Agent skill

Isms Audit Expert

by borghei in borghei/Claude-Skills

ISMS auditing for ISO 27001 compliance, control assessment, and certification support.

MITAuto-check passedLegal & Compliance

Install Isms Audit Expert

skills CLI
$ npx skills add borghei/Claude-Skills --skill isms-audit-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills isms-audit-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/isms-audit-expert .claude/skills/isms-audit-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
isms-audit-expert
GitHub stars
886
Token cost
~4.9k tokens
SKILL.md length
1,915 words
Files
5 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

ISMS auditing for ISO 27001 compliance, control assessment, and certification support.

  • Works in 2 steps: Audit Preparation Checklist → Audit Preparation Checklist
  • ISMS audit programs
  • SKILL.md covers Clarify First, Audit Program Management, Audit Execution and Control Assessment, plus 10 more sections
  • Runs Python scripts from its folder; calls python

What it does

Isms Audit Expert is an agent skill from borghei/Claude-Skills. ISMS auditing for ISO 27001 compliance, control assessment, and certification support. Use for ISMS audit programs, internal/external ISO 27001 audits, ISO 27002 Annex A control testing, and Stage 1/Stage 2 certification audits.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/cloud-security-audit.md`, `references/iso27001-audit-methodology.md` and `references/security-control-testing.md`).

It sits in Legal & Compliance, covering Audit readiness and SOC 2 and security compliance. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • ISMS audit programs
  • Internal/external ISO 27001 audits
  • ISO 27002 Annex A control testing
  • Stage 1/Stage 2 certification audits

Example prompts

  • “/isms-audit-expert”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Audit Preparation Checklist
  2. Audit Preparation Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Isms Audit Expert loads about 4.9k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 62 tokens; SKILL.md has 1,915 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 1,915 words, ~4,907 tokens.

Download SKILL.mdSave it as .claude/skills/isms-audit-expert/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
isms-audit-expert
description
ISMS auditing for ISO 27001 compliance, control assessment, and certification support. Use for ISMS audit programs, internal/external ISO 27001 audits, ISO 27002 Annex A control testing, and Stage 1/Stage 2 certification audits.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
security-audit
metadata.updated
2026-03-31
metadata.tags
iso-27001, isms-audit, security-testing, certification, controls

ISMS Audit Expert

Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.


Clarify First

Before planning or executing the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Audit type — internal annual, Stage 1, Stage 2, surveillance, or recertification (sets the scope and checklist depth)
  • Controls in scope — which Annex A controls / SoA coverage for this engagement (drives the schedule and testing)
  • Risk ratings and prior findings — per-control risk and outstanding nonconformities (picks audit frequency and sample size)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the audit plan.

Audit Program Management

Risk-Based Audit Schedule
Risk LevelAudit FrequencyExamples
CriticalQuarterlyPrivileged access, vulnerability management, logging
HighSemi-annualAccess control, incident response, encryption
MediumAnnualPolicies, awareness training, physical security
LowAnnualDocumentation, asset inventory
Workflow: Annual Audit Planning
  1. Review prior audit results -- analyze previous findings, open items, and risk assessment outputs from the most recent cycle.
  2. Identify high-risk controls -- flag controls involved in recent security incidents or with outstanding nonconformities.
  3. Determine audit scope -- define ISMS boundaries, confirm Statement of Applicability (SoA) coverage for the certification cycle.
  4. Assign auditors -- ensure independence from audited areas; verify auditor competency (ISO 27001 Lead Auditor certification preferred).
  5. Create audit schedule -- allocate resources, assign dates, and distribute across the year by risk priority.
  6. Obtain management approval for the finalized audit plan.
  7. Validation checkpoint: Audit plan covers all 93 Annex A controls within the certification cycle; schedule approved by management; auditor independence confirmed.
Example: Annual Audit Plan Output
ISMS AUDIT PLAN 2026

Prepared by: Information Security Manager
Approved by: CISO
Date: 2026-01-15

Q1 2026 (January-March)
  Scope: Privileged access (A.8.2, A.8.18), Logging (A.8.15, A.8.16)
  Auditor: External consultant (independence required)
  Risk level: Critical

