/) — extract security requirements, acceptable risk levels, mandatory controls, certification scope, validity dates
- Read any enterprise standards in
projects/000-global/external/ — extract enterprise security baselines, penetration test reports, cross-project security assessment patterns
- If no external docs exist but they would improve the assessment, ask: "Do you have any existing security assessments, pen test reports, or threat models? I can read PDFs and images directly. Place them in
projects/{project-dir}/external/ and re-run, or skip."
- Citation traceability: When referencing content from external documents, follow the citation instructions in
.arckit/references/citation-instructions.md. Place inline citation markers (e.g., [PP-C1]) next to findings informed by source documents and populate the "External References" section in the template.
Assess security using NCSC CAF (14 principles across 4 objectives):
Objective A: Managing Security Risk (4 principles)
- A1: Governance - SIRO appointed, security policies, oversight
- A2: Risk Management - Asset classification, risk register, treatment plans
- A3: Asset Management - Inventory of hardware, software, data
- A4: Supply Chain - Vendor assessments, contracts, third-party controls
Objective B: Protecting Against Cyber Attack (6 principles)
- B1: Service Protection Policies - Acceptable use, access control, data protection policies
- B2: Identity and Access Control - MFA, PAM, least privilege, access reviews
- B3: Data Security - Encryption, UK GDPR compliance, DPIA, DLP
- B4: System Security - Patching, hardening, anti-malware, EDR
- B5: Resilient Networks - Segmentation, firewalls, IDS/IPS, VPN
- B6: Staff Awareness - Security training, phishing awareness, data protection
Objective C: Detecting Cyber Security Events (2 principles)
- C1: Security Monitoring - SIEM, alerting, logging, threat intelligence
- C2: Proactive Security Event Discovery - Vulnerability scanning (including NCSC VMS enrollment), pen testing, threat hunting
Objective D: Minimising the Impact of Incidents (2 principles)
- D1: Response and Recovery Planning - Incident response, BC/DR, RTO/RPO
- D2: Improvements - Post-incident reviews, metrics, continuous improvement
Assess Cyber Essentials compliance (5 controls):
- Firewalls - Boundary firewalls configured
- Secure Configuration - Hardened systems, unnecessary services disabled
- Access Control - User accounts, MFA, least privilege
- Malware Protection - Anti-malware on all devices
- Patch Management - Timely patching (critical within 14 days)
Assess UK GDPR compliance (if processing personal data):
- DPO appointed (if required)
- Lawful basis identified
- Privacy notice published
- Data subject rights procedures
- DPIA completed (if high risk)
- Data breach notification process (72 hours to ICO)
- Records of Processing Activities (ROPA)
For each CAF principle and control:
- Assess status: ✅ Achieved / ⚠️ Partially Achieved / ❌ Not Achieved / N/A
- Gather evidence from project documents
- Check relevant security controls
- Identify gaps and risks
- Provide specific remediation actions with owners and timelines
Calculate overall CAF score: X/14 principles achieved
Assess UK Government Cyber Security Standard compliance:
9.1 GovAssure Status — For critical systems subject to GovAssure assurance:
- Identify which systems are in scope for the current GovAssure cycle
- Record assessment status per system (Planned / In Progress / Complete)
- Summarize findings and remediation status
- Reference NCSC GovAssure guidance
9.2 Secure by Design Confidence Rating — Self-assessment against SbD high-confidence profile:
- Assess confidence level (Low / Medium / High)
- Evaluate against SbD principles: secure development, secure deployment, secure operation
- Document evidence of high-confidence profile achievement
- Identify gaps and improvement actions
9.3 Cyber Security Standard Exception Register — Per CSS clauses 4.3/4.4:
- Record any exceptions to CSS compliance with clause references
- Assess risk for each exception
- Document mitigation measures and approval authority
- Track improvement plans to achieve compliance
9.4 Cyber Action Plan Alignment — Assess alignment with the £210m cross-government Cyber Action Plan (February 2026):
- Determine departmental enrollment and participation status
- Map project activities to the four Cyber Action Plan pillars: Skills & Workforce, Tooling & Infrastructure, Resilience & Response, Collaboration & Sharing
- Identify investment alignment and funding opportunities
- Record gaps where the project or department does not yet meet Cyber Action Plan expectations
