iso-expert

Guide ISO 27001 ISMS certification with Annex A mapping and risk assessment.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill iso-expert-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso-expert
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/frameworks/iso27001/skills/iso-expert
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill iso-expert-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Implementing ISO 27001 ISMS is complex, requiring alignment of governance, risk, and controls to meet certification requirements and maintain continual improvement.

Core Features & Use Cases

  • Guidance on ISMS scope, context, leadership, risk assessment, controls selection, and continual improvement.
  • Annex A controls mapping with practical implementation guidance for certification readiness.
  • Use Case: prepare for ISO 27001 certification by identifying gaps, documenting policies, and planning a risk-based treatment plan.

Quick Start

Outline your ISMS scope, identify context, and begin a risk assessment using the ISO 27001 guidance.

Frequently Asked Questions about iso-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare for ISO 27001 certification?

The ISO 27001 ISMS implementation process aligns information security governance, risk assessment, and control selection to satisfy certification requirements. It guides scope definition, context identification, and risk-based treatment planning for continual improvement.

What is included in ISO 27001 Annex A controls mapping?

ISO 27001 Annex A controls mapping provides structured guidance for selecting and implementing security controls. It maps controls directly to ISMS certification requirements to ensure your risk treatment plan addresses all necessary governance gaps.

How do I start an ISMS risk assessment for certification readiness?

Start an ISMS risk assessment by outlining your information security scope and organizational context. Use ISO 27001 guidance to identify risks, select appropriate controls, and document policies for a structured risk-based treatment plan.

Can I use this for ISO 27001 continual improvement planning?

Yes, you can use this for ISO 27001 continual improvement planning. It supports maintaining ISMS certification by guiding ongoing risk assessment updates, control re-evaluation, and governance alignment to sustain certification readiness over time.

Does ISO 27001 guidance work for any organization implementing an ISMS?

Yes, ISO 27001 guidance applies to information security governance projects across any organization implementing an ISMS. It supports risk assessment, Annex A control selection, and certification readiness regardless of organizational size or sector.