interview

Guide ISO 27001 client intake through an eight-question process to produce an Engagement Brief.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill interview-gombing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: interview
Source: https://github.com/gombing/ISO27001Agent/tree/main/interview
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill interview-gombing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill guides a GRC consultant through a structured ISO 27001 client intake to surface the real situation — not the polished version the client prepared — before any gap assessment or roadmap work begins. It ensures the engagement driver, scope, leadership commitment, and resources are clearly understood to produce a reliable Engagement Brief.

Core Features & Use Cases

  • Step-by-step Phase 1–3 intake workflow that surfaces client context, drivers, scope, posture, and risk.
  • Generates a formal Engagement Brief used to guide subsequent gap assessments, roadmaps, and policy templates.
  • Includes a synthesis check to confirm accuracy before finalizing the brief and handing off to the gap assessment.

Quick Start

Start the ISO 27001 intake by launching the /interview session to collect client context and trigger engagement flow.

Frequently Asked Questions about interview

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct an ISO 27001 client intake to define engagement scope?

This ISO 27001 intake workflow targets both formal certification and internal compliance by using forcing questions to move beyond the client's polished version and clearly define the real engagement scope and resources.

What is the best way to prepare an ISO 27001 engagement brief for gap assessments?

The intake process integrates context collection, forcing questions, and a synthesis check to confirm accuracy, producing a formal engagement brief that ensures reliable handoff to subsequent gap assessment and roadmap work.

Can I use this intake workflow for internal compliance instead of formal ISO 27001 certification?

Yes, this ISO 27001 intake workflow explicitly targets internal compliance alongside formal certification by adapting its eight-question process to evaluate the organization's current posture and engagement drivers regardless of the final audit goal.

What questions are included in the ISO 27001 intake process?

The ISO 27001 intake process includes a structured eight-question workflow that uses forcing questions to uncover leadership commitment, available resources, and the true scope of the engagement before finalizing documentation.

How does the synthesis check work before finalizing the ISO 27001 engagement brief?

The synthesis check confirms the accuracy of the collected client context, drivers, and risk posture in Phase 3 before Phase 4 documentation finalizes the ISO 27001 engagement brief for downstream gap assessments.