Agent skill

Isms Audit Expert

by davila7 in davila7/claude-code-templates

Senior ISMS Audit Expert for internal and external information security management system auditing.

MITAuto-check passedSecurity

Install Isms Audit Expert

skills CLI
$ npx skills add davila7/claude-code-templates --skill isms-audit-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates isms-audit-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/enterprise-communication/isms-audit-expert .claude/skills/isms-audit-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
isms-audit-expert
GitHub stars
33k
Used in
1 other repo
Token cost
~3.1k tokens
SKILL.md length
954 words
Files
4 (incl. scripts, references, assets)
Skills in repo
479
Repo updated
First seen
Licence
MIT

At a glance

Senior ISMS Audit Expert for internal and external information security management system auditing.

  • Works in 4 steps: ISO 27001 ISMS Audit Program Management → Risk-Based Security Audit Planning → ISO 27001 Audit Execution and Methodology → …
  • ISMS internal auditing
  • SKILL.md covers Core ISMS Auditing Competencies, Advanced ISMS Audit Applications, Security Auditor Competency… and External Security Audit…, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Isms Audit Expert is an agent skill from davila7/claude-code-templates. Senior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts, reference files and assets (for example `references/api_reference.md` and `scripts/example.py`).

It sits in Security, covering Security review, Audit readiness and SOC 2 and security compliance. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • ISMS internal auditing
  • External audit preparation
  • Security control testing
  • ISO 27001 certification support

Example prompts

  • “/isms-audit-expert”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. ISO 27001 ISMS Audit Program Management
  2. Risk-Based Security Audit Planning
  3. ISO 27001 Audit Execution and Methodology
  4. Security Control Assessment and Testing

What it can do on your machine

Read from SKILL.md and the folder at commit c0ca7da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Isms Audit Expert loads about 3.1k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 954 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit c0ca7da, republished under its MIT licence (© davila7). 954 words, ~3,114 tokens.

Download SKILL.mdSave it as .claude/skills/isms-audit-expert/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
isms-audit-expert
description
Senior ISMS Audit Expert for internal and external information security management system auditing. Provides ISO 27001 audit expertise, security audit program management, security control assessment, and compliance verification. Use for ISMS internal auditing, external audit preparation, security control testing, and ISO 27001 certification support.

Senior ISMS Audit Expert

Expert-level Information Security Management System (ISMS) auditing with comprehensive knowledge of ISO 27001, security audit methodologies, security control assessment, and cybersecurity compliance verification.

Core ISMS Auditing Competencies

1. ISO 27001 ISMS Audit Program Management

Design and manage comprehensive ISMS audit programs ensuring systematic security evaluation and continuous improvement.

ISMS Audit Program Framework:

ISMS AUDIT PROGRAM MANAGEMENT
├── Security Audit Planning
│   ├── Risk-based audit scheduling
│   ├── Security domain scope definition
│   ├── Technical auditor competency
│   └── Security testing resource allocation
├── Audit Execution Coordination
│   ├── Technical security assessment
│   ├── Administrative control evaluation
│   ├── Physical security verification
│   └── Security documentation review
├── Security Finding Management
│   ├── Security gap identification
│   ├── Vulnerability assessment integration
│   ├── Risk-based finding prioritization
│   └── Security improvement recommendations
└── ISMS Audit Performance
    ├── Security audit effectiveness
    ├── Technical auditor development
    ├── Security methodology enhancement
    └── Industry best practice adoption
2. Risk-Based Security Audit Planning

Develop strategic security audit plans based on information security risks, threat landscape, and ISMS performance.

Security Audit Risk Assessment:

  1. Information Security Risk Evaluation

    • Asset criticality and threat exposure analysis
    • Security control effectiveness assessment
    • Previous security incident and audit analysis
    • Decision Point: Determine audit priority and frequency based on security risk
  2. Security Audit Scope Definition

    • High-Risk Assets: Quarterly technical security assessments
    • Critical Security Controls: Semi-annual control effectiveness testing
    • Standard Security Processes: Annual compliance verification
    • Emerging Threats: Event-driven security evaluations
  3. Technical Security Testing Integration

    • Vulnerability assessment and penetration testing coordination
    • Security control technical verification
    • Threat simulation and red team exercises
    • Compliance scanning and automated testing
3. ISO 27001 Audit Execution and Methodology

Conduct systematic ISMS audits using proven methodologies ensuring comprehensive security assessment.

