IRAP Evidence Trail
TL;DR: This skill takes an ad-hoc set of governance documents and reorganises them into a folder structure organised by Information Security Manual (ISM) family, with each artefact timestamped, indexed by control, and missing families flagged as gaps.
How does the IRAP Evidence Trail skill structure an ISM evidence pack?
The IRAP Evidence Trail skill reorganises a flat set of governance documents into a folder structure indexed by Information Security Manual (ISM) control reference, so an IRAP assessor can find each artefact. It records each file’s modified date and flags families with no evidence as gaps. It only moves or copies files.
The folder names below are this skill’s own working convention, not official ISM chapter titles. Align them to the current ISM published by the Australian Cyber Security Centre before sharing a pack with an assessor.
When should you run this skill?
- “Organise IRAP evidence trail”
- “Build ISM evidence pack”
- “Prepare for an IRAP assessment”
- “Restructure our security documents by ISM family”
Target folder structure
IRAP-Evidence-<cycle>/
00-INDEX.md
01-Governance/
02-Personnel-Security/
03-Communications-Security/
04-Information-Technology-Security/
05-Network-Security/
06-Cryptography/
07-Application-Security/
08-Cloud-Computing-Security/
09-Enterprise-Mobility/
10-Incident-Management/How this skill works, step by step
- Confirm the assessment cycle name (for example, your organisation’s assessment name and year)
- Read each existing document and tag it with the most appropriate ISM family
- Move documents into the target structure (or copy with original linked back)
- Create
00-INDEX.mdlisting every artefact: file path, ISM family, control references where known, last modified date - Flag gaps: ISM families with zero artefacts get a “GAP — needs evidence” row in the index
- Produce a one-page summary for the assessor’s pre-read
Output format
- File system reorganisation (or copies) in the target structure
00-INDEX.mdas the master cross-reference- Summary table at the end of the run
Scope and safety
This skill does NOT:
- Author missing evidence (gaps are flagged, not filled)
- Make IRAP assessment decisions
- Modify the original documents — moves or copies only
Licensing and permissions
- This skill works on files you already hold and needs no Microsoft 365 licence, Microsoft Entra role or Microsoft Graph permission of its own. It does not call Microsoft Graph.
- Microsoft documents that Microsoft Purview Compliance Manager offers a premium assessment template for IRAP. Licence requirements for premium templates are not covered on the pages cited here, so check them on Microsoft Learn before relying on that template.
Related skills
- IRAP Control Evidence: run before this to produce control-by-control evidence from the tenant.
- ISM Control Pack: run before this to map tenant configuration to ISM controls.
- Compliance Manager Control Mapper: run alongside this to map controls to the ISM and Essential Eight.
- E8 Evidence Packager: run after this if you also need an Essential Eight evidence folder.
- Australian Compliance for Microsoft 365 Copilot and AI: pillar page on Australian compliance evidence, including IRAP.
Sources
Reviewed 2026-09-30 against the two Microsoft Learn pages below. ISM chapter names were not verified against the ISM itself, so the folder names are a working convention only.
- Australian Government Information Security Registered Assessor Program (IRAP), Microsoft Learn : IRAP is governed and administered by the Australian Cyber Security Centre (ACSC); endorsed assessors give independent assessment; the Compliance Manager premium template.
- Australia IRAP, Microsoft Learn : IRAP assesses a system’s security against the Australian Government Information Security Manual (ISM).
- Pair with the E8 Evidence Packager skill for the data-repository portion of the evidence pack.
Licensed under CC BY 4.0 by EDUC4TE .
SKILL.md— paste into Microsoft 365 Copilot or ClaudeDownload▸ View skill file▾ Hide skill file
How to use this skill
- Get the file. Download or copy the
SKILL.mdfrom the SKILL.md panel on this page. - Load it into your host:
- Microsoft 365 Copilot / Copilot Studio — add it as the instructions of a declarative agent or Copilot Studio agent.
- Claude (Cowork / Claude Code) — drop the file into your skills folder; it loads as an Agent Skill automatically.
- Any chat host — paste the file contents as your prompt.
- Grant read-only access. Assign the least-privilege roles and Microsoft Graph scopes listed in Licensing and permissions section of this article.
- Provide your tenant scope and run it (a site, a collection, or the whole tenant).
- Review the report and action the risk-ranked recommendations.
This skill is read-only by default — it inspects and reports, and never changes your tenant.
Last reviewed 2026-09-30 · Published 2026-06-02