Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

Regulatory & QualityFree Safe

isms-audit-expert

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when planning or running an ISO 27001 ISMS audit — Annex A control assessment, Statement of Applicability, gap analysis, nonconformity findings, or Stage 1/2 certification prep.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: isms-audit-expert
description: Use when planning or running an ISO 27001 ISMS audit — Annex A control assessment, Statement of Applicability, gap analysis, nonconformity findings, or Stage 1/2 certification prep.
category: Regulatory & Quality
version: 1.0.0
tools: []
---

# ISMS Audit Expert

Internal and external ISMS audit management for ISO 27001 compliance verification, security-control assessment, and certification support.

## Audit Program Management

Audit frequency by risk level: Critical controls (privileged access, vulnerability management, logging) — quarterly. High (access control, incident response, encryption) — semi-annual. Medium (policies, awareness training, physical security) — annual. Low (documentation, asset inventory) — annual.

Annual planning: review prior findings and risk-assessment results; identify high-risk controls and recent incidents; scope the audit to the ISMS boundaries; assign auditors who are independent of the areas they audit; build the schedule with resourcing; get management approval. Validate: the plan covers every Annex A control within the certification cycle. Auditors should ideally hold an ISO 27001 Lead Auditor certification, have no operational responsibility for what they audit, understand technical security controls, and know applicable regulations (GDPR, HIPAA).

## Audit Execution

**Pre-audit:** review ISMS documentation (policies, SoA, risk assessment); review prior reports and open findings; build the audit plan and interview schedule; notify auditees of scope and timing; prepare checklists. Validate: all documentation reviewed before the opening meeting.

**Conduct:** open with a meeting confirming scope, objectives, team, and methodology. Collect evidence — interview control owners, review documentation/records, observe processes, inspect technical configurations. Verify controls by testing both design (does it address the risk?) and operation (is it actually working?), sampling transactions/records, and documenting everything. Close with a meeting presenting preliminary findings, clarifying factual inaccuracies, agreeing on classification, and confirming corrective-action timelines. Validate: every control in scope is assessed with documented evidence.

**Control testing:** identify the ISO 27002 control objective; choose a testing method (inquiry, observation, inspection, re-performance); size the sample by population and risk; execute and document; evaluate effectiveness. Validate: the evidence actually supports the conclusion.

## Finding Management

Severity and response time: Major Nonconformity (control failure creating significant risk) — 30 days. Minor Nonconformity (isolated deviation, limited impact) — 90 days. Observation (improvement opportunity) — next audit cycle.

Document each finding with: an ID, the Annex A control reference, severity, the specific evidence observed (records, interview statements), the risk impact if unaddressed, the root cause, and a recommendation.

Corrective-action workflow: the auditee acknowledges the finding and severity; root-cause analysis completes within 10 days; a corrective-action plan is submitted with target dates; responsible parties implement; the auditor verifies effectiveness; the finding closes with evidence of resolution. Validate: the root cause is addressed and recurrence is prevented.

## Certification Support

**Stage 1 readiness:** ISMS scope statement, management-signed security policy, Statement of Applicability, risk-assessment methodology and results, risk-treatment plan, internal-audit results from the past 12 months, management-review minutes.

**Stage 2 readiness:** every Stage 1 finding addressed, ISMS operational for a minimum of 3 months, evidence of control implementation, security-awareness training records, incident-response evidence if applicable, access-review documentation.

**Surveillance cycle:** Year 1 Q2 — high-risk controls plus Stage 2 findings follow-up. Year 1 Q4 — continual improvement plus a control sample. Year 2 Q2 — full surveillance. Year 2 Q4 — re-certification prep. Target: zero major nonconformities at any surveillance audit.

## Performance Metrics

Audit-plan completion target 100%; finding-closure rate target >90% within SLA; major nonconformities target 0 per certification cycle; audit effectiveness measured by security improvements actually implemented as a result.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/skills/isms-audit-expert/SKILL.md

Open Source Link
Regulatory & Quality

Related Skills