Agent skill

Iso27001 Audit Prep

by alirezarezvani in alirezarezvani/claude-skills

/cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation.

MITAuto-check passedLegal & Compliance

Install Iso27001 Audit Prep

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill iso27001-audit-prep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills iso27001-audit-prep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/compliance-os/skills/iso27001-audit-prep .claude/skills/iso27001-audit-prep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iso27001-audit-prep
GitHub stars
28k
Token cost
~1.4k tokens
SKILL.md length
423 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation.

  • Works in 6 steps: What's the audit scope, and is rolling… → When was the risk register last… → Show me the access review records —… → …
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers When to Run, The Six ISMS Questions, Workflow and Output Format, plus 2 more sections
  • Calls python

What it does

Iso27001 Audit Prep is an agent skill from alirezarezvani/claude-skills. /cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage 1 certification readiness.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance and Audit readiness. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Audit readiness

Example prompts

  • “/iso27001-audit-prep”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. What's the audit scope, and is rolling 3-year coverage on track?
  2. When was the risk register last refreshed, and are treatments linked to Annex A controls?
  3. Show me the access review records — quarterly cadence, the last 4 quarters.
  4. What's the supplier inventory + last review evidence?
  5. Where's the incident response evidence + post-incident review?
  6. What's the management review cadence + inputs?

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iso27001 Audit Prep loads about 1.4k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 423 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 423 words, ~1,412 tokens.

Download SKILL.mdSave it as .claude/skills/iso27001-audit-prep/SKILL.md (or your agent's skills folder).
name
iso27001-audit-prep
description
/cs:iso27001-audit-prep <scope> — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Use before annual Clause 9.2 internal audit, surveillance audit prep, or stage 1 certification readiness.

/cs:iso27001-audit-prep — ISO 27001 ISMS Audit Forcing Questions

Command: /cs:iso27001-audit-prep <scope>

The ISO 27001 ISMS auditor pressure-tests any ISMS work. Six sample-driven questions before any internal audit, stage 1 readiness, or surveillance audit.

When to Run

  • Before annual Clause 9.2 internal audit
  • Before stage 1 / stage 2 ISO 27001 certification audit
  • Before surveillance audit (year 2 / year 3)
  • After material change to ISMS scope (new business unit, new product line, new SaaS adoption)
  • Post-incident (breach triggers ad-hoc ISMS audit)
  • Quarterly during high-growth phase

The Six ISMS Questions

1. What's the audit scope, and is rolling 3-year coverage on track?

No 3-year coverage discipline, no defensible programme.

  • Every Clause 4-10 + every applicable Annex A control must be audited at least once per 3-year cycle
  • Run isms_audit_scheduler.py in ra-qm-team/skills/isms-audit-expert/
  • Confirm auditor independence — no self-audit on any sample
2. When was the risk register last refreshed, and are treatments linked to Annex A controls?

Stale risk register = certification finding.

  • Quarterly refresh expected; annual minimum
  • Every high/critical risk must link to ≥ 1 Annex A control treating it
  • Residual risk acceptance documented + signed
  • Review against iso27001_audit_playbook.md for stage 1 expectations
3. Show me the access review records — quarterly cadence, the last 4 quarters.

Most-cited finding area.

  • Annex A.5.15 + A.8.2 + A.8.3 access controls
  • Sample real records pulled from Okta / IAM, not curated audit-prep packs
  • For each terminated employee in last 90 days: deprovisioning evidence within 24-hour SLA
  • Privileged access reviewed at finer granularity
Show full SKILL.md (187 more words)Show less
4. What's the supplier inventory + last review evidence?

Second-most-cited finding area.

  • Annex A.5.19-A.5.21 supplier management
  • Critical SaaS suppliers reviewed at least annually
  • DPAs signed for personal-data sub-processors (cross-check with cs-dpo-gdpr)
  • AI-specific contract clauses where third-party AI services in use (cross-check with cs-aims-iso42001)
5. Where's the incident response evidence + post-incident review?

A.5.24-27 + A.6.8 — high-stakes audit area.

  • Severity definitions documented + consistently applied
  • Last 5 incidents have post-incident review (PIR) within 30-day SLA
  • GDPR Article 33 / 34 notification timing aligned with A.5.24 (cross-check with cs-dpo-gdpr)
  • Blameless retro culture; not punitive
6. What's the management review cadence + inputs?

Clause 9.3 required inputs are prescriptive — easy to miss.