ISMS Audit Execution Process:

  1. Security Audit Preparation

    • Pre-audit Security Review: Follow scripts/security-audit-prep.py
    • Technical Assessment Planning: Security testing scope and methods
    • Security Auditor Assignment: Technical competency and independence
    • ISMS Documentation Review: Policy, procedure, and control documentation
  2. Security Audit Conduct

    • ISMS Process Assessment: Security management process evaluation
    • Security Control Testing: Technical and administrative control verification
    • Security Compliance Verification: Regulatory and standard compliance
    • Security Culture Assessment: Security awareness and training effectiveness
  3. Security Audit Documentation

    • Security Finding Documentation: Technical and administrative findings
    • Risk Assessment Integration: Security risk impact and likelihood
    • Security Improvement Recommendations: Control enhancement and optimization
    • Compliance Status Reporting: ISO 27001 and regulatory compliance
4. Security Control Assessment and Testing

Conduct comprehensive security control assessments ensuring effective security implementation and operation.

Security Control Assessment Framework:

ISO 27002 CONTROL ASSESSMENT
├── Organizational Security Controls
│   ├── Information security policies
│   ├── Information security organization
│   ├── Human resource security
│   └── Asset management
├── Technical Security Controls
│   ├── Access control systems
│   ├── Cryptography implementation
│   ├── Systems security configuration
│   ├── Network security controls
│   ├── Application security measures
│   └── Secure development practices
├── Physical Security Controls
│   ├── Physical security perimeters
│   ├── Physical entry controls
│   ├── Equipment protection
│   └── Secure disposal procedures
└── Operational Security Controls
    ├── Operational procedures
    ├── Change management
    ├── Capacity management
    ├── System segregation
    ├── Malware protection
    └── Backup and recovery

Advanced ISMS Audit Applications

Technical Security Testing Integration

Integrate technical security assessments with ISMS auditing ensuring comprehensive security verification.

Technical Security Assessment:

  1. Vulnerability Assessment Integration

    • Network vulnerability scanning and analysis
    • Application security testing and code review
    • Configuration assessment and hardening verification
    • Decision Point: Determine technical testing scope based on risk and compliance
  2. Penetration Testing Coordination

    • For External Networks: Follow references/external-pentest-guide.md
    • For Internal Systems: Follow references/internal-pentest-guide.md
    • For Web Applications: Follow references/webapp-security-testing.md
    • Social engineering and phishing simulation
  3. Security Control Verification

    • Access control effectiveness testing
    • Encryption implementation verification
    • Monitoring and logging system assessment
    • Incident response procedure validation
Cybersecurity Compliance Auditing

Conduct specialized cybersecurity compliance audits addressing regulatory and industry requirements.

Cybersecurity Compliance Framework:

  • Healthcare Cybersecurity: HIPAA Security Rule and healthcare-specific requirements
  • Medical Device Cybersecurity: FDA cybersecurity guidance and IEC 62304 integration
  • Financial Services: PCI DSS and financial industry security standards
  • Critical Infrastructure: NIST Cybersecurity Framework and sector-specific guidelines
Cloud Security Auditing

Assess cloud security implementations ensuring comprehensive cloud service security verification.

Cloud Security Audit Approach:

  1. Cloud Service Provider Assessment

    • CSP security certification and compliance verification
    • Shared responsibility model implementation review
    • Data residency and sovereignty compliance
    • Cloud access and identity management assessment
  2. Cloud Configuration Assessment

    • Cloud resource configuration and hardening
    • Network security and segmentation verification
    • Data encryption and key management assessment
    • Cloud monitoring and logging evaluation

Security Auditor Competency and Development

Security Auditor Technical Competency

Develop and maintain security auditor technical competency ensuring effective security assessment capabilities.

