artifacts/bundle/skills/ra-qm-team/isms-audit-expert/SKILL.md
# ISMS Audit Expert Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support. ## Table of Contents - [Audit Program Management](#audit-program-management) - [Audit Execution](#audit-execution) - [Control Assessment](#control-assessment) - [Finding Management](#finding-management) - [Certification Support](#certification-support) - [Tools](#tools) - [References](#references) --- ## Audit Program Management ###
npx skillsauth add neekware/ehayeskills artifacts/bundle/skills/ra-qm-team/isms-audit-expertInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
| Risk Level | Audit Frequency | Examples | | ---------- | --------------- | ---------------------------------------------------- | | Critical | Quarterly | Privileged access, vulnerability management, logging | | High | Semi-annual | Access control, incident response, encryption | | Medium | Annual | Policies, awareness training, physical security | | Low | Annual | Documentation, asset inventory |
Opening Meeting
Evidence Collection
Control Verification
Closing Meeting
Validation: All controls in scope assessed with documented evidence
For detailed technical verification procedures by Annex A control, see security-control-testing.md.
| Severity | Definition | Response Time | | ------------------- | ----------------------------------------- | ---------------- | | Major Nonconformity | Control failure creating significant risk | 30 days | | Minor Nonconformity | Isolated deviation with limited impact | 90 days | | Observation | Improvement opportunity | Next audit cycle |
Finding ID: ISMS-[YEAR]-[NUMBER]
Control Reference: A.X.X - [Control Name]
Severity: [Major/Minor/Observation]
Evidence:
- [Specific evidence observed]
- [Records reviewed]
- [Interview statements]
Risk Impact:
- [Potential consequences if not addressed]
Root Cause:
- [Why the nonconformity occurred]
Recommendation:
- [Specific corrective action steps]
Ensure documentation is complete:
Verify operational readiness:
| Period | Focus | | ---------- | ---------------------------------------------- | | Year 1, Q2 | High-risk controls, Stage 2 findings follow-up | | Year 1, Q4 | Continual improvement, control sample | | Year 2, Q2 | Full surveillance | | Year 2, Q4 | Re-certification preparation |
Validation: No major nonconformities at surveillance audits.
| Script | Purpose | Usage |
| ------------------------- | ------------------------------- | ---------------------------------------------------------------------- |
| isms_audit_scheduler.py | Generate risk-based audit plans | python scripts/isms_audit_scheduler.py --year 2025 --format markdown |
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown
| File | Content | | ------------------------------------------------------------------------- | --------------------------------------------------------------- | | iso27001-audit-methodology.md | Audit program structure, pre-audit phase, certification support | | security-control-testing.md | Technical verification procedures for ISO 27002 controls | | cloud-security-audit.md | Cloud provider assessment, configuration security, IAM review |
| KPI | Target | Measurement | | --------------------- | ------------------- | --------------------------------- | | Audit plan completion | 100% | Audits completed vs. planned | | Finding closure rate | >90% within SLA | Closed on time vs. total | | Major nonconformities | 0 at certification | Count per certification cycle | | Audit effectiveness | Incidents prevented | Security improvements implemented |
Creator: Ra Qm Team License: MIT Source Repo:
neekware/ehaye-skillsSource Bucket:ra-qm-teamOriginal Path:ra-qm-team/isms-audit-expert
testing
/em -stress-test — Business Assumption Stress Testing
research
/em -postmortem — Honest Analysis of What Went Wrong
development
/em -hard-call — Framework for Decisions With No Good Options
research
/em -challenge — Pre-Mortem Plan Analysis