iso27001

Analyze ISO 27001:2022 Annex A controls across AWS environments for implementation gaps.

7|2|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/kkmookhey/shasta --skill iso27001
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso27001
Source: https://github.com/kkmookhey/shasta/tree/main/.claude/skills/iso27001
Command: npx skills add https://github.com/kkmookhey/shasta --skill iso27001

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

ISO 27001:2022 Annex A gap analysis in AWS helps founders and security teams identify where controls are missing or not fully implemented, reducing time to readiness for certification.

Core Features & Use Cases

  • Annex A control mapping: align AWS controls with ISO 27001 requirements.
  • Automated gap identification and scoring: generate a clear remediation plan and evidence for audits.
  • Markdown report generation: produce auditable documentation that can be shared with auditors.

Quick Start

Run the ISO 27001 gap analysis against your AWS environment using the Python command specified in shasta.config.json.

Frequently Asked Questions about iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an ISO 27001 gap analysis in my AWS environment?

To perform an ISO 27001 gap analysis in AWS, run the Shasta scanner with the Python command specified in shasta.config.json to evaluate Annex A controls and generate a markdown report identifying implementation gaps.

What is AWS control mapping for ISO 27001:2022 Annex A?

AWS control mapping for ISO 27001:2022 Annex A aligns your AWS environment configurations with ISO 27001 requirements to identify missing or incomplete security controls and produce auditable evidence.

Can I use this tool to generate ISO 27001 compliance reports for auditors?

Yes, you can generate ISO 27001 compliance reports for auditors by running the ISO27001 mapper and scorer modules against your AWS accounts, which produces markdown documentation detailing your remediation plan and evidence.

Does ISO 27001 gap analysis require configuring AWS account access?

Yes, ISO 27001 gap analysis requires AWS account access configured through the shasta.config.json file, specifically setting up the python_cmd to enable the Shasta scanner to evaluate your environment.

What is the best way to identify missing ISO 27001 controls in AWS?

The best way to identify missing ISO 27001 controls in AWS is using an automated gap analysis tool that scores your Annex A implementation readiness and highlights specific security gaps across your accounts.

When do I need an ISO 27001 gap analysis for AWS readiness?

You need an ISO 27001 gap analysis for AWS readiness when preparing for certification, allowing founders and security teams to pinpoint unimplemented controls and reduce time to audit readiness.