information-security-manager-iso27001

Automate ISO 27001 ISMS design, risk assessment, and governance for HealthTech and MedTech organizations.

Updated Mar 5, 2026
One-click install
npx skills add https://github.com/theandyalvarez7-ruby/claude-skills --skill information-security-manager-iso27001-theandyalvarez7-ruby
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: information-security-manager-iso27001
Source: https://github.com/theandyalvarez7-ruby/claude-skills/tree/main/ra-qm-team/information-security-manager-iso27001
Command: npx skills add https://github.com/theandyalvarez7-ruby/claude-skills --skill information-security-manager-iso27001-theandyalvarez7-ruby

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill provides a standardized, repeatable framework to design ISO 27001–compliant ISMS, perform risk assessment, map controls, and prepare for certifications and audits.

Core Features & Use Cases

  • ISMS design and governance planning tailored for HealthTech and MedTech environments.
  • ISO 27001:2022 risk assessment, control mapping, and evidence generation for SoA and audits.
  • Policy development, third-party risk considerations, and incident response alignment.

Quick Start

Generate an ISO 27001–compliant ISMS design and initial risk assessment for your organization.

Frequently Asked Questions about information-security-manager-iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design an ISO 27001 ISMS for a healthcare organization?

You can design an ISO 27001 ISMS for HealthTech and MedTech by automating ISMS scoping, governance planning, and policy mapping. This approach tailors your information security management system to specific healthcare regulatory contexts.

What is the best way to perform an ISO 27001 risk assessment and generate a risk register?

ISO 27001 risk assessment is performed using included risk assessment tooling to evaluate threats and generate artifacts. This process outputs structured risk registers and Statement of Applicability (SoA) mappings for audit readiness.

Can I use this to map ISO 27002 controls and prepare for compliance audits?

Yes, you can map ISO 27002 controls and prepare for compliance audits. The framework generates evidence, SoA mappings, and audit-ready reports to verify your control implementations against healthcare requirements.

Does ISO 27001 governance work for MedTech environments with incident response requirements?

ISO 27001 governance applies directly to MedTech environments with incident response requirements. It aligns policy development, third-party risk considerations, and incident response references to maintain compliance within medical technology contexts.

When do I need to update my ISMS scope for third-party risk considerations?

You need to update your ISMS scope when integrating new third-party services or vendors. The framework addresses third-party risk considerations within policy development to ensure continuous ISO 27001 compliance and governance.