artifacts/bundle/skills/ra-qm-team/isms-audit-expert/SKILL.md
# ISMS Audit Expert Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support. ## Table of Contents - [Audit Program Management](#audit-program-management) - [Audit Execution](#audit-execution) - [Control Assessment](#control-assessment) - [Finding Management](#finding-management) - [Certification Support](#certification-support) - [Tools](#tools) - [References](#references) --- ## Audit Program Management ###
npx skillsauth add neekware/ehayeskills artifacts/bundle/skills/ra-qm-team/isms-audit-expertInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
| Risk Level | Audit Frequency | Examples | | ---------- | --------------- | ---------------------------------------------------- | | Critical | Quarterly | Privileged access, vulnerability management, logging | | High | Semi-annual | Access control, incident response, encryption | | Medium | Annual | Policies, awareness training, physical security | | Low | Annual | Documentation, asset inventory |
Opening Meeting
Evidence Collection
Control Verification
Closing Meeting
Validation: All controls in scope assessed with documented evidence
For detailed technical verification procedures by Annex A control, see security-control-testing.md.
| Severity | Definition | Response Time | | ------------------- | ----------------------------------------- | ---------------- | | Major Nonconformity | Control failure creating significant risk | 30 days | | Minor Nonconformity | Isolated deviation with limited impact | 90 days | | Observation | Improvement opportunity | Next audit cycle |
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]
Ensure documentation is complete:
Verify operational readiness:
| Period | Focus | | ---------- | ---------------------------------------------- | | Year 1, Q2 | High-risk controls, Stage 2 findings follow-up | | Year 1, Q4 | Continual improvement, control sample | | Year 2, Q2 | Full surveillance | | Year 2, Q4 | Re-certification preparation |
Validation: No major nonconformities at surveillance audits.
| Script | Purpose | Usage |
| ------------------------- | ------------------------------- | ---------------------------------------------------------------------- |
| isms_audit_scheduler.py | Generate risk-based audit plans | python scripts/isms_audit_scheduler.py --year 2025 --format markdown |
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
| File | Content | | ------------------------------------------------------------------------- | --------------------------------------------------------------- | | iso27001-audit-methodology.md | Audit program structure, pre-audit phase, certification support | | security-control-testing.md | Technical verification procedures for ISO 27002 controls | | cloud-security-audit.md | Cloud provider assessment, configuration security, IAM review |
| KPI | Target | Measurement | | --------------------- | ------------------- | --------------------------------- | | Audit plan completion | 100% | Audits completed vs. planned | | Finding closure rate | >90% within SLA | Closed on time vs. total | | Major nonconformities | 0 at certification | Count per certification cycle | | Audit effectiveness | Incidents prevented | Security improvements implemented |
Creator: Ra Qm Team License: MIT Source Repo:
neekware/ehaye-skillsSource Bucket:ra-qm-teamOriginal Path:ra-qm-team/isms-audit-expert
tools
# ehAye Multimedia Use this skill for **video, audio, images, media conversion, previews, transcription, thumbnails, frame extraction, Spotter visual search, or FFmpeg-backed processing**. Core rule: use ehAye native media tools first. Do not reach first for shell `ffmpeg`, `ffprobe`, Python, or `mediainfo` when a native media tool can do the job. Native tools use bundled engines, show proper tool UI, respect cancellation/timeouts, integrate with Preview/Spotter, and avoid cross-platform shell
development
Test-driven development skill for writing unit tests, generating test fixtures and mocks, analyzing coverage gaps, and guiding red-green-refactor workflows across Jest, Pytest, JUnit, Vitest, and Mocha. Use when the user asks to write tests, improve test coverage, practice TDD, generate mocks or stubs, or mentions testing frameworks like Jest, pytest, or JUnit. Handles test generation from source code, coverage report parsing (LCOV/JSON/XML), quality scoring, and framework conversion for TypeScript, JavaScript, Python, and Java projects.
tools
Help a user set up Telegram for ehAye Dojo. Default to Personal private bots (recommended). Group setup is advanced for teams/observers/demos.
development
# Writing Skills ## Overview **Writing skills IS Test-Driven Development applied to process documentation.** **Personal skills live in agent-specific directories (`~/.claude/skills` for Claude Code, `~/.agents/skills/` for Codex)** You write test cases (pressure scenarios with subagents), watch them fail (baseline behavior), write the skill (documentation), watch tests pass (agents comply), and refactor (close loopholes). **Core principle:** If you didn't watch an agent fail without the ski