Q2 2026 (April-June)
  Scope: Access control (A.8.3-A.8.5), Incident response (A.5.24-A.5.28)
  Auditor: Internal audit team
  Risk level: High

Q3 2026 (July-September)
  Scope: Physical security (A.7.1-A.7.14), HR security (A.6.1-A.6.8)
  Auditor: Internal audit team
  Risk level: Medium

Q4 2026 (October-December)
  Scope: Policies (A.5.1-A.5.8), Asset management (A.5.9-A.5.14)
  Auditor: Internal audit team
  Risk level: Medium-Low

Coverage: 93/93 Annex A controls scheduled across 4 quarters

Audit Execution

Workflow: Pre-Audit Preparation
  1. Review ISMS documentation -- policies, Statement of Applicability, risk assessment, and risk treatment plan.
  2. Analyze previous audit reports -- note open findings and areas requiring follow-up.
  3. Prepare audit plan -- define interview schedule, control sample, and evidence requirements.
  4. Notify auditees -- communicate scope, timing, and documentation needed at least 2 weeks in advance.
  5. Prepare control-specific checklists for all controls in scope.
  6. Validation checkpoint: All documentation received and reviewed before the opening meeting.
Workflow: Audit Conduct
  1. Opening Meeting -- confirm scope, introduce audit team, agree on communication channels and logistics.
  2. Evidence Collection -- interview control owners, review documentation and records, observe processes in operation, inspect technical configurations.
  3. Control Verification -- test control design (does it address the risk?), test control operation (is it working as intended?), sample transactions and records, document all evidence.
  4. Closing Meeting -- present preliminary findings, clarify factual inaccuracies, agree on finding classification, confirm corrective action timelines.
  5. Validation checkpoint: All controls in scope assessed with documented evidence; findings classified and communicated.
Evidence Collection Methods
MethodUse CaseExample
InquiryProcess understandingInterview Security Manager about incident response
ObservationOperational verificationWatch visitor sign-in process at reception
InspectionDocumentation reviewCheck access approval records for last quarter
Re-performanceControl testingAttempt login with weak password to verify policy enforcement

Control Assessment

ISO 27002 Control Categories

Organizational Controls (A.5): Information security policies, roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, information security in projects.

People Controls (A.6): Screening and background checks, employment terms, security awareness and training, disciplinary process, remote working security.

Physical Controls (A.7): Physical security perimeters, entry controls, securing offices and facilities, physical security monitoring, equipment protection.

Technological Controls (A.8): User endpoint devices, privileged access rights, access restriction, secure authentication, malware protection, vulnerability management, backup and recovery, logging and monitoring, network security, cryptography.

Workflow: Control Testing
  1. Identify control objective from the relevant ISO 27002 clause.
  2. Determine testing method -- inquiry, observation, inspection, or re-performance based on control type.
  3. Define sample size -- base on population size and risk level (e.g., 25 samples for quarterly access reviews, 5 for annual policy reviews).
  4. Execute test and document results with specific evidence references.
  5. Evaluate control effectiveness -- effective, partially effective, or ineffective.
  6. Validation checkpoint: Evidence supports conclusion; finding documented if control is not fully effective.
Example: Control Test Working Paper
CONTROL TEST WORKING PAPER

Control: A.8.2 - Privileged access rights
Objective: Privileged access is restricted and managed
Test date: 2026-03-10
Auditor: J. Smith

Test procedure:
  1. Obtained list of privileged accounts from IAM system (42 accounts)
  2. Selected sample of 10 accounts (25% sample rate)
  3. For each account, verified:
     - Documented business justification exists
     - Manager approval on file
     - Quarterly access review completed
     - No dormant accounts (last login within 90 days)

Results:
  - 8/10 accounts: All criteria met (PASS)
  - 1/10: Missing quarterly review for Q4 2025 (MINOR NC)
  - 1/10: No documented business justification (MINOR NC)

Conclusion: Control partially effective - minor nonconformity raised
Finding reference: ISMS-2026-007

Finding Management

Finding Classification
SeverityDefinitionResponse Time
Major NonconformityControl failure creating significant risk30 days
Minor NonconformityIsolated deviation with limited impact90 days
ObservationImprovement opportunityNext audit cycle
Finding Documentation Template
Finding ID: ISMS-2026-007
Control Reference: A.8.2 - Privileged access rights
Severity: Minor Nonconformity

