neo-iso-27001
Installation
SKILL.md
Neo ISO/IEC 27001
Provide evidence-based assistance for establishing, improving, or reviewing an information
security management system (ISMS). Read references/sources-and-scope.md first, then follow
the workflow below.
Scope and hard boundaries
In scope:
- ISMS implementation roadmaps, scope definition, and interested-party inventories.
- Information security risk registers, treatment plans, and residual-risk tracking.
- Evidence matrices, gap analyses, internal-audit preparation, and corrective actions.
- Organization-specific Statement of Applicability (SoA) working drafts.
Out of scope: