iso-27001-controls

Implement and audit ISO 27001:2022 Annex A controls across the CIA platform.

235|56|Updated Aug 1, 2015
One-click install
npx skills add https://github.com/Hack23/cia --skill iso-27001-controls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-27001-controls
Source: https://github.com/Hack23/cia/tree/main/.github/skills/iso-27001-controls
Command: npx skills add https://github.com/Hack23/cia --skill iso-27001-controls

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and developers verify and enforce ISO 27001:2022 Annex A controls across the CIA platform, ensuring consistent security posture and auditable evidence.

Core Features & Use Cases

  • Guidance and templates to map Annex A controls to CIA platform components (A.5 Organizational, A.8 Technical, A.14 Development and Maintenance).
  • Evidence templates and checklists to support ISMS audits, risk assessments, and certification readiness.
  • Use Case: When preparing for ISO 27001 certification, run a control gap analysis and generate an evidence pack for A.8 and A.14 in your ISMS repository.

Quick Start

Follow the ISO 27001 controls guidance to perform a starter audit, map controls to existing assets, and generate an evidence pack for A.8 and A.14 in your ISMS repository.

Frequently Asked Questions about iso-27001-controls

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I verify ISO 27001 Annex A controls for an ISMS audit?

Verify ISO 27001 Annex A controls by mapping organizational, technical, and development controls to platform components. Generate evidence templates and checklists to support ISMS audits, risk assessments, and certification readiness.

What is included in ISO 27001:2022 Annex A control gap analysis?

ISO 27001:2022 Annex A control gap analysis covers organizational controls (A.5), technical controls (A.8), and development controls (A.14). It codifies responsibilities, testing approaches like SAST and DAST, and example configurations to verify control effectiveness.

How do I prepare an evidence pack for ISO 27001 certification?

Prepare an ISO 27001 certification evidence pack by running a control gap analysis and generating documentation for A.8 and A.14 controls. Store the resulting evidence templates and checklists directly in your ISMS repository.

Can I map vulnerability management and incident handling to ISO 27001 controls?

Map vulnerability management and incident handling to ISO 27001 controls through defined testing approaches. The skill codifies these responsibilities alongside SAST and DAST configurations to verify technical and system development control effectiveness.

Does this ISO 27001 controls guidance cover system development and maintenance controls?

Yes, the ISO 27001 controls guidance covers A.14 system development and maintenance controls. It provides practical use cases, example configurations, and audit-ready documentation to verify development lifecycle security effectiveness.