Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
information-security-manager-iso27001
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when designing an ISMS, running a security risk assessment, implementing ISO 27001/27002 controls, preparing for certification or a security audit, or responding to a security incident.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: information-security-manager-iso27001 description: Use when designing an ISMS, running a security risk assessment, implementing ISO 27001/27002 controls, preparing for certification or a security audit, or responding to a security incident. category: Regulatory & Quality version: 1.0.0 tools: [] --- # Information Security Manager — ISO 27001 Implement and manage an Information Security Management System (ISMS) aligned with ISO 27001:2022 and healthcare regulatory requirements, for HealthTech and MedTech companies. Use for: implementing ISO 27001, an ISMS, a security risk assessment, an information security policy, ISO 27001 certification prep, security-controls implementation, an incident-response plan, healthcare data security, medical device cybersecurity, or a security compliance audit. ## Security Risk Assessment (ISO 27001 Clause 6.1.2) Build an asset inventory with classification (information, software, hardware, services, people), map threats and vulnerabilities per asset, score risk as **likelihood × impact**, and produce treatment recommendations with residual-risk calculations. A healthcare template weighs patient-data and EHR-specific threats more heavily; a cloud template focuses on misconfiguration and outage risk. Risk-level bands and required response: Critical (score 20–25) — immediate action; High (15–19) — treatment plan within 30 days; Medium (10–14) — treatment plan within 90 days; Low (5–9) — accept or monitor; Minimal (1–4) — accept. ## Compliance Checking (ISO 27001 / 27002) Verify control-implementation status against ISO 27001/27002 (and HIPAA where relevant), by domain (e.g. access-control, cryptography), and produce a compliance percentage with a prioritized gap-analysis and remediation recommendations. ## Workflow 1: ISMS Implementation 1. **Define scope and context** — identify interested parties and requirements, define ISMS boundaries, document internal/external issues. Validate: the scope statement is management-approved. 2. **Conduct risk assessment** — identify assets, assess threats/vulnerabilities, calculate risk levels, determine treatment options. Validate: every critical asset is in the register with an assigned owner. 3. **Select and implement controls** — map risks to ISO 27002 controls across four categories: Organizational (policies, roles, responsibilities), People (screening, awareness, training), Physical (perimeters, equipment, media), Technological (access, crypto, network, application). Validate: the Statement of Applicability (SoA) documents every control with justification. 4. **Establish monitoring** — track incident count/severity trend, control-effectiveness scores, training completion, audit-finding closure rate. Validate: a dashboard shows real-time compliance status. ## Workflow 2: Security Risk Assessment (worked pattern) Identify assets and owners (e.g. patient records = confidential information; EHR system/APIs = critical software; servers/medical devices = high hardware; cloud hosting/backup = high services; admin accounts/developers = varies). Map threats per asset (patient data → unauthorized access/breach, high likelihood; medical devices → malware/tampering, medium; cloud services → misconfiguration/outage, medium; credentials → phishing/brute force, high). Assess vulnerabilities across technical (unpatched systems, weak configs), process (missing procedures), and people (lack of training, insider risk) dimensions. Score and treat each risk per the likelihood × impact bands above, and confirm every high/critical risk has an approved treatment plan. **Worked example:** a patient-data management system assessment might surface a data breach on the patient database (weak encryption, likelihood 3 × impact 5 = 15 → mitigate with AES-256 encryption within 30 days), a SQL-injection risk on the EHR application (4×4=16 → mitigate with input validation and a WAF within 14 days), and credential theft on admin accounts (4×5=20 → mitigate by enforcing MFA within 7 days). Verification afterward should show cryptography and access controls fully implemented (AES-256 at rest, TLS 1.3 in transit, MFA on 100% of admin accounts) and flag anything still partial, e.g. a WAF not yet deployed — overall compliance is reported as a percentage. ## Workflow 3: Incident Response Categorize incidents (security breach, malware, data leakage, system compromise, policy violation) and log within 15 minutes of detection. Triage by severity: Critical (data breach, system down) — immediate response; High (active threat, significant risk) — 1 hour; Medium (contained threat, limited impact) — 4 hours; Low (minor violation, no impact) — 24 hours. Contain and eradicate: isolate affected systems, preserve evidence, block threat vectors, remove malicious artifacts — confirm no ongoing compromise. Recover: restore from clean backups, verify integrity before reconnection, document the timeline, run a post-incident review, and update controls — complete the post-incident report within 5 business days. ## Certification Readiness Before Stage 1: ISMS scope documented/approved, security policy published, risk assessment complete, SoA finalized, internal audit conducted, management review complete, nonconformities addressed. Before Stage 2: all Stage 1 findings resolved, ISMS operational for a minimum of 3 months, evidence of control effectiveness available, staff trained, incidents logged and managed, and at least 3 months of metrics collected.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/information-security-manager-iso27001/SKILL.md
Open Source LinkRelated Skills
agent-decision-receipts
Use when an autonomous agent takes a consequential, side-effecting action (deploy, delete, pay, grant-access...
Regulatory & Qualitycapa-officer
Use when running CAPA investigations, 5-Why or fishbone root cause analysis, corrective action planning and...
Regulatory & Qualityeu-ai-act-specialist
Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a...
Regulatory & Qualityfda-consultant-specialist
Use when handling FDA submission pathway selection (510(k)/PMA/De Novo), QMSR/ISO 13485 compliance, medical...