  • Required inputs: audit results, risks, performance, nonconformities, opportunities
  • Schedule: annual minimum; quarterly preferred for mature programs
  • Outputs documented + tracked to closure
  • Integrated review across frameworks (per multi_framework_audit_playbook.md) preferred to separate reviews

Workflow

bash
# 1. Audit programme planning
python ra-qm-team/skills/isms-audit-expert/scripts/isms_audit_scheduler.py audit_scope.json

# 2. Mock audit for readiness check
python ../../skills/compliance-os/scripts/audit_simulator.py iso27001_scope.json

# 3. Cross-framework reuse (SOC 2 = 75% overlap; ISO 42001 = 60% reuse)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

Output Format

markdown
# ISO 27001 Audit Prep: <scope>
**Date:** YYYY-MM-DD

## The Decision Being Made
[programme-plan | finding-severity | cert-readiness | incident-followup]

## Audit Programme Status
- Clauses scheduled this year: <list>
- Annex A controls scheduled: <count>
- Rolling 3-year coverage: clean | gaps in <list>
- Auditor independence: clean | issues in <list>

## Risk Register Health
- Last refresh: YYYY-MM-DD
- High/critical risks without Annex A control link: N
- Residual risk acceptance documentation: complete | gaps

## High-Stakes Controls Status
- A.5.15 + A.8.2 + A.8.3 access control: pass/fail with sample
- A.5.19-A.5.21 supplier mgmt: pass/fail with sample
- A.5.24-27 + A.6.8 incident response: pass/fail with sample
- A.8.15-16 logging: pass/fail with sample

## Management Review Status
- Last review date: YYYY-MM-DD
- Required Article 9.3 inputs present: yes/no
- Open action items past due: N

## Cross-Framework Impact
- SOC 2 controls affected: <list>
- ISO 42001 controls affected (if applicable): <list>
- GDPR Article 32 controls affected: <list>

## Verdict
🟢 READY | 🟡 CLOSE-CRITICALS-FIRST | 🔴 NOT-READY

## Top 3 Actions
[3 concrete next steps with owner + corrective-action timeline]

Routing

  • /cs:compliance-readiness — for multi-framework view
  • /cs:soc2-audit-prep — for SOC 2 cross-walk pair (75% overlap)
  • /cs:aims-audit — for ISO 42001 AIMS cross-walk
  • /cs:gdpr-audit-prep — for Article 32 organizational measures overlap
  • /cs:ciso-review — for executive cybersecurity strategy
  • /cs:decide — to log the verdict

Version: 1.0.0

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in compliance-os/skills/iso27001-audit-prep of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Iso27001 Audit Prep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iso27001 Audit Prep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iso27001 Audit Prep this skillalirezarezvani/claude-skills28k—~1.4kAutomated safety check: PassMIT
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Implementing Complianceancoleman/ai-design-components525—~4kAutomated safety check: PassMIT
Assisting With Soc2 Audit Preparationjeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: PassMIT
Isms Audit Expertborghei/Claude-Skills891—~4.9kAutomated safety check: PassMIT

Similar skills

  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 6 days ago
    Legal & ComplianceAuto-check passed
  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    525 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Assisting With Soc2 Audit Preparation

    jeremylongshore/tons-of-skills-marketplace

    Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

    2.8k GitHub stars~1.6k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed
  • Isms Audit Expert

    borghei/Claude-Skills

    ISMS auditing for ISO 27001 compliance, control assessment, and certification support.

    891 GitHub stars~4.9k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Soc2 Audit Prep

    borghei/Claude-Skills

    SOC 2 audit-prep playbook: the 4/8/12-week sprint to audit-ready for a Type I or Type II observation.

    891 GitHub stars~2.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about Iso27001 Audit Prep

What does Iso27001 Audit Prep do?

/cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation. Iso27001 Audit Prep is an agent skill from alirezarezvani/claude-skills. /cs:iso27001-audit-prep <scope — ISO 27001 ISMS audit readiness 6-question forcing interrogation.

When should I use Iso27001 Audit Prep?

Iso27001 Audit Prep fits situations like: tasks that involve SOC 2 and security compliance; tasks that involve Audit readiness.

How do I install Iso27001 Audit Prep in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill iso27001-audit-prep -a claude-code`. Or copy the skill folder (compliance-os/skills/iso27001-audit-prep in alirezarezvani/claude-skills) into .claude/skills/iso27001-audit-prep in your project. Claude Code loads it when a task matches its description.

How do I install Iso27001 Audit Prep in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill iso27001-audit-prep -a codex`. Or copy the skill folder (compliance-os/skills/iso27001-audit-prep in alirezarezvani/claude-skills) into .agents/skills/iso27001-audit-prep in your project. Codex loads it when a task matches its description.

Can I use Iso27001 Audit Prep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill iso27001-audit-prep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iso27001-audit-prep, .gemini/skills/iso27001-audit-prep, .github/skills/iso27001-audit-prep and .opencode/skills/iso27001-audit-prep in your project.

What does Iso27001 Audit Prep need to run?

Going by SKILL.md and its folder, Iso27001 Audit Prep needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Iso27001 Audit Prep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Iso27001 Audit Prep safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iso27001 Audit Prep use?

Iso27001 Audit Prep is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iso27001 Audit Prep use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iso27001 Audit Prep?

Skills that share tags, products or a category with Iso27001 Audit Prep: Trust Center Builder (GRCEngClub/claude-grc-engineering, 419 stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Compliance (ancoleman/ai-design-components, 525 stars) and Assisting With Soc2 Audit Preparation (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iso27001 Audit Prep?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.