From arckit-au-energy
Generates an AESCSF maturity assessment for energy-sector projects, covering IT, OT, market, and grid-edge dependencies.
How this command is triggered — by the user, by Claude, or both
Slash command
/arckit-au-energy:au-aescsf <project ID or system, e.g. '001', 'DNSP DERMS Platform'>The summary Claude sees in its command listing — used to decide when to auto-load this command
> WARNING: **Community-contributed command** - not part of the officially-maintained ArcKit baseline. Output must be reviewed by qualified energy-sector cyber security, OT security, regulatory, legal, and operational risk advisers before reliance. Verify the current AESCSF version, publication date, AEMO source availability, and applicable entity obligations before external use; if AEMO resources are unavailable, record the attempted access date and re-check before finalising. You are an enterprise architect generating an **Australian Energy Sector Cyber Security Framework (AESCSF) maturit...
WARNING: Community-contributed command - not part of the officially-maintained ArcKit baseline. Output must be reviewed by qualified energy-sector cyber security, OT security, regulatory, legal, and operational risk advisers before reliance. Verify the current AESCSF version, publication date, AEMO source availability, and applicable entity obligations before external use; if AEMO resources are unavailable, record the attempted access date and re-check before finalising.
You are an enterprise architect generating an Australian Energy Sector Cyber Security Framework (AESCSF) maturity assessment for an Australian energy-sector project, asset, market interface, OT environment, DER platform, or regulated energy business capability.
$ARGUMENTS
The Australian Energy Sector Cyber Security Framework is an energy-sector cyber maturity framework coordinated through AEMO and industry partners. Use it as an authoritative energy-sector anchor while avoiding verbatim reproduction of detailed AESCSF source text. This artefact complements /arckit:au-e8-posture, /arckit:au-ism-controls, /arckit:au-ot-security, and /arckit:au-soci-cirmp by translating baseline cyber, OT, and critical-infrastructure evidence into an energy-specific maturity view.
Authoritative anchors:
Read prerequisites:
projects/000-global/ARC-000-PRIN-*.md if present.ARC-{P}-AUE8-v*) if available.ARC-{P}-AUISM-v*) if available.ARC-{P}-AUOT-v*) if available.ARC-{P}-AUSOCI-v*) if available.${CLAUDE_PLUGIN_ROOT}/templates/_partials/RENDERING.mdRead the template:
.arckit/templates-custom/au-aescsf-template.md (user override).arckit/templates/au-aescsf-template.md${CLAUDE_PLUGIN_ROOT}/templates/au-aescsf-template.mdUse scripts/bash/create-project.sh --json <project-name> if the project does not yet exist.
Use scripts/bash/generate-document-id.sh <PROJECT_ID> AUAESCSF --filename for the artefact filename.
Resolve the <!-- DOC-CONTROL-HEADER --> marker per RENDERING.md. Use the Australian classification scheme (UNOFFICIAL / OFFICIAL / OFFICIAL:Sensitive / PROTECTED / SECRET) -- replace the standard UK line in the header.
Generate the following sections:
Energy Context and AESCSF Scope - identify the energy sub-sector, asset or platform, market role, operational environment, criticality, and AESCSF applicability assumptions.
Criticality and Target Maturity Profile - document business criticality, safety and market impacts, target maturity rationale, and any legal or regulatory assumptions requiring qualified review.
Domain Maturity Assessment - assess maturity by AESCSF capability domain using current evidence, target state, gaps, owners, and uplift actions. Do not quote detailed AESCSF source text verbatim.
OT/IT and Grid-Edge Findings - require OT/IT zone and conduit diagrams, DERMS / DOE / CSIP-AUS flows where applicable, field telemetry, metering, control-room, and grid-edge dependency evidence.
Architecture Evidence - require OT/IT zone and conduit diagrams, IT/OT data flows, DERMS/DOE/CSIP-AUS flows, vendor remote-access paths, energy data-model dependencies, and cross-references to DFD, diagram, data-model, traceability, and risk evidence.
IT/OT and Market Data Flows - document IT/OT flows, AEMO or market interfaces, settlement or metering flows, telemetry, API exchanges, file transfers, and protocol gateways.
Energy Data Model Dependencies - identify dependencies across network assets, DER, meters, NMI / customer records, market settlements, telemetry, outage, switching, and operational data.
Asset, Interface, and Evidence Inventory - identify source-of-truth registers for OT assets, IT systems, DERMS / DOE platforms, market interfaces, APIs, telemetry links, metering assets, vendor remote-access paths, data catalogues, control evidence, owners, criticality, and inventory gaps. Where ServiceNow or another CMDB exists, cross-reference /arckit:servicenow output and ensure inventory rows can be visualised with colour-coded criticality, maturity, or risk status.
Diagram and Traceability Handoffs - list required /arckit:dfd, /arckit:diagram, /arckit:data-model, /arckit:traceability, and /arckit:risk updates.
AESCSF Anti-Pattern Register - call out flat OT networks, undocumented market interfaces, unmanaged vendor remote access, stale DER integration assumptions, missing data ownership, and unsupported control-room dependencies.
Federal Baseline Cross-Reference - map relevant findings to /arckit:au-e8-posture, /arckit:au-ism-controls, /arckit:au-ot-security, and /arckit:au-soci-cirmp.
Maturity Gaps and Risk Treatment - convert maturity gaps into risk treatments with owner, due date, evidence artefact, and residual risk.
Uplift Roadmap - prioritise immediate, 30-90 day, 90-180 day, and strategic uplift actions.
Populate the External References section per ${CLAUDE_PLUGIN_ROOT}/references/citation-instructions.md. AEMO AESCSF, the verified AESCSF version / publication date, access date, and any AEMO availability issue MUST appear in the Document Register.
Write the artefact via the Write tool to projects/<project-id>/<filename>.
Show only a summary to the user: AESCSF scope, target maturity, highest-risk gaps, architecture evidence gaps, and top five uplift actions.
/arckit:au-soci-cirmp; where it includes connected OT, cross-reference /arckit:au-ot-security./arckit:data-model for data catalogues, /arckit:servicenow for CMDB/service inventory, /arckit:dfd and /arckit:diagram for colour-coded visualisation, /arckit:risk for heat/scoring, /arckit:maturity-model for maturity criteria, and /arckit:graph-report for coverage gaps.npx claudepluginhub tractorjuice/arckit-claude --plugin arckit-au-energy2plugins reuse this command
First indexed Jul 17, 2026
/au-aescsfGenerates an AESCSF maturity assessment for energy-sector projects, covering IT, OT, market, and grid-edge dependencies.
/au-ot-securityGenerates an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments. Accepts a project ID or system name as argument.
/secureGenerates a Secure by Design assessment for UK Government civilian projects, evaluating security controls against NCSC Cyber Assessment Framework (CAF) and producing a compliance document.
/eu-nis2Assesses NIS2 Directive compliance obligations for an EU entity, producing a gap analysis against Article 21 security measures and sector-specific requirements.
/at-nisgAssesses Austrian NISG compliance (BGBl. I Nr. 94/2025) for a project or organisation, covering entity designation, incident reporting to GovCERT/SPOC, KSÖ coordination, and sector-specific obligations beyond the EU NIS2 baseline.
/fr-ebiosConducts an EBIOS Risk Manager risk analysis following the ANSSI methodology across five workshops, from study framing to risk treatment and homologation recommendation.