Evidence:
- 1 of 10 sampled privileged accounts missing Q4 2025 review
- 1 of 10 sampled accounts lacks documented business justification
- Screenshots of IAM records and review log exported 2026-03-10

Risk Impact:
- Unreviewed privileged access increases insider threat exposure
- Non-justified accounts may represent unnecessary attack surface

Root Cause:
- Access review process relies on manual tracking; no automated reminder

Recommendation:
- Implement automated quarterly review reminders via IAM platform
- Require business justification field as mandatory in provisioning workflow
- Backfill missing reviews within 14 days
Workflow: Corrective Action
  1. Auditee acknowledges finding and severity classification.
  2. Root cause analysis completed within 10 business days.
  3. Corrective action plan submitted with target dates and responsible owners.
  4. Actions implemented by responsible parties per the plan.
  5. Auditor verifies effectiveness -- re-tests control with fresh evidence.
  6. Finding closed with documented evidence of resolution.
  7. Validation checkpoint: Root cause addressed; recurrence prevented; evidence of effective correction on file.

Certification Support

Stage 1 Audit Preparation Checklist
  • ISMS scope statement finalized
  • Information security policy (management signed)
  • Statement of Applicability (SoA) complete
  • Risk assessment methodology and results documented
  • Risk treatment plan current
  • Internal audit results available (past 12 months)
  • Management review minutes on file
Stage 2 Audit Preparation Checklist
  • All Stage 1 findings addressed and closed
  • ISMS operational for minimum 3 months
  • Evidence of control implementation across all SoA controls
  • Security awareness training records for all personnel
  • Incident response evidence (if incidents occurred)
  • Access review documentation for the audit period
Surveillance Audit Cycle
PeriodFocus
Year 1, Q2High-risk controls, Stage 2 findings follow-up
Year 1, Q4Continual improvement, control sample
Year 2, Q2Full surveillance
Year 2, Q4Re-certification preparation

Tools

ScriptPurposeUsage
isms_audit_scheduler.pyGenerate risk-based audit planspython scripts/isms_audit_scheduler.py --year 2026 --format markdown
bash
# Generate annual audit plan
python scripts/isms_audit_scheduler.py --year 2026 --output audit_plan.json

# With custom control risk ratings
python scripts/isms_audit_scheduler.py --controls controls.csv --format markdown

# Generate plan for specific quarters only
python scripts/isms_audit_scheduler.py --year 2026 --quarters Q1 Q2 --format json

References

FileContent
iso27001-audit-methodology.mdAudit program structure, pre-audit phase, certification support
security-control-testing.mdTechnical verification procedures for ISO 27002 controls
cloud-security-audit.mdCloud provider assessment, configuration security, IAM review

Audit Performance Metrics

KPITargetMeasurement
Audit plan completion100%Audits completed vs. planned
Finding closure rate>90% within SLAClosed on time vs. total
Major nonconformities0 at certificationCount per certification cycle
Audit effectivenessIncidents preventedSecurity improvements implemented

Compliance Framework Integration

FrameworkISMS Audit Relevance
GDPRA.5.34 Privacy, A.8.10 Information deletion
HIPAAAccess controls, audit logging, encryption
PCI DSSNetwork security, access control, monitoring
SOC 2Trust Services Criteria mapped to ISO 27002

