New to Claude Skills? Learn how to install them →

alirezarezvani on GitHub

ISO 27001 Audit Prep

Free

Prepare for ISO 27001 audits with targeted interrogation questions.

Get this skill

Free · Opens the source repo

What ISO 27001 Audit Prep does

The ISO 27001 Audit Prep skill is designed to assist organizations in preparing for ISO 27001 audits by employing a structured approach to readiness. This skill utilizes a command that prompts users to answer six critical questions that are essential for evaluating the effectiveness of their Information Security Management System (ISMS). By focusing on areas such as audit scope, risk management, access controls, supplier management, incident response, and management reviews, this skill ensures that users are thoroughly prepared for internal audits and certification processes.

When invoked, the skill requires a specific scope to assess, guiding users through a series of interrogative checks that highlight potential gaps in compliance. The questions are designed to pressure-test the ISMS, ensuring that all necessary controls are in place and functioning as intended. This proactive approach not only aids in compliance but also helps organizations identify areas for improvement before facing an audit.

The skill is particularly useful for compliance officers, security managers, and any stakeholders involved in the ISO 27001 certification process. It is applicable before annual audits, during surveillance audits, and after significant changes to the ISMS. By regularly utilizing this skill, organizations can maintain a high level of readiness and confidence in their compliance posture.

In addition to the interrogation questions, the skill provides a structured output format that summarizes the findings and suggests actionable next steps. This ensures that users have a clear understanding of their audit readiness and can address any identified issues in a timely manner.

When to use it

Use this skill before internal audits, certification audits, or after significant changes to your ISMS to assess readiness.

When not to use it

This skill may not be suitable for organizations not pursuing ISO 27001 certification or those without an established ISMS.

What you can build with it

Pre-Audit Preparation

Use the skill to prepare for an upcoming internal audit by answering the six critical questions.

Post-Incident Review

Invoke the skill after a security incident to ensure your ISMS is still compliant and ready for audits.

Quarterly Compliance Checks

Regularly run the skill to maintain ongoing readiness and address any compliance gaps proactively.

How to install ISO 27001 Audit Prep

View source

1. Install with the skills CLI

npx skills add alirezarezvani/claude-skills/iso27001-audit-prep --agent claude-code

2. Or install it manually

Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.

Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs

Inside SKILL.md

Written by alirezarezvani

/cs:iso27001-audit-prep — ISO 27001 ISMS Audit Forcing Questions

Command: /cs:iso27001-audit-prep <scope>

The ISO 27001 ISMS auditor pressure-tests any ISMS work. Six sample-driven questions before any internal audit, stage 1 readiness, or surveillance audit.

When to Run

  • Before annual Clause 9.2 internal audit
  • Before stage 1 / stage 2 ISO 27001 certification audit
  • Before surveillance audit (year 2 / year 3)
  • After material change to ISMS scope (new business unit, new product line, new SaaS adoption)
  • Post-incident (breach triggers ad-hoc ISMS audit)
  • Quarterly during high-growth phase

The Six ISMS Questions

1. What's the audit scope, and is rolling 3-year coverage on track?

No 3-year coverage discipline, no defensible programme.

  • Every Clause 4-10 + every applicable Annex A control must be audited at least once per 3-year cycle
  • Run isms_audit_scheduler.py in ra-qm-team/skills/isms-audit-expert/
  • Confirm auditor independence — no self-audit on any sample

2. When was the risk register last refreshed, and are treatments linked to Annex A controls?

Stale risk register = certification finding.

  • Quarterly refresh expected; annual minimum
  • Every high/critical risk must link to ≥ 1 Annex A control treating it
  • Residual risk acceptance documented + signed
  • Review against iso27001_audit_playbook.md for stage 1 expectations

3. Show me the access review records — quarterly cadence, the last 4 quarters.

Most-cited finding area.

  • Annex A.5.15 + A.8.2 + A.8.3 access controls
  • Sample real records pulled from Okta / IAM, not curated audit-prep packs
  • For each terminated employee in last 90 days: deprovisioning evidence within 24-hour SLA
  • Privileged access reviewed at finer granularity

4. What's the supplier inventory + last review evidence?

Second-most-cited finding area.

  • Annex A.5.19-A.5.21 supplier management
  • Critical SaaS suppliers reviewed at least annually
  • DPAs signed for personal-data sub-processors (cross-check with cs-dpo-gdpr)
  • AI-specific contract clauses where third-party AI services in use (cross-check with cs-aims-iso42001)

5. Where's the incident response evidence + post-incident review?

A.5.24-27 + A.6.8 — high-stakes audit area.

  • Severity definitions documented + consistently applied
  • Last 5 incidents have post-incident review (PIR) within 30-day SLA
  • GDPR Article 33 / 34 notification timing aligned with A.5.24 (cross-check with cs-dpo-gdpr)
  • Blameless retro culture; not punitive

6. What's the management review cadence + inputs?

Clause 9.3 required inputs are prescriptive — easy to miss.

  • Required inputs: audit results, risks, performance, nonconformities, opportunities
  • Schedule: annual minimum; quarterly preferred for mature programs
  • Outputs documented + tracked to closure
  • Integrated review across frameworks (per multi_framework_audit_playbook.md) preferred to separate reviews

Workflow

# 1. Audit programme planning
python ra-qm-team/skills/isms-audit-expert/scripts/isms_audit_scheduler.py audit_scope.json

# 2. Mock audit for readiness check
python ../../skills/compliance-os/scripts/audit_simulator.py iso27001_scope.json

# 3. Cross-framework reuse (SOC 2 = 75% overlap; ISO 42001 = 60% reuse)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

Output Format

# ISO 27001 Audit Prep: <scope>
**Date:** YYYY-MM-DD

## The Decision Being Made
[programme-plan | finding-severity | cert-readiness | incident-followup]

## Audit Programme Status
- Clauses scheduled this year: <list>
- Annex A controls scheduled: <count>
- Rolling 3-year coverage: clean | gaps in <list>
- Auditor independence: clean | issues in <list>

## Risk Register Health
- Last refresh: YYYY-MM-DD
- High/critical risks without Annex A control link: N
- Residual risk acceptance documentation: complete | gaps

## High-Stakes Controls Status
- A.5.15 + A.8.2 + A.8.3 access control: pass/fail with sample
- A.5.19-A.5.21 supplier mgmt: pass/fail with sample
- A.5.24-27 + A.6.8 incident response: pass/fail with sample
- A.8.15-16 logging: pass/fail with sample

## Management Review Status
- Last review date: YYYY-MM-DD
- Required Article 9.3 inputs present: yes/no
- Open action items past due: N

## Cross-Framework Impact
- SOC 2 controls affected: <list>
- ISO 42001 controls affected (if applicable): <list>
- GDPR Article 32 controls affected: <list>

## Verdict
🟢 READY | 🟡 CLOSE-CRITICALS-FIRST | 🔴 NOT-READY

## Top 3 Actions
[3 concrete next steps with owner + corrective-action timeline]

Routing

  • /cs:compliance-readiness — for multi-framework view
  • /cs:soc2-audit-prep — for SOC 2 cross-walk pair (75% overlap)
  • /cs:aims-audit — for ISO 42001 AIMS cross-walk
  • /cs:gdpr-audit-prep — for Article 32 organizational measures overlap
  • /cs:ciso-review — for executive cybersecurity strategy
  • /cs:decide — to log the verdict

Related


Version: 1.0.0

Frequently asked questions about ISO 27001 Audit Prep

Similar skills