isms-audit-expert

Plan and conduct ISO 27001 ISMS audits with risk-based scopes and evidence collection.

Updated Feb 13, 2026
One-click install
npx skills add https://github.com/mwathiben/PropManager --skill isms-audit-expert-mwathiben
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/mwathiben/PropManager/tree/main/.claude/skills/isms-audit-expert
Command: npx skills add https://github.com/mwathiben/PropManager --skill isms-audit-expert-mwathiben

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This skill provides expert ISMS auditing guidance to plan, execute, and improve ISO 27001 compliance programs efficiently.

Core Features & Use Cases

  • ISMS Audit Program Management: Design and manage comprehensive audit programs covering planning, execution, findings, and performance.
  • Risk-Based Planning: Create risk-driven audit scopes, asset criticality analysis, and control testing schedules.
  • Certification Readiness & Compliance: Prepare for Stage 1/Stage 2 audits and ongoing surveillance with structured evidence, reporting, and remediation workflows.
  • Use Case: An organization prepares for ISO 27001 certification by building an audit plan, mapping controls, and generating evidence packs for the auditor.

Quick Start

Guide an ISMS audit planning session by describing scope, selecting controls, and initiating evidence collection.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan an ISO 27001 ISMS audit using a risk-based approach?

Plan an ISO 27001 ISMS audit by creating risk-driven scopes, performing asset criticality analysis, and scheduling control testing. This approach targets high-risk areas first, ensuring efficient evidence collection and comprehensive security domain coverage for compliance verification.

What is included in ISO 27001 certification readiness for Stage 1 and Stage 2 audits?

ISO 27001 certification readiness involves preparing structured evidence packs, mapping security controls, and establishing remediation workflows. It ensures your ISMS meets Stage 1 documentation reviews and Stage 2 control testing requirements for successful external auditor validation.

How do I manage ISMS audit findings and report compliance gaps effectively?

Manage ISMS audit findings by collecting testing evidence, tracking compliance gaps, and generating structured audit reports. This workflow documents nonconformities against ISO 27001 security controls and drives targeted remediation across your information security domains.

Can I use this for internal ISMS audits and external certification surveillance?

Yes, you can use this for internal ISMS audits and external certification surveillance. It supports control testing, evidence collection, and ongoing risk assessment workflows to maintain ISO 27001 compliance during regular surveillance audits.

What is the best way to map security controls and generate evidence packs for an ISMS audit?

The best way to map security controls and generate evidence packs is to define your audit scope, select relevant ISO 27001 controls, and systematically collect verification artifacts. This structured approach ensures all security domains are thoroughly documented for auditor review.

What are the limitations when testing security controls across complex ISMS domains?

When testing security controls across complex ISMS domains, limitations arise if the risk-based planning scope is too narrow or asset criticality analysis lacks granularity. Insufficient evidence collection can hinder accurate compliance verification and finding management during certification audits.