isms-audit-expert

Generate risk-based ISO 27001 ISMS audit plans and testing procedures.

2|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/zhangzhang-111-i/claude-skills111 --skill isms-audit-expert-zhangzhang-111-i
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: isms-audit-expert
Source: https://github.com/zhangzhang-111-i/claude-skills111/tree/main/ra-qm-team/isms-audit-expert
Command: npx skills add https://github.com/zhangzhang-111-i/claude-skills111 --skill isms-audit-expert-zhangzhang-111-i

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the complex process of conducting Information Security Management System (ISMS) audits for ISO 27001 compliance, ensuring thorough verification and certification readiness.

Core Features & Use Cases

  • Risk-Based Audit Planning: Generates tailored audit schedules based on control risk levels.
  • Control Assessment Guidance: Provides detailed testing procedures for ISO 27002 controls.
  • Finding Management: Offers templates and workflows for documenting and tracking nonconformities.
  • Certification Support: Guides users through Stage 1 and Stage 2 audit preparations.
  • Use Case: A company preparing for its ISO 27001 certification can use this Skill to create a comprehensive audit plan, understand how to test specific controls like access management and logging, and manage any findings identified during internal audits.

Quick Start

Use the isms-audit-expert skill to generate a risk-based audit plan for the year 2025.

Frequently Asked Questions about isms-audit-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a risk-based audit schedule for ISO 27001 compliance?

An ISO 27001 risk-based audit schedule prioritizes controls by risk level. This Skill generates tailored audit plans using Python scripts to ensure comprehensive coverage for internal and Stage 1 or Stage 2 certification audits.

What are the detailed testing procedures for ISO 27001 Annex A controls?

Testing ISO 27001 Annex A controls involves verifying specific security requirements like access management and logging. Reference methodologies provide structured procedures to assess compliance and identify nonconformities accurately.

How do I manage and document nonconformities found during an ISMS audit?

Managing ISMS audit nonconformities requires structured finding management workflows. Using provided templates ensures findings are documented, tracked, and resolved systematically to maintain security compliance.

Can I use this approach to prepare for both Stage 1 and Stage 2 ISO 27001 certification audits?

Yes, preparing for Stage 1 and Stage 2 ISO 27001 certification audits is fully supported. The methodology guides you through readiness checks, detailed control testing, and documentation required for both certification stages.

When do I need to conduct an internal ISMS audit versus a surveillance audit?

An internal ISMS audit verifies your own security compliance before certification, while a surveillance audit is conducted periodically by external auditors. Both require detailed control testing and risk-based audit planning.