Show full SKILL.md (897 more words)Show less

Troubleshooting

ProblemPossible CauseResolution
Audit plan does not cover all 93 Annex A controls within the certification cycleControls not inventoried against the 2022 four-theme structure or risk-based scheduling gapsUse isms_audit_scheduler.py with a complete controls CSV covering all 93 controls; ensure the 3-year cycle allocates quarterly audits for critical controls and annual coverage for all others
Major nonconformity found during certification auditSystemic control failure or complete absence of a required ISMS elementConduct immediate root cause analysis; develop corrective action plan with 30-day target; re-test the control with fresh evidence; schedule verification audit with certification body
Auditor independence challenged by certification bodyInternal auditors assigned to areas they manage or operateEstablish clear auditor independence policy; never assign auditors to areas they are responsible for; consider external consultants for high-risk control areas; document independence verification for each audit
Evidence collection incomplete for technological controls (A.8)Technical configurations not captured, logs not retained, or screenshots not timestampedPrepare control-specific evidence checklists before audit; request system administrators to export configurations; ensure log retention covers the audit period; timestamp all evidence artifacts
Finding closure rate below 90% targetCorrective actions not prioritized, unclear ownership, or insufficient follow-upAssign specific owners with due dates for every finding; implement automated tracking with escalation at 50% and 75% of SLA; conduct monthly corrective action reviews
Surveillance audit identifies regression in previously passed controlsControls degraded after initial certification due to staff changes, system updates, or process driftImplement continuous compliance monitoring (not just annual checks); schedule monthly control spot-checks for high-risk areas; include control effectiveness in management review
Sample-based testing misses systemic issuesSample size too small or selection biased toward known-good recordsCalculate sample size based on population and risk level (minimum 25 for quarterly reviews); use random selection methods; increase sample for areas with prior findings

Success Criteria

  • Audit plan completion rate of 100% -- all scheduled audits executed within the planned quarter, with no deferrals or cancellations without management approval
  • Zero major nonconformities at certification/surveillance audits -- all systemic control failures identified and corrected during internal audits before external assessment
  • Finding closure rate above 90% within SLA -- major nonconformities closed within 30 days, minor within 90 days, observations addressed by next audit cycle
  • All 93 Annex A controls audited within the 3-year certification cycle -- with critical controls (A.8.2, A.8.5, A.8.8, A.8.15) audited quarterly and high-risk controls semi-annually
  • Audit evidence documented with specific references -- every finding includes control reference, evidence type (inquiry/observation/inspection/re-performance), sample details, and conclusion
  • Auditor competency verified -- all assigned auditors have ISO 27001 Lead Auditor certification or equivalent, with independence confirmed for each audit engagement

Scope & Limitations

In Scope:

  • Risk-based annual audit planning and scheduling across all 93 ISO 27001:2022 Annex A controls
  • Audit execution workflows including pre-audit preparation, evidence collection, control testing, and closing meetings
  • Finding management with severity classification (Major NC, Minor NC, Observation) and corrective action tracking
  • Certification support for Stage 1 (documentation review) and Stage 2 (implementation effectiveness) audits
  • Surveillance audit preparation and recertification planning
  • Control-specific testing procedures for organizational, people, physical, and technological control themes
  • Audit performance metrics and KPI tracking

Out of Scope:

  • Actual certification body selection, engagement, or fee negotiation
  • Technical penetration testing or vulnerability scanning -- use infrastructure-compliance-auditor for technical checks
  • ISO 27001 ISMS implementation -- use information-security-manager-iso27001 for implementation guidance
  • SOC 2 or other framework-specific audit execution beyond ISO 27001 cross-reference
  • Legal or contractual advice on audit findings or regulatory reporting obligations

Important Notes:

  • ISO 27001:2013 certifications expired after October 2025; all audits must now conform to the 2022 edition with 93 controls across 4 themes
  • 81% of organizations are pursuing ISO 27001 certification as of 2025 (up from 67% in 2024), reflecting heightened market demand for certified security programs
  • Best practice is to embed ISMS audit findings into continuous improvement rather than treating audits as periodic compliance events

Integration Points

SkillIntegrationWhen to Use
information-security-manager-iso27001ISMS implementation provides the controls and documentation that audits assessWhen audit findings require control improvements or ISMS enhancements
infrastructure-compliance-auditorTechnical infrastructure checks provide audit evidence for Annex A technological controlsWhen audit requires evidence of A.8 technological control implementation
soc2-compliance-expertSOC 2 audit evidence and Trust Services Criteria overlap with ISO 27001 controlsWhen organization maintains both ISO 27001 and SOC 2 compliance programs
capa-officerAudit findings requiring formal corrective action feed into CAPA processWhen major nonconformities require structured root cause analysis and corrective action

Tool Reference

isms_audit_scheduler.py

Generates risk-based annual audit plans with quarterly scheduling based on control risk ratings.

