iso27001

Generates ISO 27001 gap analyses, policies, risk registers, and Annex A control guidance.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso27001-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iso27001
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/iso27001
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill iso27001-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security and compliance teams spend significant time interpreting ISO 27001 requirements, writing policies, and preparing audit evidence. This Skill provides expert-level guidance on both ISO 27001:2013 and ISO 27001:2022, producing structured deliverables like gap analyses, policies, risk registers, and Statements of Applicability. ## Core Features & Use Cases - Gap Analysis: Produces clause-by-clause and Annex A control assessment tables with status, evidence needed, and gap notes. - Policy & Document Generation: Writes full structured policies (access control, incident response, supplier security, etc.) mapped to clauses and Annex A controls with document control blocks. - Risk Assessment Support: Builds risk registers using likelihood × impact methodology with treatment options and residual risk tracking. - Version Transition Guidance: Maps all 114 controls from 2013 to the 93 controls of 2022, including the 11 new controls. - Use Case: A compliance manager preparing for certification asks for a gap analysis against ISO 27001:2022 and receives a complete table covering mandatory clauses 4–10 plus Annex A themes, with prioritized remediation recommendations. ## Quick Start Ask the assistant to perform an ISO 27001:2022 gap analysis for your organization or to draft an access control policy mapped to Annex A controls.

Frequently Asked Questions about iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform an ISO 27001 gap analysis?

Specify your target version (2013 or 2022), ISMS scope, and industry. The skill produces a table covering all mandatory clauses 4-10 and applicable Annex A controls, with status ratings, evidence needed, gap notes, and a prioritized remediation summary.

What are the differences between ISO 27001:2013 and 2022?

The 2022 version reduced Annex A from 114 controls in 14 domains to 93 controls in 4 themes, added 11 new controls covering cloud security, threat intelligence, and data masking, and introduced minor clause changes like 6.3 and split sub-clauses in 9.2 and 9.3.

What documents are mandatory for ISO 27001 certification?

Mandatory records include the ISMS scope, information security policy, risk assessment and treatment processes, Statement of Applicability, security objectives, competence evidence, internal audit results, management review results, and nonconformity records with corrective actions.

How do I write an ISO 27001 access control policy?

The policy should include purpose, scope, policy statement, roles and responsibilities, procedures, review cycle, and a document control block. It maps primarily to clause 8.1 and Annex A 2022 controls A.5.15 through A.5.18.

What are the 11 new controls in ISO 27001:2022?

The new controls are A.5.7 threat intelligence, A.5.23 cloud services security, A.5.30 ICT readiness for business continuity, A.7.4 physical security monitoring, A.8.9 configuration management, A.8.10 information deletion, A.8.11 data masking, A.8.12 data leakage prevention, A.8.16 monitoring activities, A.8.23 web filtering, and A.8.28 secure coding.

Does this skill replace a certified ISO 27001 auditor?

No. The skill provides general compliance information and implementation guidance, not legal advice. Certification decisions and formal audits require an accredited certification body, and complex compliance questions should be verified with qualified counsel or assessors.