Assess Government Cyber Security Profession alignment:
- Determine whether the department participates in the Government Cyber Security Profession
- Record Certified Cyber Professional (CCP) certification status for project security roles
- Map security roles to DDaT (Digital, Data and Technology) profession framework
- Assess engagement with the Government Cyber Academy (learning areas, completions)
- Identify workforce development gaps and training actions
Map GovS 007: Security alignment:
- Complete the GovS 007 principle mapping table (9 principles → CAF sections and ArcKit artefacts)
- For principle 5 (Security culture), reference Section 11 (Government Cyber Security Profession) in addition to CAF B6
- For principle 8 (Continuous improvement), reference Section 9.4 (Cyber Action Plan Alignment) in addition to CAF D2
- Identify named security role holders (SSRO, DSO, SIRO) and populate the security roles table
- Assess status for each GovS 007 principle based on evidence from sections 1–9 and the Cyber Action Plan / Profession sections
Identify critical security issues:
- Issues that block progression to next phase
- Unacceptable risk levels
- Regulatory non-compliance (UK GDPR, Data Protection Act)
Generate actionable recommendations:
- Critical priority (0-30 days) - blockers for next phase
- High priority (1-3 months) - significant risk reduction
- Medium priority (3-6 months) - continuous improvement
- Include VMS enrollment and Cyber Action Plan alignment actions where applicable
Detect version: Before generating the document ID, check if a previous version exists:
- Look for existing
ARC-{PROJECT_ID}-SECD-v*.md files in the project directory
- If no existing file: Use VERSION="1.0"
- If existing file found:
- Read the existing document to understand its scope
- Compare against current inputs and project state
- Minor increment (e.g., 1.0 → 1.1): Scope unchanged — refreshed assessments, updated control status, corrected details
- Major increment (e.g., 1.0 → 2.0): Scope materially changed — new CAF objectives assessed, fundamentally different security posture, significant architecture changes
- For v1.1+/v2.0+: Add a Revision History entry describing what changed from the previous version
Save the document:
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks plus the SECD per-type checks pass. Fix any failures before proceeding.
Write to projects/[project-folder]/ARC-{PROJECT_ID}-SECD-v${VERSION}.md
CRITICAL - Auto-Populate Document Control Fields:
Before completing the document, populate ALL document control fields in the header:
Step 1: Construct Document ID
- Document ID:
ARC-{PROJECT_ID}-SECD-v{VERSION} (e.g., ARC-001-SECD-v1.0)
Step 2: Populate Required Fields
Auto-populated fields (populate these automatically):
[PROJECT_ID] → Extract from project path (e.g., "001" from "projects/001-project-name")
[VERSION] → Determined version from step 11
[DATE] / [YYYY-MM-DD] → Current date in YYYY-MM-DD format
[DOCUMENT_TYPE_NAME] → "Secure by Design Assessment"
ARC-[PROJECT_ID]-SECD-v[VERSION] → Construct using format from Step 1
[COMMAND] → "arckit.secure"
User-provided fields (extract from project metadata or user input):
[PROJECT_NAME] → Full project name from project metadata or user input
[OWNER_NAME_AND_ROLE] → Document owner (prompt user if not in metadata)
- Classification → comes from the resolved Document Control header, not from a placeholder.
_partials/RENDERING.md fixes the ladder from the artefact's own regime; ${default_classification} applies only where that regime falls through to user config.
Calculated fields:
[YYYY-MM-DD] for Next Review Date → Current date + 30 days (requirements, research, risks)
[YYYY-MM-DD] for Next Review Date → Phase gate dates (Alpha/Beta/Live for compliance docs)
Pending fields (leave as [PENDING] until manually updated):
[REVIEWER_NAME] → [PENDING]
[APPROVER_NAME] → [PENDING]
[DISTRIBUTION_LIST] → Default to "Project Team, Architecture Team" or [PENDING]
Step 3: Populate Revision History
| 1.0 | {DATE} | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |
Step 4: Populate Generation Metadata Footer
The footer should be populated with:
**Generated by**: ArcKit `$arckit-secure` command
**Generated on**: {DATE} {TIME} GMT
**ArcKit Version**: {ARCKIT_VERSION}
**Project**: {PROJECT_NAME} (Project {PROJECT_ID})
**AI Model**: [Use actual model name, e.g., "Claude Sonnet 5 (session default)"]
**Generation Context**: [Brief note about source documents used]
Example Rendered Header and Revision History
## Document Control
<!-- DOC-CONTROL-HEADER -->
<!-- Resolved at command-execution time per _partials/RENDERING.md. -->
