Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use...
数据来源:ClawHub。 在 ClawSkills 查看
选择你使用的 Agent
方法一:命令行安装(推荐)
推荐(无需提前安装 clawhub)
npx clawhub@latest --dir ~/.claude/skills install isms-audit-expert或使用 clawhub CLI(需提前安装)
clawhub --dir ~/.claude/skills install isms-audit-expert⚠️ 需要 Node.js 18+,没有 Node?请使用下方方法二直接下载 ZIP。 安装 Node.js →
方法二:手动下载安装(无需 Node)
下载 ZIP,解压后将文件夹放到以下路径,重启 Agent 即可:
安装路径
~/.claude/skills/isms-audit-expert/💡解压后将文件夹放到上方路径,重启 Agent 即可生效
--- name: "isms-audit-expert" description: Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows. triggers: - ISMS audit - ISO 27001 audit - security audit - internal audit ISO 27001 - security control assessment - certification audit - surveillance audit - audit finding - nonconformity ---
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
---
| Risk Level | Audit Frequency | Examples | |------------|-----------------|----------| | Critical | Quarterly | Privileged access, vulnerability management, logging | | High | Semi-annual | Access control, incident response, encryption | | Medium | Annual | Policies, awareness training, physical security | | Low | Annual | Documentation, asset inventory |
---
- Confirm audit scope and objectives - Introduce audit team and methodology - Agree on communication channels and logistics
- Interview control owners and operators - Review documentation and records - Observe processes in operation - Inspect technical configurations
- Test control design (does it address the risk?) - Test control operation (is it working as intended?) - Sample transactions and records - Document all evidence collected
- Present preliminary findings - Clarify any factual inaccuracies - Agree on finding classification - Confirm corrective action timelines
---
For detailed technical verification procedures by Annex A control, see security-control-testing.md.
---
| Severity | Definition | Response Time | |----------|------------|---------------| | Major Nonconformity | Control failure creating significant risk | 30 days | | Minor Nonconformity | Isolated deviation with limited impact | 90 days | | Observation | Improvement opportunity | Next audit cycle |
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]
---
Ensure documentation is complete:
Verify operational readiness:
| Period | Focus | |--------|-------| | Year 1, Q2 | High-risk controls, Stage 2 findings follow-up | | Year 1, Q4 | Continual improvement, control sample | | Year 2, Q2 | Full surveillance | | Year 2, Q4 | Re-certification preparation |
Validation: No major nonconformities at surveillance audits.
---
| Script | Purpose | Usage | |--------|---------|-------| | isms_audit_scheduler.py | Generate risk-based audit plans | python scripts/isms_audit_scheduler.py --year 2025 --format markdown |
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
---
| File | Content | |------|---------| | iso27001-audit-methodology.md | Audit program structure, pre-audit phase, certification support | | security-control-testing.md | Technical verification procedures for ISO 27002 controls | | cloud-security-audit.md | Cloud provider assessment, configuration security, IAM review |
---
| KPI | Target | Measurement | |-----|--------|-------------| | Audit plan completion | 100% | Audits completed vs. planned | | Finding closure rate | >90% within SLA | Closed on time vs. total | | Major nonconformities | 0 at certification | Count per certification cycle | | Audit effectiveness | Incidents prevented | Security improvements implemented |
安装 Isms Audit Expert 后,可以对 AI 说这些话来触发它
Send a Slack message to the #engineering channel about the deployment
Formats and sends the message with relevant context, tagging the right people
Summarize all unread messages in my inbox from today
Reads messages across connected channels and returns a prioritized summary
Draft a reply to this customer complaint and send it for review
Writes an empathetic, professional response and routes it to the approval queue
将技能文件夹放到 ~/.claude/skills/isms-audit-expert/ 目录(个人级,所有项目可用),或 .claude/skills/isms-audit-expert/(项目级)。重启 AI 客户端后,用 /isms-audit-expert 主动调用,或让 AI 根据上下文自动发现并使用。
Isms Audit Expert 支持 Claude、Cursor、OpenClaw,可与这些 AI 平台无缝集成,扩展其能力。
Isms Audit Expert 可免费安装使用。请查阅仓库了解许可证信息。
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use...
Isms Audit Expert 属于「Communication」分类,该分类的技能帮助 AI 智能体在此领域执行专业任务。