isms-audit-expert

Plan and execute ISO 27001 ISMS audits with Annex A control mapping.

Updated Apr 16, 2026
One-click install
npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill isms-audit-expert-devcharuzu
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/devCharuzu/philfida-taskmanage/tree/main/.windsurf/skills/isms-audit-expert
Command: npx skills add https://github.com/devCharuzu/philfida-taskmanage --skill isms-audit-expert-devcharuzu

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.

Core Features & Use Cases

  • Audit Program Management: Plan and manage audit programs with risk-based schedules and Annex A mapping.
  • Audit Execution: Conduct audits with evidence collection, testing guidance, and closing activities.
  • Control Assessment: Test and evaluate control effectiveness with guidance linked to ISO 27002.
  • Finding Management: Classify findings, document evidence, and manage corrective actions.
  • Certification Support: Prepare for Stage 1/Stage 2 and surveillance audits, ensure continual improvement.
  • Tools & References: Access to the ISMS audit scheduler script and reference materials for procedures.

Quick Start

Outline the ISMS scope and SoA, then generate a risk-based audit plan and draft Stage 1/Stage 2 documentation.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for an ISO 27001 internal audit?

To prepare for an ISO 27001 internal audit, define your ISMS scope and Statement of Applicability, then generate a risk-based audit plan mapping Annex A controls to required evidence and testing procedures.

What is a risk-based audit schedule for ISMS compliance?

A risk-based ISMS audit schedule prioritizes assessments based on risk levels and control criticality. It uses scheduling logic to assign audit dates, ensuring consistent and auditable outcomes across the ISO 27001 certification lifecycle.

How do I map Annex A controls to audit evidence?

You map Annex A controls to audit evidence by testing control effectiveness against ISO 27002 guidance. This process links specific control requirements to documented evidence, forming the basis for your audit findings.

Can I use this for Stage 1 and Stage 2 ISO 27001 certification audits?

Yes, this supports Stage 1 and Stage 2 ISO 27001 certification audits. It aids preparation by generating necessary documentation, reviewing control implementation evidence, and guiding surveillance audit activities.

How do I classify nonconformities found during an ISMS audit?

Classify ISMS audit nonconformities using formal finding management workflows. Document the evidence, categorize the finding severity, and initiate corrective action workflows to ensure continual improvement and compliance.