## Revision History
| Version | Date | Author | Changes | Approved By | Approval Date |
|---------|------|--------|---------|-------------|---------------|
| 1.0 | 2025-10-29 | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |
Assessment Guidelines
Status Indicators
- ✅ Achieved: All key controls implemented and effective, no significant gaps
- ⚠️ Partially Achieved: Some controls in place but gaps remain
- ❌ Not Achieved: Controls not implemented or ineffective
- N/A: Principle genuinely not applicable
Critical Security Issues (Phase Blockers)
Mark as CRITICAL if:
- No UK GDPR compliance for personal data processing
- No DPIA for high-risk processing
- No encryption for sensitive data (OFFICIAL-SENSITIVE)
- Cyber Essentials not obtained (required for most gov contracts)
- No incident response capability
- No backup/recovery capability
- Critical vulnerabilities unpatched (>30 days)
- No MFA for privileged access
- SIRO not appointed or engaged
Data Classification Requirements
PUBLIC:
- Basic security controls
- No special encryption requirements
- Standard access controls
OFFICIAL:
- Cyber Essentials baseline minimum
- Encryption in transit (TLS 1.2+)
- Access control and audit logging
- Regular security patching
OFFICIAL-SENSITIVE:
- Cyber Essentials Plus recommended
- Encryption at rest and in transit (strong algorithms)
- Multi-factor authentication required
- Enhanced audit logging
- DPIA if processing personal data
- Data loss prevention controls
Project Phase Considerations
Discovery/Alpha:
- Security principles identified
- Data classification determined
- Initial risk assessment
- Security requirements defined
- SIRO engaged
Beta:
- Security controls implemented
- Penetration testing completed
- DPIA completed (if required)
- Cyber Essentials certification obtained
- Vulnerability management operational
- Incident response plan documented
Live:
- All CAF principles addressed
- Cyber Essentials Plus for high-risk systems
- Continuous security monitoring
- Regular penetration testing (annual minimum)
- Security incident capability proven
- Annual security review with SIRO
Cyber Essentials Requirements
Basic Cyber Essentials: Self-assessment questionnaire
Cyber Essentials Plus: External technical verification
Required for:
- All central government contracts involving handling personal data
- Contracts valued at £5 million or more
- Most public sector technology procurements
UK Government Context
Senior Information Risk Owner (SIRO)
- Senior executive responsible for information risk
- Must be board-level or equivalent
- Reviews and approves risk treatment
- Signs off on major security decisions
- Typically Permanent Secretary or Director level
Data Protection Officer (DPO)
Required if:
- Public authority or public body
- Core activities involve regular/systematic monitoring
- Core activities involve large-scale processing of special category data
Responsibilities:
- Advise on UK GDPR compliance
- Monitor compliance with UK GDPR
- Advise on DPIA
- Liaise with ICO
Information Commissioner's Office (ICO)
- UK's independent data protection regulator
- Enforces UK GDPR and Data Protection Act 2018
- Must be notified of data breaches within 72 hours
- Can impose fines up to £17.5 million or 4% of turnover
Common UK Government Security Requirements
Cyber Essentials Controls:
- Firewalls and internet gateways configured
- Secure configuration (CIS benchmarks)
- User access control (least privilege, MFA)
- Malware protection (up-to-date anti-malware)
- Security update management (patching within 14 days)
Cloud Hosting:
- Prefer UK or EU data centers for data residency
- NCSC Cloud Security Principles compliance
- Cloud provider certifications (ISO 27001, etc.)
- Clear data ownership and portability
Network Security:
- PSN (Public Services Network) connectivity if required
- Network segmentation by sensitivity
- VPN for remote access
- WiFi security (WPA3 preferred, WPA2 minimum)
Example Output Structure
# UK Government Secure by Design Assessment
**Project**: HMRC Tax Credits Modernization
**Department**: HMRC
**Data Classification**: OFFICIAL-SENSITIVE
**NCSC CAF Score**: 11/14 Achieved
## NCSC CAF Assessment
### Objective A: Managing Security Risk
#### A1: Governance
**Status**: ✅ Achieved
**Evidence**: SIRO appointed (Director of Digital Services), security policies approved, quarterly security reviews...
#### A2: Risk Management
**Status**: ⚠️ Partially Achieved
**Evidence**: Risk register exists, but threat modeling incomplete...
**Gaps**:
- Complete threat modeling for payment processing (HIGH - 30 days)
- Update risk register with emerging threats (MEDIUM - 60 days)
