Arjun is a read-only ISM assessment tool that installs into your own Azure or AWS tenant and generates a System Security Plan and its Annex.

>_ arjun@your-tenant:~$ ./assess.sh_

ARJUN

ISM assessment & IRAP evidence — in your own tenant.

read-only · no egress · yours to run

$ curl -sL https://arjunsec.run/install.sh | bash -s -- --region australiaeast
$ curl -sL https://arjunsec.run/install-aws.sh | bash -s -- --region ap-southeast-2

Copy a line and paste it into your cloud's browser shell — it runs the same from Windows, macOS or Linux. One command lands the whole app in a single resource group / stack you can delete as a unit.  Read the docs →

// what it does

The whole ISM, answerable — and the documents to prove it.

full ISM coverage

Every control applicable at your classification becomes an answerable question — all ~1,000, not a curated subset. Nothing is left as a silent gap.

attestations

Record each control's implementation status with a justification and supporting-evidence references. Re-checked for currency against every ISM release.

multiple systems

Assess several authorisation boundaries from one deployment — each with its own classification, answers and SSP. A control can be Effective for one system and Inherited for another.

control inheritance

Mark controls inherited from a CSP's IRAP-assessed platform or a parent system. The SSP cites the source and its assessment and reports inherited controls distinctly — the way an assessor expects.

ssp + annex

Generate a formatted System Security Plan and its control-implementation Annex as real Office documents, ready for an assessor.

report branding

Apply your agency's logo and header/footer to the output. The protective marking stays on every page — a document obligation, not a style choice.

honest coverage

Controls you haven't answered are reported as not assessed, with the reason — never assumed compliant. An assessor can trust the gaps.

any cloud

Runs on Azure, AWS, or any host. One tool, one SSP, whichever cloud your system lives in.

// how it runs

In your cloud. Read-only. Nothing leaves.

read-only

Reader on Azure, ReadOnlyAccess on AWS — and nothing more. Arjun reads configuration to assess it and changes nothing in your tenant.

no egress

Your configuration and attestations stay in your own tenant. Nothing is sent to us, cached by us, or seen by us.

your cloud

Installs into your own subscription or account. You own the deployment, the database, and every document it produces.

small footprint

One container, one managed database, sign-in through your own identity provider. Approvable by a security architect in an afternoon.

Security audits welcome. Arjun runs inside your own tenant and holds read-only access — so don’t take our word for it, audit it. The install templates and the exact permissions it requests are public, and the full source code is available to security teams for review on request. Responsible disclosure and source-access requests — security@arjunsec.run.

// the winrar model

One price. Nothing gated.

$100 AUD / month · on your honour

No feature gates. No licence keys. No nagware. Every feature — the questionnaire, the attestations, the SSP and Annex — is on for everyone, forever. If Arjun is useful to your agency, licence it.

Your subscription keeps the ISM controls current: as ASD revises the ISM, updated releases carry the new catalog, and Arjun tells you in-app when one is available. Upgrading is one command and preserves your attestations.

Use at your own risk. Arjun is provided as-is, with no warranty of any kind — the author is not responsible for any problems or costs arising from its use. It is an assessment aid, not an accreditation: an IRAP assessment is conducted by an ASD-endorsed IRAP assessor, and Arjun is neither endorsed by nor affiliated with the ASD or the Australian Government.