FlagRequiredDescription
--year <year>NoTarget year for audit plan (default: current year)
--controls <file>NoCSV file with custom control risk ratings (columns: control_id, name, risk); defaults to built-in risk ratings for 18 key controls
--quarters <list>NoGenerate plan for specific quarters only (e.g., --quarters Q1 Q2)
--format <fmt>NoOutput format: json (default) or markdown
--output <file>NoExport audit plan to specified file path

Audit Frequency by Risk Level:

  • critical: Quarterly (4x per year) -- e.g., A.8.2 Privileged access, A.8.5 Authentication, A.8.8 Vulnerabilities, A.8.15 Logging
  • high: Semi-annual (2x per year) -- e.g., A.5.15 Access control, A.5.24 Incident management, A.8.7 Malware protection
  • medium: Annual (1x per year) -- e.g., A.5.1 Policies, A.6.3 Awareness training, A.7.1 Physical perimeters
  • low: Annual (1x per year) -- e.g., Documentation, asset inventory

Output: Quarterly audit schedule with control assignments, auditor allocation guidance, risk-based prioritization, and coverage tracking ensuring all controls are scheduled within the certification cycle.

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in ra-qm-team/isms-audit-expert of borghei/Claude-Skills.

  • SKILL.md
  • references/cloud-security-audit.md
  • references/iso27001-audit-methodology.md
  • references/security-control-testing.md
  • scripts/isms_audit_scheduler.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Isms Audit Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Isms Audit Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Isms Audit Expert this skillborghei/Claude-Skills886—~4.9kAutomated safety check: PassMIT
Trust Center BuilderGRCEngClub/claude-grc-engineering420—~2.6kAutomated safety check: PassCustom licence
Isms Audit Expertalirezarezvani/claude-skills28k1 repos~1.9kAutomated safety check: PassMIT
Performing Soc2 Type2 Audit Preparationmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Compliance Osalirezarezvani/claude-skills28k—~3.3kAutomated safety check: PassMIT
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT

Similar skills

  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    420 GitHub stars~2.6k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Isms Audit Expert

    alirezarezvani/claude-skills

    Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support.

    28k GitHub starsUsed in 1 repo~1.9k tokens
    Legal & ComplianceAuto-check passed
  • Performing Soc2 Type2 Audit Preparation

    mukul975/Anthropic-Cybersecurity-Skills

    Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Assisting With Soc2 Audit Preparation

    jeremylongshore/tons-of-skills-marketplace

    Execute automate SOC 2 audit preparation including evidence gathering, control assessment, and compliance gap identification.

    2.8k GitHub stars~1.6k tokensUpdated today
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    886 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    886 GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    886 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    886 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    886 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    886 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed

Questions about Isms Audit Expert

What does Isms Audit Expert do?

ISMS auditing for ISO 27001 compliance, control assessment, and certification support. Isms Audit Expert is an agent skill from borghei/Claude-Skills. ISMS auditing for ISO 27001 compliance, control assessment, and certification support.

When should I use Isms Audit Expert?

Isms Audit Expert fits situations like: ISMS audit programs; internal/external ISO 27001 audits; ISO 27002 Annex A control testing; stage 1/Stage 2 certification audits.

How do I install Isms Audit Expert in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a claude-code`. Or copy the skill folder (ra-qm-team/isms-audit-expert in borghei/Claude-Skills) into .claude/skills/isms-audit-expert in your project. Claude Code loads it when a task matches its description.

How do I install Isms Audit Expert in Codex?

Run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a codex`. Or copy the skill folder (ra-qm-team/isms-audit-expert in borghei/Claude-Skills) into .agents/skills/isms-audit-expert in your project. Codex loads it when a task matches its description.

Can I use Isms Audit Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill isms-audit-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/isms-audit-expert, .gemini/skills/isms-audit-expert, .github/skills/isms-audit-expert and .opencode/skills/isms-audit-expert in your project.

What does Isms Audit Expert need to run?

Going by SKILL.md and its folder, Isms Audit Expert needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Isms Audit Expert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Isms Audit Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Isms Audit Expert use?

Isms Audit Expert is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Isms Audit Expert use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Isms Audit Expert?

Skills that share tags, products or a category with Isms Audit Expert: Trust Center Builder (GRCEngClub/claude-grc-engineering, 420 stars), Isms Audit Expert (alirezarezvani/claude-skills, 28k stars), Performing Soc2 Type2 Audit Preparation (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Compliance Os (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Isms Audit Expert?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 886 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.