### Objective B: Protecting Against Cyber Attack
#### B3: Data Security
**Status**: ⚠️ Partially Achieved
**Evidence**: TLS 1.3 in transit, AES-256 at rest, but DPIA not completed...
**Gaps**:
- Complete DPIA before Beta (CRITICAL - blocker for Beta phase)
- Implement Data Loss Prevention (HIGH - 90 days)
## Cyber Essentials
**Status**: Certified Basic (expires 2024-06-30)
**Target**: Cyber Essentials Plus by Beta
**Gaps**:
- External vulnerability scan required for Plus certification
## UK GDPR Compliance
**Status**: ⚠️ Partially Compliant
**DPO**: Appointed ([Data Protection Officer Name])
**DPIA**: Not completed (REQUIRED before Beta)
**Critical Issues**:
1. DPIA not completed for tax credit processing (CRITICAL)
2. Data retention policy not documented (HIGH)
## Critical Issues
1. DPIA incomplete (CAF B3, UK GDPR) - Blocks Beta phase
2. Threat modeling incomplete (CAF A2) - Significant risk gap
## Recommendations
**Critical** (0-30 days):
- Complete DPIA - DPO - 15 days
- Complete threat model - Security Architect - 30 days
Important Notes
NCSC CAF is the standard framework for UK Government security assessment
Cyber Essentials is mandatory for most government contracts
UK GDPR compliance is legally required for personal data processing
SIRO sign-off required for security risk acceptance
Data classification drives security controls - OFFICIAL-SENSITIVE requires stronger controls
Penetration testing recommended annually minimum
Incident response - 72-hour reporting to ICO for personal data breaches
Cloud First - prefer cloud hosting, assess against NCSC Cloud Security Principles
Markdown escaping: When writing less-than or greater-than comparisons, always include a space after < or > (e.g., < 3 seconds, > 99.9% uptime) to prevent markdown renderers from interpreting them as HTML tags or emoji
Related UK Government Standards
- NCSC Cyber Assessment Framework (CAF)
- UK Government Cyber Security Standard (July 2025, Cabinet Office)
- NCSC Vulnerability Monitoring Service (VMS)
- Government Cyber Security Profession & Cyber Academy
- £210m Cyber Action Plan (February 2026)
- Cyber Essentials Scheme
- UK Government Security Classifications
- Government Functional Standard GovS 007: Security
- NCSC Cloud Security Principles
- HMG Security Policy Framework
- Public Services Network (PSN) Code of Connection
Resources
Generate the UK Government Secure by Design assessment now based on the project information provided.
1---2name: arckit-secure3description: Generate a Secure by Design assessment for UK Government projects (civilian departments)4---56# UK Government Secure by Design Assessment78You are helping to conduct a **Secure by Design assessment** for a UK Government technology project (civilian/non-MOD).910## User Input1112```text13$ARGUMENTS14```1516## Context1718UK Government departments must follow NCSC (National Cyber Security Centre) guidance and achieve appropriate security certifications before deploying systems. This assessment evaluates security controls using the NCSC Cyber Assessment Framework (CAF).1920**Key UK Government Security References**:2122- NCSC Cyber Assessment Framework (CAF)23- UK Government Cyber Security Standard (July 2025, Cabinet Office)24- NCSC Vulnerability Monitoring Service (VMS)25- Government Cyber Security Profession & Cyber Academy26- Cyber Essentials / Cyber Essentials Plus27- UK GDPR and Data Protection Act 201828- Government Security Classifications Policy29- Cloud Security Principles3031## Your Task3233> **Note**: Before generating, scan `projects/` for existing project directories. For each project, list all `ARC-*.md` artifacts, check `external/` for reference documents, and check `000-global/` for cross-project policies. If no external docs exist but they would improve output, ask the user.3435Generate a comprehensive Secure by Design assessment document by:36371. **Loading the template** (with user override support):38 - **First**, check if `.arckit/templates-custom/ukgov-secure-by-design-template.md` exists in the project root39 - **If found**: Read the user's customized template (user override takes precedence)40 - **If not found**: Read `.arckit/templates/ukgov-secure-by-design-template.md` (default)41 - **Then read** `.arckit/templates/_partials/RENDERING.md` and resolve the `<!-- DOC-CONTROL-HEADER -->` marker in the template before writing. Do not hand-write the Document Control table: the partial `RENDERING.md` selects is the only source of the 14 standard fields and of the classification ladder.4243 > **Tip**: Users can customize templates with `$arckit-customize secure`44452. **Understanding the project context**:46 - Department/organization (HMRC, DWP, Home Office, DEFRA, etc.)47 - Data classification (PUBLIC, OFFICIAL, OFFICIAL-SENSITIVE)48 - Project phase (Discovery, Alpha, Beta, Live)49 - User base (public-facing, internal staff, both)50 - Hosting approach (cloud, on-premise, hybrid)51523. **Read existing artifacts from the project context:**5354 **MANDATORY** (warn if missing):55 - **REQ** (Requirements) in `projects/{project-name}/`56 - Extract: NFR-SEC (security), NFR-P (performance), NFR-A (availability), INT (integration), DR (data) requirements57 - If missing: warn user to run `$arckit-requirements` first58 - **PRIN** (Architecture Principles, in `projects/000-global/`)59 - Extract: Security standards, approved platforms, compliance requirements, cloud policy60 - If missing: warn user to run `$arckit-principles` first6162 **RECOMMENDED** (read if available, note if missing):63 - **RISK** (Risk Register) in `projects/{project-name}/`64 - Extract: Security risks, threat model, risk appetite, mitigations65 - **DPIA** (DPIA) in `projects/{project-name}/`66 - Extract: Personal data processing, lawful basis, data protection risks67 - **DIAG** (Architecture Diagrams) in `projects/{project-name}/diagrams/`68 - Extract: Deployment topology, network boundaries, data flows, integration points6970 **OPTIONAL** (read if available, skip silently if missing):71 - **TCOP** (TCoP Assessment) in `projects/{project-name}/`72 - Extract: Technology governance compliance, Point 6 (Secure) findings73 - **AIPB** (AI Playbook) in `projects/{project-name}/`74 - Extract: AI-specific security requirements (prompt injection, data poisoning)75 - **ATRS** (ATRS record) in `projects/{project-name}/`76 - Extract: Algorithmic transparency security requirements77784. **Read external documents and policies**:79 - Read any **external documents** listed in the project context (`external/` files) — extract vulnerability findings, risk ratings, remediation recommendations, threat actors, attack vectors, existing mitigations80 - Read any **global policies** listed in the project context (`000-global/policies/`) — extract security requirements, acceptable risk levels, mandatory controls, certification scope, validity dates81 - Read any **enterprise standards** in `projects/000-global/external/` — extract enterprise security baselines, penetration test reports, cross-project security assessment patterns82 - If no external docs exist but they would improve the assessment, ask: "Do you have any existing security assessments, pen test reports, or threat models? I can read PDFs and images directly. Place them in `projects/{project-dir}/external/` and re-run, or skip."83 - **Citation traceability**: When referencing content from external documents, follow the citation instructions in `.arckit/references/citation-instructions.md`. Place inline citation markers (e.g., `[PP-C1]`) next to findings informed by source documents and populate the "External References" section in the template.84855. **Assess security using NCSC CAF (14 principles across 4 objectives)**:8687 **Objective A: Managing Security Risk (4 principles)**88 - A1: Governance - SIRO appointed, security policies, oversight89 - A2: Risk Management - Asset classification, risk register, treatment plans90 - A3: Asset Management - Inventory of hardware, software, data91 - A4: Supply Chain - Vendor assessments, contracts, third-party controls9293 **Objective B: Protecting Against Cyber Attack (6 principles)**94 - B1: Service Protection Policies - Acceptable use, access control, data protection policies95 - B2: Identity and Access Control - MFA, PAM, least privilege, access reviews96 - B3: Data Security - Encryption, UK GDPR compliance, DPIA, DLP97 - B4: System Security - Patching, hardening, anti-malware, EDR98 - B5: Resilient Networks - Segmentation, firewalls, IDS/IPS, VPN99 - B6: Staff Awareness - Security training, phishing awareness, data protection100101 **Objective C: Detecting Cyber Security Events (2 principles)**102 - C1: Security Monitoring - SIEM, alerting, logging, threat intelligence103 - C2: Proactive Security Event Discovery - Vulnerability scanning (including NCSC VMS enrollment), pen testing, threat hunting104105 **Objective D: Minimising the Impact of Incidents (2 principles)**106 - D1: Response and Recovery Planning - Incident response, BC/DR, RTO/RPO107 - D2: Improvements - Post-incident reviews, metrics, continuous improvement1081096. **Assess Cyber Essentials compliance (5 controls)**:110 - Firewalls - Boundary firewalls configured111 - Secure Configuration - Hardened systems, unnecessary services disabled112 - Access Control - User accounts, MFA, least privilege113 - Malware Protection - Anti-malware on all devices114 - Patch Management - Timely patching (critical within 14 days)1151167. **Assess UK GDPR compliance (if processing personal data)**:117 - DPO appointed (if required)118 - Lawful basis identified119 - Privacy notice published120 - Data subject rights procedures121 - DPIA completed (if high risk)122 - Data breach notification process (72 hours to ICO)123 - Records of Processing Activities (ROPA)1241258. **For each CAF principle and control**:126 - Assess status: ✅ Achieved / ⚠️ Partially Achieved / ❌ Not Achieved / N/A127 - Gather evidence from project documents128 - Check relevant security controls129 - Identify gaps and risks130 - Provide specific remediation actions with owners and timelines1311329. **Calculate overall CAF score**: X/14 principles achieved13313410. **Assess UK Government Cyber Security Standard compliance**:135136 **9.1 GovAssure Status** — For critical systems subject to GovAssure assurance:137 - Identify which systems are in scope for the current GovAssure cycle138 - Record assessment status per system (Planned / In Progress / Complete)139 - Summarize findings and remediation status140 - Reference NCSC GovAssure guidance141142 **9.2 Secure by Design Confidence Rating** — Self-assessment against SbD high-confidence profile:143 - Assess confidence level (Low / Medium / High)144 - Evaluate against SbD principles: secure development, secure deployment, secure operation145 - Document evidence of high-confidence profile achievement146 - Identify gaps and improvement actions147148 **9.3 Cyber Security Standard Exception Register** — Per CSS clauses 4.3/4.4:149 - Record any exceptions to CSS compliance with clause references150 - Assess risk for each exception151 - Document mitigation measures and approval authority152 - Track improvement plans to achieve compliance153154 **9.4 Cyber Action Plan Alignment** — Assess alignment with the £210m cross-government Cyber Action Plan (February 2026):155 - Determine departmental enrollment and participation status156 - Map project activities to the four Cyber Action Plan pillars: Skills & Workforce, Tooling & Infrastructure, Resilience & Response, Collaboration & Sharing157 - Identify investment alignment and funding opportunities158 - Record gaps where the project or department does not yet meet Cyber Action Plan expectations15916010. **Assess Government Cyber Security Profession alignment**:161 - Determine whether the department participates in the Government Cyber Security Profession162 - Record Certified Cyber Professional (CCP) certification status for project security roles163 - Map security roles to DDaT (Digital, Data and Technology) profession framework164 - Assess engagement with the Government Cyber Academy (learning areas, completions)165 - Identify workforce development gaps and training actions16616711. **Map GovS 007: Security alignment**:168 - Complete the GovS 007 principle mapping table (9 principles → CAF sections and ArcKit artefacts)169 - For principle 5 (Security culture), reference Section 11 (Government Cyber Security Profession) in addition to CAF B6170 - For principle 8 (Continuous improvement), reference Section 9.4 (Cyber Action Plan Alignment) in addition to CAF D2171 - Identify named security role holders (SSRO, DSO, SIRO) and populate the security roles table172 - Assess status for each GovS 007 principle based on evidence from sections 1–9 and the Cyber Action Plan / Profession sections17317412. **Identify critical security issues**:175176- Issues that block progression to next phase177- Unacceptable risk levels178- Regulatory non-compliance (UK GDPR, Data Protection Act)17918013. **Generate actionable recommendations**:181 - Critical priority (0-30 days) - blockers for next phase182 - High priority (1-3 months) - significant risk reduction183 - Medium priority (3-6 months) - continuous improvement184 - Include VMS enrollment and Cyber Action Plan alignment actions where applicable18518614. **Detect version**: Before generating the document ID, check if a previous version exists:187 - Look for existing `ARC-{PROJECT_ID}-SECD-v*.md` files in the project directory188 - **If no existing file**: Use VERSION="1.0"189 - **If existing file found**:190 - Read the existing document to understand its scope191 - Compare against current inputs and project state192 - **Minor increment** (e.g., 1.0 → 1.1): Scope unchanged — refreshed assessments, updated control status, corrected details193 - **Major increment** (e.g., 1.0 → 2.0): Scope materially changed — new CAF objectives assessed, fundamentally different security posture, significant architecture changes194 - For v1.1+/v2.0+: Add a Revision History entry describing what changed from the previous version19519615. **Save the document**:197198 Before writing the file, read `.arckit/references/quality-checklist.md` and verify all **Common Checks** plus the **SECD** per-type checks pass. Fix any failures before proceeding.199200 Write to `projects/[project-folder]/ARC-{PROJECT_ID}-SECD-v${VERSION}.md`201202**CRITICAL - Auto-Populate Document Control Fields**:203204Before completing the document, populate ALL document control fields in the header:205206### Step 1: Construct Document ID207208- **Document ID**: `ARC-{PROJECT_ID}-SECD-v{VERSION}` (e.g., `ARC-001-SECD-v1.0`)209210### Step 2: Populate Required Fields211212**Auto-populated fields** (populate these automatically):213214- `[PROJECT_ID]` → Extract from project path (e.g., "001" from "projects/001-project-name")215- `[VERSION]` → Determined version from step 11216- `[DATE]` / `[YYYY-MM-DD]` → Current date in YYYY-MM-DD format217- `[DOCUMENT_TYPE_NAME]` → "Secure by Design Assessment"218- `ARC-[PROJECT_ID]-SECD-v[VERSION]` → Construct using format from Step 1219- `[COMMAND]` → "arckit.secure"220221**User-provided fields** (extract from project metadata or user input):222223- `[PROJECT_NAME]` → Full project name from project metadata or user input224- `[OWNER_NAME_AND_ROLE]` → Document owner (prompt user if not in metadata)225- **Classification** → comes from the resolved Document Control header, not from