information-security-manager-iso27001

Manages ISO 27001 certification workflows for healthcare software and IT systems.

Updated Mar 4, 2026
One-click install
npx skills add https://github.com/Tonybleything76/more-claude-skills --skill information-security-manager-iso27001-tonybleything76
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: information-security-manager-iso27001
Source: https://github.com/Tonybleything76/more-claude-skills/tree/main/ra-qm-team/information-security-manager-iso27001
Command: npx skills add https://github.com/Tonybleything76/more-claude-skills --skill information-security-manager-iso27001-tonybleything76

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complex challenge of implementing and managing robust Information Security Management Systems (ISMS) specifically tailored for HealthTech and MedTech companies, ensuring compliance with ISO 27001 and stringent healthcare regulations.

Core Features & Use Cases

  • ISMS Design & Implementation: Guides through the entire process of establishing an ISO 27001 compliant ISMS.
  • Risk Assessment & Management: Automates security risk assessments, identifies vulnerabilities, and recommends treatment plans.
  • Compliance & Auditing: Verifies control implementation, generates gap analysis reports, and prepares for certification audits.
  • Incident Response: Provides structured workflows for detecting, responding to, and recovering from security incidents.
  • Use Case: A MedTech startup needs to achieve ISO 27001 certification to secure a major contract. This Skill will help them design their ISMS, conduct a thorough risk assessment of their patient data systems, implement necessary security controls, and prepare for the certification audit.

Quick Start

Run a security risk assessment for the patient-data-system and output the results to risk_register.json.

Frequently Asked Questions about information-security-manager-iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement an ISO 27001 compliant ISMS for HealthTech?

To implement an ISO 27001 compliant Information Security Management System (ISMS) for HealthTech, you must establish security policies, conduct risk assessments, and apply controls tailored to patient data systems while ensuring alignment with healthcare regulations like HIPAA.

What is the best way to prepare for an ISO 27001 certification audit in MedTech?

The best way to prepare for an ISO 27001 certification audit in MedTech is to verify control implementation and generate gap analysis reports. This identifies compliance shortfalls in your medical device cybersecurity practices before the formal assessment.

How do I conduct a security risk assessment for patient data systems?

You can conduct a security risk assessment for patient data systems by identifying vulnerabilities, evaluating threats, and recommending treatment plans. Automating this process generates a risk register output to track and mitigate identified security issues.

Does ISO 27001 compliance cover HIPAA and medical device cybersecurity requirements?

Yes, ISO 27001 compliance covers HIPAA and medical device cybersecurity requirements by providing a structured framework for information security controls. Implementing an ISMS ensures your HealthTech organization meets cross-standard regulatory obligations.

How do I create an incident response plan for a HealthTech ISMS?

You create an incident response plan for a HealthTech ISMS by establishing structured workflows for detecting, responding to, and recovering from security incidents. This ensures systematic handling of data breaches affecting patient information.