ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control imple...
数据来源:ClawHub。 在 ClawSkills 查看
选择你使用的 Agent
方法一:命令行安装(推荐)
推荐(无需提前安装 clawhub)
npx clawhub@latest --dir ~/.claude/skills install information-security-manager-iso27001或使用 clawhub CLI(需提前安装)
clawhub --dir ~/.claude/skills install information-security-manager-iso27001⚠️ 需要 Node.js 18+,没有 Node?请使用下方方法二直接下载 ZIP。 安装 Node.js →
方法二:手动下载安装(无需 Node)
下载 ZIP,解压后将文件夹放到以下路径,重启 Agent 即可:
安装路径
~/.claude/skills/information-security-manager-iso27001/💡解压后将文件夹放到上方路径,重启 Agent 即可生效
--- name: "information-security-manager-iso27001" description: ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control implementation, ISO 27001 certification, security audits, incident response, and compliance verification. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity. ---
Implement and manage Information Security Management Systems (ISMS) aligned with ISO 27001:2022 and healthcare regulatory requirements.
---
---
Use this skill when you hear:
---
python scripts/risk_assessment.py --scope "patient-data-system" --output risk_register.json
python scripts/compliance_checker.py --standard iso27001 --controls-file controls.csv
python scripts/compliance_checker.py --standard iso27001 --gap-analysis --output gaps.md
---
Automated security risk assessment following ISO 27001 Clause 6.1.2 methodology.
Usage:
# Full risk assessment
python scripts/risk_assessment.py --scope "cloud-infrastructure" --output risks.json
# Healthcare-specific assessment
python scripts/risk_assessment.py --scope "ehr-system" --template healthcare --output risks.json
# Quick asset-based assessment
python scripts/risk_assessment.py --assets assets.csv --output risks.json
Parameters:
| Parameter | Required | Description | |-----------|----------|-------------| | --scope | Yes | System or area to assess | | --template | No | Assessment template: general, healthcare, cloud | | --assets | No | CSV file with asset inventory | | --output | No | Output file (default: stdout) | | --format | No | Output format: json, csv, markdown |
Output:
Verify ISO 27001/27002 control implementation status.
Usage:
# Check all ISO 27001 controls
python scripts/compliance_checker.py --standard iso27001
# Gap analysis with recommendations
python scripts/compliance_checker.py --standard iso27001 --gap-analysis
# Check specific control domains
python scripts/compliance_checker.py --standard iso27001 --domains "access-control,cryptography"
# Export compliance report
python scripts/compliance_checker.py --standard iso27001 --output compliance_report.md
Parameters:
| Parameter | Required | Description | |-----------|----------|-------------| | --standard | Yes | Standard to check: iso27001, iso27002, hipaa | | --controls-file | No | CSV with current control status | | --gap-analysis | No | Include remediation recommendations | | --domains | No | Specific control domains to check | | --output | No | Output file path |
Output:
---
Step 1: Define Scope and Context
Document organizational context and ISMS boundaries:
Validation: Scope statement reviewed and approved by management.
Step 2: Conduct Risk Assessment
python scripts/risk_assessment.py --scope "full-organization" --template general --output initial_risks.json
Validation: Risk register contains all critical assets with assigned owners.
Step 3: Select and Implement Controls
Map risks to ISO 27002 controls:
python scripts/compliance_checker.py --standard iso27002 --gap-analysis --output control_gaps.md
Control categories:
Validation: Statement of Applicability (SoA) documents all controls with justification.
Step 4: Establish Monitoring
Define security metrics:
Validation: Dashboard shows real-time compliance status.
Step 1: Asset Identification
Create asset inventory:
| Asset Type | Examples | Classification | |------------|----------|----------------| | Information | Patient records, source code | Confidential | | Software | EHR system, APIs | Critical | | Hardware | Servers, medical devices | High | | Services | Cloud hosting, backup | High | | People | Admin accounts, developers | Varies |
Validation: All assets have assigned owners and classifications.
Step 2: Threat Analysis
Identify threats per asset category:
| Asset | Threats | Likelihood | |-------|---------|------------| | Patient data | Unauthorized access, breach | High | | Medical devices | Malware, tampering | Medium | | Cloud services | Misconfiguration, outage | Medium | | Credentials | Phishing, brute force | High |
Validation: Threat model covers top-10 industry threats.
Step 3: Vulnerability Assessment
python scripts/risk_assessment.py --scope "network-infrastructure" --output vuln_risks.json
Document vulnerabilities:
Validation: Vulnerability scan results mapped to risk register.
Step 4: Risk Evaluation and Treatment
Calculate risk: Risk = Likelihood × Impact
| Risk Level | Score | Treatment | |------------|-------|-----------| | Critical | 20-25 | Immediate action required | | High | 15-19 | Treatment plan within 30 days | | Medium | 10-14 | Treatment plan within 90 days | | Low | 5-9 | Accept or monitor | | Minimal | 1-4 | Accept |
Validation: All high/critical risks have approved treatment plans.
Step 1: Detection and Reporting
Incident categories:
Validation: Incident logged within 15 minutes of detection.
Step 2: Triage and Classification
| Severity | Criteria | Response Time | |----------|----------|---------------| | Critical | Data breach, system down | Immediate | | High | Active threat, significant risk | 1 hour | | Medium | Contained threat, limited impact | 4 hours | | Low | Minor violation, no impact | 24 hours |
Validation: Severity assigned and escalation triggered if needed.
Step 3: Containment and Eradication
Immediate actions:
Validation: Containment confirmed, no ongoing compromise.
Step 4: Recovery and Lessons Learned
...
安装 Information Security Manager Iso27001 后,可以对 AI 说这些话来触发它
Help me get started with Information Security Manager Iso27001
Explains what Information Security Manager Iso27001 does, walks through the setup, and runs a quick demo based on your current project
Use Information Security Manager Iso27001 to iSO 27001 ISMS implementation and cybersecurity governance for Heal...
Invokes Information Security Manager Iso27001 with the right parameters and returns the result directly in the conversation
What can I do with Information Security Manager Iso27001 in my developer & devops workflow?
Lists the top use cases for Information Security Manager Iso27001, with example commands for each scenario
将技能文件夹放到 ~/.claude/skills/information-security-manager-iso27001/ 目录(个人级,所有项目可用),或 .claude/skills/information-security-manager-iso27001/(项目级)。重启 AI 客户端后,用 /information-security-manager-iso27001 主动调用,或让 AI 根据上下文自动发现并使用。
Information Security Manager Iso27001 支持 Claude、Cursor、OpenClaw,可与这些 AI 平台无缝集成,扩展其能力。
Information Security Manager Iso27001 可免费安装使用。请查阅仓库了解许可证信息。
ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control imple...
Automate my developer & devops tasks using Information Security Manager Iso27001
Identifies repetitive steps in your workflow and sets up Information Security Manager Iso27001 to handle them automatically
Information Security Manager Iso27001 属于「Developer & DevOps」分类,该分类的技能帮助 AI 智能体在此领域执行专业任务。