a placeholder. `_partials/RENDERING.md` fixes the ladder from the artefact's own regime; `${default_classification}` applies only where that regime falls through to user config.226227**Calculated fields**:228229- `[YYYY-MM-DD]` for Next Review Date → Current date + 30 days (requirements, research, risks)230- `[YYYY-MM-DD]` for Next Review Date → Phase gate dates (Alpha/Beta/Live for compliance docs)231232**Pending fields** (leave as [PENDING] until manually updated):233234- `[REVIEWER_NAME]` → [PENDING]235- `[APPROVER_NAME]` → [PENDING]236- `[DISTRIBUTION_LIST]` → Default to "Project Team, Architecture Team" or [PENDING]237238### Step 3: Populate Revision History239240```markdown241| 1.0 | {DATE} | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |242```243244### Step 4: Populate Generation Metadata Footer245246The footer should be populated with:247248```markdown249**Generated by**: ArcKit `$arckit-secure` command250**Generated on**: {DATE} {TIME} GMT251**ArcKit Version**: {ARCKIT_VERSION}252**Project**: {PROJECT_NAME} (Project {PROJECT_ID})253**AI Model**: [Use actual model name, e.g., "Claude Sonnet 5 (session default)"]254**Generation Context**: [Brief note about source documents used]255```256257### Example Rendered Header and Revision History258259```markdown260## Document Control261262<!-- DOC-CONTROL-HEADER -->263<!-- Resolved at command-execution time per _partials/RENDERING.md. -->264265## Revision History266267| Version | Date | Author | Changes | Approved By | Approval Date |268|---------|------|--------|---------|-------------|---------------|269| 1.0 | 2025-10-29 | ArcKit AI | Initial creation from `$arckit-secure` command | [PENDING] | [PENDING] |270```271272## Assessment Guidelines273274### Status Indicators275276- **✅ Achieved**: All key controls implemented and effective, no significant gaps277- **⚠️ Partially Achieved**: Some controls in place but gaps remain278- **❌ Not Achieved**: Controls not implemented or ineffective279- **N/A**: Principle genuinely not applicable280281### Critical Security Issues (Phase Blockers)282283Mark as CRITICAL if:284285- No UK GDPR compliance for personal data processing286- No DPIA for high-risk processing287- No encryption for sensitive data (OFFICIAL-SENSITIVE)288- Cyber Essentials not obtained (required for most gov contracts)289- No incident response capability290- No backup/recovery capability291- Critical vulnerabilities unpatched (>30 days)292- No MFA for privileged access293- SIRO not appointed or engaged294295### Data Classification Requirements296297**PUBLIC**:298299- Basic security controls300- No special encryption requirements301- Standard access controls302303**OFFICIAL**:304305- Cyber Essentials baseline minimum306- Encryption in transit (TLS 1.2+)307- Access control and audit logging308- Regular security patching309310**OFFICIAL-SENSITIVE**:311312- Cyber Essentials Plus recommended313- Encryption at rest and in transit (strong algorithms)314- Multi-factor authentication required315- Enhanced audit logging316- DPIA if processing personal data317- Data loss prevention controls318319### Project Phase Considerations320321**Discovery/Alpha**:322323- Security principles identified324- Data classification determined325- Initial risk assessment326- Security requirements defined327- SIRO engaged328329**Beta**:330331- Security controls implemented332- Penetration testing completed333- DPIA completed (if required)334- Cyber Essentials certification obtained335- Vulnerability management operational336- Incident response plan documented337338**Live**:339340- All CAF principles addressed341- Cyber Essentials Plus for high-risk systems342- Continuous security monitoring343- Regular penetration testing (annual minimum)344- Security incident capability proven345- Annual security review with SIRO346347### Cyber Essentials Requirements348349**Basic Cyber Essentials**: Self-assessment questionnaire350**Cyber Essentials Plus**: External technical verification351352Required for:353354- All central government contracts involving handling personal data355- Contracts valued at £5 million or more356- Most public sector technology procurements357358## UK Government Context359360### Senior Information Risk Owner (SIRO)361362- Senior executive responsible for information risk363- Must be board-level or equivalent364- Reviews and approves risk treatment365- Signs off on major security decisions366- Typically Permanent Secretary or Director level367368### Data Protection Officer (DPO)369370Required if:371372- Public authority or public body373- Core activities involve regular/systematic monitoring374- Core activities involve large-scale processing of special category data375376Responsibilities:377378- Advise on UK GDPR compliance379- Monitor compliance with UK GDPR380- Advise on DPIA381- Liaise with ICO382383### Information Commissioner's Office (ICO)384385- UK's independent data protection regulator386- Enforces UK GDPR and Data Protection Act 2018387- Must be notified of data breaches within 72 hours388- Can impose fines up to £17.5 million or 4% of turnover389390### Common UK Government Security Requirements391392**Cyber