isms-audit-expert

Plans and executes ISO 27001 ISMS audits with security control assessment and compliance verification.

Updated May 22, 2026
One-click install
npx skills add https://github.com/kitfunso/claude-config --skill isms-audit-expert-kitfunso
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/kitfunso/claude-config/tree/main/skills/ra-qm-team/isms-audit-expert
Command: npx skills add https://github.com/kitfunso/claude-config --skill isms-audit-expert-kitfunso

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve? Organizations preparing for ISO 27001 certification or maintaining an ISMS often lack structured audit programs, risk-based scheduling, and consistent security control testing, leading to failed certification audits and unresolved security gaps. ## Core Features & Use Cases - Risk-Based Audit Planning: Build ISMS audit programs with risk-driven scheduling, scope definition, and auditor assignment across technical, administrative, and physical security domains. - Security Control Assessment: Test ISO 27002 controls including access control, cryptography, network security, and cloud configuration, integrated with vulnerability scanning and penetration testing coordination. - Certification & Compliance Support: Prepare for Stage 1/Stage 2 ISO 27001 certification audits, surveillance audits, and regulatory inspections such as HIPAA, PCI DSS, and NIST CSF assessments. - Use Case: A compliance manager needs to prepare for an upcoming ISO 27001 Stage 2 audit. Use this Skill to run a mock certification audit, test critical security controls, document findings with risk prioritization, and generate a compliance status report. ## Quick Start Ask the assistant to create a risk-based ISMS internal audit plan for your organization covering ISO 27001 Annex A controls and cloud security configuration.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for an ISO 27001 certification audit?▼

ISO 27001 certification preparation involves completing internal ISMS audits, verifying security control implementation, reviewing ISMS documentation, and running a mock certification audit. The process supports both Stage 1 documentation review and Stage 2 implementation testing.

How to build a risk-based ISMS audit plan?▼

A risk-based ISMS audit plan evaluates asset criticality, threat exposure, control effectiveness, and prior incidents to set audit priority and frequency. High-risk assets get quarterly assessments, critical controls semi-annual testing, and standard processes annual verification.

What security controls does an ISO 27002 assessment cover?▼

An ISO 27002 assessment covers organizational controls like security policies and asset management, technical controls like access control and cryptography, physical controls like entry controls and equipment protection, and operational controls like change management and backup.

Does ISMS auditing include cloud security assessment?▼

Yes, cloud security auditing covers cloud service provider certification review, shared responsibility model verification, data residency compliance, resource configuration hardening, encryption and key management, and cloud monitoring and logging evaluation.

Can ISMS audits integrate penetration testing results?▼

ISMS audits integrate vulnerability assessments and penetration testing for external networks, internal systems, and web applications. Technical findings feed into risk-based finding prioritization and security improvement recommendations within the audit report.

What are the limitations of automated security control testing?▼

Automated control testing verifies configurations and scans for vulnerabilities but cannot assess security culture, awareness training effectiveness, or process maturity. These areas require auditor interviews, documentation review, and manual observation during the audit.