/gcloud-kit:security
Generate security assertions and evidence document for a G-Cloud service.
Overview
Creates a comprehensive security document mapping your service against the NCSC 14 Cloud Security Principles, documenting certifications, security testing, clearances, and building an evidence register. This is a critical submission document — most buyers require ISO 27001 and Cyber Essentials Plus.
Usage
/gcloud-kit:security My Cloud Platform
Arguments: Service name (must match an existing service directory).
Prerequisites
- Supplier profile (
services/supplier/supplier-profile.md) - Service design (
services/{name}/service-design.md) - SDD (
services/{name}/sdd.md)
Output
services/{name}/security.md
Template used: .gcloud/templates/security-template.md
What it does
- Loads context from supplier profile, service design, and SDD
- Reads the security template
- Documents each of the NCSC 14 Cloud Security Principles:
- Data in transit protection
- Asset protection and resilience
- Separation between consumers
- Governance framework
- Operational security
- Personnel security
- Secure development
- Supply chain security
- Secure consumer management
- Identity and authentication
- External interface protection
- Secure service administration
- Audit information provision
- Secure use of the service
- Documents certifications (ISO 27001, Cyber Essentials, SOC 2, CSA STAR, PCI DSS)
- Records security testing regime (penetration testing, vulnerability scanning)
- Lists security clearances held
- Creates an evidence register with certificate numbers and expiry dates
Related commands
- /gcloud-kit:supplier-profile — certifications come from supplier profile
- /gcloud-kit:review — checks security evidence completeness
- /gcloud-kit:submission-pack — bundles security document for submission