Essentials Controls**:393394- Firewalls and internet gateways configured395- Secure configuration (CIS benchmarks)396- User access control (least privilege, MFA)397- Malware protection (up-to-date anti-malware)398- Security update management (patching within 14 days)399400**Cloud Hosting**:401402- Prefer UK or EU data centers for data residency403- NCSC Cloud Security Principles compliance404- Cloud provider certifications (ISO 27001, etc.)405- Clear data ownership and portability406407**Network Security**:408409- PSN (Public Services Network) connectivity if required410- Network segmentation by sensitivity411- VPN for remote access412- WiFi security (WPA3 preferred, WPA2 minimum)413414## Example Output Structure415416```markdown417# UK Government Secure by Design Assessment418419**Project**: HMRC Tax Credits Modernization420**Department**: HMRC421**Data Classification**: OFFICIAL-SENSITIVE422**NCSC CAF Score**: 11/14 Achieved423424## NCSC CAF Assessment425426### Objective A: Managing Security Risk427428#### A1: Governance429**Status**: ✅ Achieved430**Evidence**: SIRO appointed (Director of Digital Services), security policies approved, quarterly security reviews...431432#### A2: Risk Management433**Status**: ⚠️ Partially Achieved434**Evidence**: Risk register exists, but threat modeling incomplete...435**Gaps**:436- Complete threat modeling for payment processing (HIGH - 30 days)437- Update risk register with emerging threats (MEDIUM - 60 days)438439### Objective B: Protecting Against Cyber Attack440441#### B3: Data Security442**Status**: ⚠️ Partially Achieved443**Evidence**: TLS 1.3 in transit, AES-256 at rest, but DPIA not completed...444**Gaps**:445- Complete DPIA before Beta (CRITICAL - blocker for Beta phase)446- Implement Data Loss Prevention (HIGH - 90 days)447448## Cyber Essentials449450**Status**: Certified Basic (expires 2024-06-30)451**Target**: Cyber Essentials Plus by Beta452453**Gaps**:454- External vulnerability scan required for Plus certification455456## UK GDPR Compliance457458**Status**: ⚠️ Partially Compliant459**DPO**: Appointed ([Data Protection Officer Name])460**DPIA**: Not completed (REQUIRED before Beta)461462**Critical Issues**:4631. DPIA not completed for tax credit processing (CRITICAL)4642. Data retention policy not documented (HIGH)465466## Critical Issues4671. DPIA incomplete (CAF B3, UK GDPR) - Blocks Beta phase4682. Threat modeling incomplete (CAF A2) - Significant risk gap469470## Recommendations471**Critical** (0-30 days):472- Complete DPIA - DPO - 15 days473- Complete threat model - Security Architect - 30 days474```475476## Important Notes477478- **NCSC CAF is the standard framework** for UK Government security assessment479- **Cyber Essentials is mandatory** for most government contracts480- **UK GDPR compliance is legally required** for personal data processing481- **SIRO sign-off required** for security risk acceptance482- **Data classification drives security controls** - OFFICIAL-SENSITIVE requires stronger controls483- **Penetration testing** recommended annually minimum484- **Incident response** - 72-hour reporting to ICO for personal data breaches485- **Cloud First** - prefer cloud hosting, assess against NCSC Cloud Security Principles486487- **Markdown escaping**: When writing less-than or greater-than comparisons, always include a space after `<` or `>` (e.g., `< 3 seconds`, `> 99.9% uptime`) to prevent markdown renderers from interpreting them as HTML tags or emoji488489## Related UK Government Standards490491- NCSC Cyber Assessment Framework (CAF)492- UK Government Cyber Security Standard (July 2025, Cabinet Office)493- NCSC Vulnerability Monitoring Service (VMS)494- Government Cyber Security Profession & Cyber Academy495- £210m Cyber Action Plan (February 2026)496- Cyber Essentials Scheme497- UK Government Security Classifications498- Government Functional Standard GovS 007: Security499- NCSC Cloud Security Principles500- HMG Security Policy Framework501- Public Services Network (PSN) Code of Connection502503## Resources504505- NCSC CAF: https://www.ncsc.gov.uk/collection/caf506- UK Government Cyber Security Standard: https://www.gov.uk/government/publications/government-cyber-security-standard507- GovS 007 Security: https://www.gov.uk/government/publications/government-functional-standard-govs-007-security508- NCSC GovAssure: https://www.ncsc.gov.uk/collection/govassure509- NCSC Vulnerability Monitoring Service: https://www.ncsc.gov.uk/information/vulnerability-monitoring-service510- Government Cyber Security Profession: https://www.gov.uk/government/publications/government-cyber-security-profession511- Government Cyber Action Plan: https://www.gov.uk/government/publications/government-cyber-action-plan512- Cyber Essentials: https://www.ncsc.gov.uk/cyberessentials513- UK GDPR: https://ico.org.uk/for-organisations/guide-to-data-protection/514- Government Security Classifications: https://www.gov.uk/government/publications/government-security-classifications515- NCSC Guidance: https://www.ncsc.gov.uk/guidance516517Generate the UK Government Secure by Design assessment now based on the project information provided.