What problem does it solve? Security and compliance teams spend significant time interpreting ISO 27001 requirements, writing policies, and preparing audit evidence. This Skill provides expert-level guidance on both ISO 27001:2013 and ISO 27001:2022, producing structured deliverables like gap analyses, policies, risk registers, and Statements of Applicability. ## Core Features & Use Cases - Gap Analysis: Produces clause-by-clause and Annex A control assessment tables with status, evidence needed, and gap notes. - Policy & Document Generation: Writes full structured policies (access control, incident response, supplier security, etc.) mapped to clauses and Annex A controls with document control blocks. - Risk Assessment Support: Builds risk registers using likelihood × impact methodology with treatment options and residual risk tracking. - Version Transition Guidance: Maps all 114 controls from 2013 to the 93 controls of 2022, including the 11 new controls. - Use Case: A compliance manager preparing for certification asks for a gap analysis against ISO 27001:2022 and receives a complete table covering mandatory clauses 4–10 plus Annex A themes, with prioritized remediation recommendations. ## Quick Start Ask the assistant to perform an ISO 27001:2022 gap analysis for your organization or to draft an access control policy mapped to Annex A controls.