iso-27001-isms
Installation
SKILL.md
ISO 27001 ISMS Skill
ISO 27001 certifies a system (the ISMS), not a checklist — auditors check that you scoped it, assessed risk, and can justify which Annex A controls you applied or excluded (the Statement of Applicability). This skill builds that backbone: scope, risk treatment, and a defensible SoA, so certification is a documented management system rather than a scramble.
Required Inputs
Ask for these only if they aren't already provided:
- ISMS scope — the products, locations, and information assets in scope (and what's deliberately out).
- Context & interested parties — the business, its regulatory/customer security obligations, and key risks.
- Risk approach — how you identify, assess, and treat information-security risk (the SoA flows from the risk assessment, not the other way round).
- Current controls — what's already implemented across the Annex A domains.