annex-review

Rate ISO 27001 Annex A controls and generate a Markdown RAG report.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill annex-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: annex-review
Source: https://github.com/gombing/ISO27001Agent/tree/main/annex-review
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill annex-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This capability enables consistent, auditable assessment of ISO 27001 Annex A controls by providing a structured framework to rate control implementation and generate an actionable Annex A RAG report.

Core Features & Use Cases

  • Load engagement context and scope from client engagement briefs.
  • Guide a step-by-step assessment across A.5–A.8 controls, capturing Green/Amber/Red ratings with gap notes.
  • Produce a consolidated Annex A RAG report with per-control details and an executive summary.

Quick Start

Run the annex-review skill to begin evaluating Annex A controls and generate the RAG report.

Frequently Asked Questions about annex-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess ISO 27001 Annex A controls and generate a RAG report?

Assess ISO 27001 Annex A controls by guiding a step-by-step evaluation across 11 control groups from A.5 to A.8, capturing Green/Amber/Red ratings and gap notes to produce a consolidated RAG report.

What is a RAG report for ISO 27001 Annex A?

A RAG report for ISO 27001 Annex A is a consolidated document rating control implementation status as Red, Amber, or Green. It includes per-control details, gap notes, and a synthesized executive summary for actionable audit reporting.

How do I rate ISO 27001 Annex A control implementation status?

Rate ISO 27001 Annex A control implementation status by stepping through 11 control groups via interactive prompts, assigning a Green, Amber, or Red rating and documenting gap notes for each individual control.

Does the ISO 27001 Annex A audit review require a specific directory setup?

The ISO 27001 Annex A audit review requires a stable engagement directory for output. It uses Bash-based prompts and stores the final Markdown RAG report under the engagements folder with a date and client name.

Can I load client engagement briefs for ISO 27001 Annex A scope definition?

You can load engagement context and scope from client engagement briefs. The skill uses this input to frame the A.5 through A.8 control assessment and structure the final Annex A RAG report output.

What is the best way to document ISO 27001 Annex A gaps and evidence?

The best way to document ISO 27001 Annex A gaps is through a structured RAG framework that captures evidence ratings and gap notes during assessment, generating a client-facing Markdown document with a synthesized executive summary.