What problem does it solve? Security teams struggle to connect firewall configurations to ISO/IEC 27001:2022 audit requirements without overclaiming compliance. This Skill maps NGFW controls, evidence, and gaps to Annex A themes while keeping conclusions grounded in the ISMS scope and Statement of Applicability. ## Core Features & Use Cases - Control Mapping: Maps firewall capabilities to ISO 27001:2022 Annex A themes such as access control, network security, logging, supplier access, and change management. - Assessment Workflow: Provides a five-step workflow covering ISMS context, evidence matrices, policy review, config evidence markers, and operating-effectiveness validation. - Audit-Ready Outputs: Generates assessment summaries, findings, and evidence-marker recommendations tied to SoA control IDs. - Use Case: Before a certification audit, use this Skill to review exported firewall policies, identify that a vendor VPN rule lacks expiry and review records, and produce a finding mapped to supplier-access and logging controls with corrective actions. ## Quick Start Use the iso27001-ngfw-compliance skill to map this firewall configuration export to ISO 27001 Annex A controls and list the evidence gaps.