iso-27001-evidence-collection

Collect and organize ISO 27001:2022 and SOC 2 audit evidence by control.

46|9|Updated Feb 9, 2026
One-click install
npx skills add https://github.com/open-agreements/open-agreements --skill iso-27001-evidence-collection
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-27001-evidence-collection
Source: https://github.com/open-agreements/open-agreements/tree/main/skills/iso-27001-evidence-collection
Command: npx skills add https://github.com/open-agreements/open-agreements --skill iso-27001-evidence-collection

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the complex and time-consuming process of gathering, organizing, and validating evidence required for ISO 27001 and SOC 2 audits, ensuring compliance and auditor readiness.

Core Features & Use Cases

  • API-First Evidence Collection: Leverages CLI commands for major cloud platforms (GCP, Azure, AWS, GitHub, Google Workspace) and endpoints for automated data retrieval.
  • Control Mapping: Organizes collected evidence according to ISO 27001 control IDs and provides guidance on evidence freshness requirements.
  • Validation & Indexing: Includes steps for validating evidence completeness, format, and freshness, culminating in an evidence package index.
  • Use Case: Before an upcoming ISO 27001 audit, activate this skill to systematically collect all necessary evidence for access control, logging, and change management, ensuring no gaps are found.

Quick Start

Use the iso-27001-evidence-collection skill to collect evidence for control A.5.15 by running the GitHub IAM policy command.

Frequently Asked Questions about iso-27001-evidence-collection

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate ISO 27001 evidence collection for cloud platforms like GCP and Azure?

Automate ISO 27001 evidence collection by using API-first CLI commands to retrieve access control and logging data from GCP, Azure, AWS, and GitHub, organizing the output by control ID. This produces timestamped, auditor-ready packages.

What is the best way to map SOC 2 audit evidence to ISO 27001 controls?

Map SOC 2 audit evidence to ISO 27001 controls by collecting data across cloud platforms and automatically organizing the artifacts according to ISO 27001:2022 control IDs. This ensures both frameworks share validated, timestamped compliance packages.

Can I detect compliance gaps automatically before an ISO 27001 audit?

Detect compliance gaps automatically before an ISO 27001 audit by using the optional MCP server for continuous validation. If unavailable, the system falls back to embedded checklists and CLI command references to ensure evidence completeness.

How do I validate freshness and format of audit evidence for ISO 27001?

Validate audit evidence freshness and format for ISO 27001 by running built-in validation steps that check data completeness and recency. This process culminates in an evidence package index to confirm auditor readiness.

Does this evidence collection process support GitHub IAM policy retrieval?

Yes, the evidence collection process supports GitHub IAM policy retrieval through specific API-first CLI commands. You can systematically collect necessary access control evidence for control A.5.15 by executing the designated GitHub command.

What are the limitations of using CLI commands for SOC 2 evidence collection?

CLI commands for SOC 2 evidence collection require proper API access configuration across cloud platforms and rely on an optional MCP server for automated gap detection. Without the server, validation falls back to manual embedded checklists.