roadmap

Translate ISO 27001:2022 findings into a phased project plan with milestones, owners, and dates.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill roadmap-gombing
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: roadmap
Source: https://github.com/gombing/ISO27001Agent/tree/main/roadmap
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill roadmap-gombing

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

ISO 27001:2022 Implementation Roadmap converts gap, annex, and risk-treatment findings into a phased project plan that aligns actions with a certifiable timeline, ensuring governance and traceability throughout the certification journey.

Core Features & Use Cases

  • Phased project planning that groups findings (Red/Amber, NIM controls) into workstreams with milestones and ownership.
  • Output a dated Project Plan that ISMS owners can track week by week and feed into /policy-gen and /internal-audit scheduling.
  • Supports alignment with SoA, RTP, and risk treatment actions to drive certification readiness across Phase 1–4.

Quick Start

Initiate the roadmap by asking the roadmap skill to translate your latest engagement findings into a structured, phased plan.

Frequently Asked Questions about roadmap

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create an ISO 27001 implementation roadmap from gap analysis findings?

An ISO 27001 implementation roadmap converts unresolved gap analysis findings and risk treatment actions into a phased project plan with milestones, owners, and dates. This aligns remediation workloads directly with your certification target timeline.

What is a phased project plan for ISO 27001 risk treatment?

A phased ISO 27001 risk treatment plan groups unresolved findings like Red/Amber gaps and NIM controls into distinct workstreams. It applies governance inputs and workload estimates to schedule actions across Phase 1–4 milestones.

Can I use my Statement of Applicability and RTP to drive ISO 27001 certification readiness?

You can drive certification readiness by aligning your Statement of Applicability (SoA) and Risk Treatment Plan (RTP) within a multi-phase implementation schedule. The roadmap translates these inputs into dated, trackable workstreams.

How do I schedule internal audits and policy generation after an ISO 27001 gap analysis?

You schedule internal audits and policy generation by creating a dated project plan from your gap analysis. The roadmap interfaces directly with policy-gen and internal-audit scheduling so ISMS owners can track dependencies week by week.

Does the ISO 27001 roadmap support workload estimates and governance constraints?

The ISO 27001 roadmap supports workload estimates and governance constraints by reflecting these inputs alongside risk treatment actions. This ensures the multi-phase plan remains executable and aligned with your certification targets.