Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.
isms-audit-expert
Security Scan Summary
Status: Safe
Source: Syntic Skills registry
Automated security scan completed with no high-risk patterns detected. Manual review is still required.
About This Skill
Use when planning or running an ISO 27001 ISMS audit — Annex A control assessment, Statement of Applicability, gap analysis, nonconformity findings, or Stage 1/2 certification prep.
Downloadable SKILL.md
Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.
--- name: isms-audit-expert description: Use when planning or running an ISO 27001 ISMS audit — Annex A control assessment, Statement of Applicability, gap analysis, nonconformity findings, or Stage 1/2 certification prep. category: Regulatory & Quality version: 1.0.0 tools: [] --- # ISMS Audit Expert Internal and external ISMS audit management for ISO 27001 compliance verification, security-control assessment, and certification support. ## Audit Program Management Audit frequency by risk level: Critical controls (privileged access, vulnerability management, logging) — quarterly. High (access control, incident response, encryption) — semi-annual. Medium (policies, awareness training, physical security) — annual. Low (documentation, asset inventory) — annual. Annual planning: review prior findings and risk-assessment results; identify high-risk controls and recent incidents; scope the audit to the ISMS boundaries; assign auditors who are independent of the areas they audit; build the schedule with resourcing; get management approval. Validate: the plan covers every Annex A control within the certification cycle. Auditors should ideally hold an ISO 27001 Lead Auditor certification, have no operational responsibility for what they audit, understand technical security controls, and know applicable regulations (GDPR, HIPAA). ## Audit Execution **Pre-audit:** review ISMS documentation (policies, SoA, risk assessment); review prior reports and open findings; build the audit plan and interview schedule; notify auditees of scope and timing; prepare checklists. Validate: all documentation reviewed before the opening meeting. **Conduct:** open with a meeting confirming scope, objectives, team, and methodology. Collect evidence — interview control owners, review documentation/records, observe processes, inspect technical configurations. Verify controls by testing both design (does it address the risk?) and operation (is it actually working?), sampling transactions/records, and documenting everything. Close with a meeting presenting preliminary findings, clarifying factual inaccuracies, agreeing on classification, and confirming corrective-action timelines. Validate: every control in scope is assessed with documented evidence. **Control testing:** identify the ISO 27002 control objective; choose a testing method (inquiry, observation, inspection, re-performance); size the sample by population and risk; execute and document; evaluate effectiveness. Validate: the evidence actually supports the conclusion. ## Finding Management Severity and response time: Major Nonconformity (control failure creating significant risk) — 30 days. Minor Nonconformity (isolated deviation, limited impact) — 90 days. Observation (improvement opportunity) — next audit cycle. Document each finding with: an ID, the Annex A control reference, severity, the specific evidence observed (records, interview statements), the risk impact if unaddressed, the root cause, and a recommendation. Corrective-action workflow: the auditee acknowledges the finding and severity; root-cause analysis completes within 10 days; a corrective-action plan is submitted with target dates; responsible parties implement; the auditor verifies effectiveness; the finding closes with evidence of resolution. Validate: the root cause is addressed and recurrence is prevented. ## Certification Support **Stage 1 readiness:** ISMS scope statement, management-signed security policy, Statement of Applicability, risk-assessment methodology and results, risk-treatment plan, internal-audit results from the past 12 months, management-review minutes. **Stage 2 readiness:** every Stage 1 finding addressed, ISMS operational for a minimum of 3 months, evidence of control implementation, security-awareness training records, incident-response evidence if applicable, access-review documentation. **Surveillance cycle:** Year 1 Q2 — high-risk controls plus Stage 2 findings follow-up. Year 1 Q4 — continual improvement plus a control sample. Year 2 Q2 — full surveillance. Year 2 Q4 — re-certification prep. Target: zero major nonconformities at any surveillance audit. ## Performance Metrics Audit-plan completion target 100%; finding-closure rate target >90% within SLA; major nonconformities target 0 per certification cycle; audit effectiveness measured by security improvements actually implemented as a result.
Bundle Download
Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.
Install Targets
Syntic App
- 1. Create a dedicated folder for this skill in your local skills library.
- 2. Place SKILL.md into that folder.
- 3. Restart Syntic and invoke this skill on matching tasks.
Syntic Code (CLI)
- 1. Save SKILL.md in your local Syntic Code skills directory.
- 2. Keep related files in the same skill folder.
- 3. Run in a safe environment and validate outputs.
Source
https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/isms-audit-expert/SKILL.md
Open Source LinkRelated Skills
agent-decision-receipts
Use when an autonomous agent takes a consequential, side-effecting action (deploy, delete, pay, grant-access...
Regulatory & Qualitycapa-officer
Use when running CAPA investigations, 5-Why or fishbone root cause analysis, corrective action planning and...
Regulatory & Qualityeu-ai-act-specialist
Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a...
Regulatory & Qualityfda-consultant-specialist
Use when handling FDA submission pathway selection (510(k)/PMA/De Novo), QMSR/ISO 13485 compliance, medical...