iso-27001-isms-architect

Designs ISO/IEC 27001:2022 ISMS artifacts and audit-ready readiness plans.

2|Updated Jul 6, 2026
One-click install
npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill iso-27001-isms-architect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-27001-isms-architect
Source: https://github.com/nguyenpv1980-wq/Project-Aegis/tree/main/.claude/skills/iso-27001-isms-architect
Command: npx skills add https://github.com/nguyenpv1980-wq/Project-Aegis --skill iso-27001-isms-architect

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps teams design and repair an ISO/IEC 27001:2022 information security management system so they can move from ad hoc security practices to a structured, auditable certification-ready program.

Core Features & Use Cases

  • ISMS Design: Defines scope, context, leadership, risk management, support, operations, performance evaluation, and improvement for an ISO 27001 program.
  • Annex A Selection Planning: Maps existing controls to the four Annex A themes and identifies where net-new management-system artifacts are needed.
  • Audit Readiness: Builds the internal audit program, management review cadence, corrective-action routing, and evidence plan needed for certification preparation.
  • Use Case: A SaaS company with strong engineering controls but no formal ISMS can use this Skill to structure its 27001 readiness plan and identify the missing management-system artifacts.

Quick Start

Ask the skill to design an ISO 27001 ISMS for your organization, including scope, risk register, Annex A mapping, internal audits, management review, and a readiness plan.

Frequently Asked Questions about iso-27001-isms-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design an ISO 27001 ISMS for an organization that already has security engineering controls?

To design an ISO 27001 ISMS for existing security controls, you define the scope and context, then build the clause 4–10 management-system artifacts, including risk registers and Annex A mappings, producing an audit-ready certification plan.

What is Annex A control selection and how does it map to existing security controls?

Annex A control selection maps your existing engineering security controls to the four ISO 27001:2022 Annex A themes, identifying gaps where net-new management-system artifacts are required to achieve compliance and certification readiness.

How do I prepare for an ISO 27001 internal audit and management review?

Preparing for an ISO 27001 internal audit involves building an internal audit program, establishing a management review cadence, routing corrective actions, and planning evidence collection to demonstrate operational effectiveness and audit readiness.

Can I use this approach to repair an ISO 27001 surveillance audit finding?

Yes, you can repair a surveillance audit finding by restructuring the information security management system, routing corrective actions through the documented improvement process, and updating the evidence plan for the next review.

Does ISO 27001 certification readiness require formal management-system artifacts if we already have strong engineering controls?

Yes, ISO 27001 certification readiness requires formal management-system artifacts. Strong engineering controls alone do not satisfy clauses 4–10; you must design leadership, risk management, support, and performance evaluation processes for compliance.

What are the limitations of designing an ISO 27001 readiness plan without claiming certification?

Designing an ISO 27001 readiness plan structures your management system and evidence, but it does not grant certification. You must still pass a formal external audit from an accredited certification body to achieve official compliance.