information-security-manager-iso27001

Develop and maintain an ISO 27001/27002-compliant ISMS for HealthTech and MedTech organizations.

52|6|Updated Nov 24, 2025
One-click install
npx skills add https://github.com/ovachiever/droid-tings --skill information-security-manager-iso27001
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: information-security-manager-iso27001
Source: https://github.com/ovachiever/droid-tings/tree/main/skills/information-security-manager-iso27001
Command: npx skills add https://github.com/ovachiever/droid-tings --skill information-security-manager-iso27001

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

Senior Information Security Manager offering ISO 27001/27002 implementation for HealthTech and MedTech, providing ISMS design, risk assessment, security controls management, and regulatory oversight.

Core Features & Use Cases

  • ISMS Implementation: design, scope, risk assessment, controls selection, and monitoring
  • Information Security Risk Assessment: asset classification, threat analysis, risk treatment
  • ISO 27002 Security Controls: organizational, people, physical, and technical controls
  • Healthcare Security Requirements: HIPAA, medical device cybersecurity, clinical data protection
  • Advanced Security Applications: device cybersecurity, cloud security, privacy integration
  • ISMS Governance & Operations: policy framework, training, management review, continuous improvement
  • Regulatory & Certification Management: ISO 27001 certification readiness and coordination

Quick Start

Review the references and templates, then run the example script to bootstrap an ISMS project. Example: python scripts/example.py

Frequently Asked Questions about information-security-manager-iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I develop an ISO 27001-compliant information security management system for healthcare?

ISO 27001 compliance requires designing an ISMS covering asset classification, risk assessment, control selection, and ongoing monitoring. This Skill provides ISMS implementation templates, risk assessment methodology, and healthcare-specific guidance including HIPAA safeguards and medical device cybersecurity to achieve certification readiness.

What's the process for conducting a security risk assessment in a HealthTech organization?

Risk assessment involves identifying information assets, analyzing threats and vulnerabilities, evaluating likelihood and impact, and defining risk treatment. This Skill covers asset classification frameworks, threat analysis techniques, and ISO 27002 control mapping to support clinical data protection and medical device security requirements.

Which ISO 27002 controls apply to healthcare organizations and cloud security?

ISO 27002 specifies organizational, people, physical, and technical controls applicable across healthcare settings. This Skill maps controls to HIPAA requirements, cloud security architecture, and clinical data interoperability, helping HealthTech teams select and implement controls aligned to their risk profile.

Can I use this for preparing a HealthTech company for ISO 27001 certification?

Yes. The Skill supports full certification readiness through ISMS design, policy framework development, control implementation, incident management setup, and management review processes. It addresses healthcare-specific regulatory requirements and provides templates and reference materials to accelerate compliance activities.

What's the difference between information security risk assessment and general compliance auditing?

Risk assessment identifies and evaluates threats to information assets, determining which controls are needed; compliance auditing verifies controls are implemented and effective. This Skill combines both—using risk assessment to drive control selection and monitoring to demonstrate ISO 27001 compliance for healthcare environments.

How does this Skill handle medical device cybersecurity within an ISMS?

Medical device cybersecurity integrates into the broader ISMS by identifying connected devices as critical assets, assessing device-specific threats, and applying appropriate technical and organizational controls. This Skill provides guidance on device threat analysis and control implementation alongside standard ISO 27001/27002 requirements.