Conducts comprehensive Information Security Management System (ISMS) audits and manages ISO 27001 compliance workflows from gap analysis to certification support.
This skill transforms Claude into a specialized ISMS auditor, providing expert-level guidance for ISO 27001 compliance. It streamlines the entire audit lifecycle by helping users generate risk-based audit schedules, perform detailed security control assessments, document nonconformities with root cause analysis, and prepare for formal certification stages. Whether managing internal audits or preparing for external surveillance, the skill ensures all Annex A requirements are mapped, evidence is verified, and corrective actions are tracked to maintain a robust security posture.
主な機能
01Automated audit planning scripts and documentation templates
02Preparation support for Stage 1 and Stage 2 certification audits
03Risk-based audit program management and scheduling
04ISO 27001 Annex A control assessment and verification
05Nonconformity classification and root cause analysis
060 GitHub stars
ユースケース
01Conducting internal ISMS audits to verify security control effectiveness
02Managing the remediation of security findings and nonconformities
03Preparing for an upcoming ISO 27001 external certification or surveillance audit