isms-audit-expert

Manage ISMS audits for ISO 27001 compliance with risk-based planning and control assessment.

Updated Mar 12, 2026
One-click install
npx skills add https://github.com/Fantasia1999/claude-skills-zh --skill isms-audit-expert-fantasia1999
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/Fantasia1999/claude-skills-zh/tree/main/translations/ra-qm-team/isms-audit-expert
Command: npx skills add https://github.com/Fantasia1999/claude-skills-zh --skill isms-audit-expert-fantasia1999

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the complex process of Information Security Management System (ISMS) audits, ensuring ISO 27001 compliance and facilitating certification.

Core Features & Use Cases

  • Audit Planning: Generate risk-based audit schedules and plans.
  • Control Assessment: Evaluate security controls against ISO 27001 Annex A requirements.
  • Finding Management: Classify, document, and track nonconformities and corrective actions.
  • Certification Support: Prepare documentation for Stage 1, Stage 2, and surveillance audits.
  • Use Case: A company preparing for its ISO 27001 certification can use this Skill to systematically plan its internal audits, assess the implementation of controls like access management and incident response, and document any identified gaps for remediation.

Quick Start

Use the isms-audit-expert skill to generate a risk-based audit schedule for the upcoming year.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an ISMS audit for ISO 27001 compliance?

To plan an ISMS audit for ISO 27001 compliance, generate a risk-based audit schedule using structured templates. This approach prioritizes high-risk areas and systematically outlines the audit program for the upcoming certification cycle.

What is the best way to assess security controls against ISO 27001 Annex A requirements?

Assessing security controls against ISO 27001 Annex A involves verifying control implementation through evidence review. Utilize structured scripts to systematically evaluate access management and incident response controls for compliance gaps.

How do I manage nonconformities identified during an internal ISMS audit?

Managing ISMS audit nonconformities requires classifying findings, documenting gaps, and tracking corrective actions. Use structured workflows to ensure each identified nonconformity is systematically remediated before external certification.

Can I prepare documentation for ISO 27001 Stage 1 and Stage 2 certification audits?

Prepare for ISO 27001 Stage 1, Stage 2, and surveillance audits by consolidating your evidence review, risk-based audit schedules, and corrective action records. This ensures systematic documentation readiness for external auditors.

Does this support both internal and external ISMS audit workflows?

This supports both internal and external ISMS audit workflows by facilitating evidence review, finding classification, and corrective action tracking. It systematically generates audit programs and verifies controls for certification support.