isms-audit-expert

Generate risk-based ISO 27001 audit plans with Python scheduling and markdown outputs.

Updated Mar 5, 2026
One-click install
npx skills add https://github.com/theandyalvarez7-ruby/claude-skills --skill isms-audit-expert-theandyalvarez7-ruby
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/theandyalvarez7-ruby/claude-skills/tree/main/ra-qm-team/isms-audit-expert
Command: npx skills add https://github.com/theandyalvarez7-ruby/claude-skills --skill isms-audit-expert-theandyalvarez7-ruby

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Information Security Management System (ISMS) audits are complex and resource-intensive; this skill provides structured, risk-based planning and execution guidance to streamline ISO 27001 compliance verification and certification support.

Core Features & Use Cases

  • Risk-based audit scheduling across ISO 27001 Annex A controls.
  • Automated generation of audit plans, findings tracking, and certification readiness artifacts.
  • Use case: an ISMS manager generates annual plans, assigns audit tasks, and tracks corrective actions.

Quick Start

Run the isms_audit_scheduler.py to generate an annual audit plan for your ISO 27001 program.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a risk-based audit plan for ISO 27001 compliance?

To generate a risk-based ISO 27001 audit plan, run the Python scheduler to map control risks across Annex A domains and output structured annual audit schedules. This automates planning for internal, external, and surveillance audits.

Can I track ISO 27001 audit findings and remediation actions automatically?

Yes, you can track ISO 27001 audit findings and remediation actions using the provided markdown and JSON outputs. The system generates findings tracking artifacts alongside the risk-based audit plans to support certification readiness.

What is risk-based audit scheduling for an ISMS?

Risk-based ISMS audit scheduling prioritizes ISO 27001 Annex A controls based on risk levels. This approach streamlines compliance verification by focusing audit resources on higher-risk areas across internal and external certification audits.

Does this ISO 27001 audit planner support certification and surveillance audits?

Yes, the ISO 27001 audit planner supports certification and surveillance audits. It applies risk-based scheduling across ISO 27001 domains to coordinate both initial certification support and ongoing surveillance activities.

What output formats does the ISO 27001 audit scheduler produce?

The ISO 27001 audit scheduler produces markdown and JSON outputs. These formats provide structured artifacts for annual audit plans, control risk mappings, findings tracking, and certification readiness documentation.

How do I prepare for an ISO 27001 audit using a Python-based scheduler?

Prepare for an ISO 27001 audit by running the Python-based scheduler to generate your annual plan. The scheduler coordinates control risk mappings across Annex A domains to produce structured audit plans and remediation tracking.