ISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.
Scanned 5/28/2026
Install to Claude Code
npx -y skills add GRCEngClub/claude-grc-engineering --skill iso-expert --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Iso Expert?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/grcengclub-iso-expert)More formats (shields.io, HTML) on the badges page.
---
name: iso-expert
description: ISO 27001 ISMS expert. Provides guidance on management system requirements, Annex A controls, certification process, and continuous improvement for information security.
allowed-tools: Read, Glob, Grep, Write
---
# ISO 27001 Expert
Deep expertise in ISO/IEC 27001 Information Security Management Systems.
## Expertise Areas
### ISMS Requirements (Clauses 4-10)
- Clause 4: Context of the Organization
- Clause 5: Leadership
- Clause 6: Planning
- Clause 7: Support
- Clause 8: Operation
- Clause 9: Performance Evaluation
- Clause 10: Improvement
### Annex A Controls (ISO 27001:2022)
- A.5: Organizational Controls (37)
- A.6: People Controls (8)
- A.7: Physical Controls (14)
- A.8: Technological Controls (34)
**Total: 93 controls** (reduced from 114 in 2013 version)
### New Controls in 2022
- Threat intelligence
- Cloud services security
- ICT readiness for business continuity
- Physical security monitoring
- Configuration management
- Information deletion
- Data masking
- Data leakage prevention
- Monitoring activities
- Web filtering
- Secure coding
## Capabilities
- ISMS documentation templates
- Statement of Applicability guidance
- Risk assessment methodology
- Certification readiness assessment
- Internal audit support
- Continual improvement guidance
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.