Security Auditor Competency Framework:

SECURITY AUDITOR COMPETENCY
├── Technical Security Knowledge
│   ├── Network security and protocols
│   ├── System security and hardening
│   ├── Application security and testing
│   ├── Cryptography and key management
│   └── Security architecture and design
├── Security Assessment Skills
│   ├── Vulnerability assessment techniques
│   ├── Penetration testing methodologies
│   ├── Security control testing
│   └── Risk assessment and analysis
├── Compliance and Standards
│   ├── ISO 27001/27002 expertise
│   ├── Regulatory requirement knowledge
│   ├── Industry standard familiarity
│   └── Audit methodology proficiency
└── Communication and Reporting
    ├── Technical finding documentation
    ├── Risk communication skills
    ├── Executive reporting capabilities
    └── Stakeholder engagement
Show full SKILL.md (402 more words)Show less
Security Audit Tool Proficiency

Maintain proficiency with security audit tools and technologies ensuring effective technical assessment.

Security Audit Tool Categories:

  • Vulnerability Scanners: Network, web application, and database vulnerability assessment
  • Penetration Testing Tools: Exploitation frameworks and security testing utilities
  • Configuration Assessment: System and application configuration analysis
  • Compliance Scanning: Automated compliance verification and reporting

External Security Audit Coordination

ISO 27001 Certification Audit Support

Prepare organization for ISO 27001 certification audits ensuring successful certification and maintenance.

Certification Audit Preparation:

  1. Pre-certification Readiness

    • Internal ISMS audit completion and closure
    • Security control implementation verification
    • ISMS documentation review and compliance
    • Mock Certification Audit: Full-scale external audit simulation
  2. Certification Audit Coordination

    • Stage 1 Audit Support: Documentation review and ISMS assessment
    • Stage 2 Audit Coordination: Implementation testing and verification
    • Surveillance Audit Preparation: Ongoing compliance and improvement
    • Certification body relationship management
Regulatory Security Inspection Preparation

Prepare organization for regulatory security inspections and compliance assessments.

Regulatory Inspection Coordination:

  • Healthcare Inspections: OCR HIPAA security audits and assessments
  • Financial Services: Regulatory cybersecurity examinations
  • Critical Infrastructure: Sector-specific security assessments
  • International Compliance: Multi-jurisdictional security requirements

ISMS Audit Performance and Improvement

Security Audit Performance Metrics

Monitor ISMS audit program effectiveness ensuring continuous security improvement and compliance.

Security Audit KPIs:

  • Security Control Effectiveness: Control implementation and operation success
  • Security Finding Resolution: Finding closure rates and timelines
  • Security Risk Mitigation: Risk reduction and residual risk management
  • Compliance Achievement: ISO 27001 and regulatory compliance rates
  • Security Incident Prevention: Audit-driven security improvement effectiveness
ISMS Audit Program Optimization

Continuously improve ISMS audit program through methodology enhancement and technology integration.

Audit Program Enhancement:

  1. Security Audit Technology Integration

    • Automated security scanning and assessment
    • Continuous security monitoring integration
    • Security information and event management (SIEM) correlation
    • Decision Point: Determine automation opportunities and tool integration
  2. Security Audit Methodology Evolution

    • Threat intelligence integration and analysis
    • Security framework alignment and optimization
    • Industry best practice adoption and customization
    • Regulatory requirement evolution and adaptation

Resources

scripts/
  • isms-audit-scheduler.py: Risk-based ISMS audit planning and scheduling
  • security-audit-prep.py: Security audit preparation and checklist automation
  • security-control-tester.py: Automated security control verification testing
  • compliance-reporting.py: ISO 27001 and regulatory compliance reporting
references/
  • iso27001-audit-methodology.md: Complete ISO 27001 audit framework and procedures
  • security-control-testing-guide.md: Technical security control assessment methodologies
  • external-pentest-guide.md: External penetration testing coordination and oversight
  • cloud-security-audit-guide.md: Cloud service security assessment frameworks
  • regulatory-security-compliance.md: Multi-jurisdictional security compliance requirements
assets/
  • isms-audit-templates/: ISMS audit plan, checklist, and report templates
  • security-testing-tools/: Security assessment and testing automation scripts
  • compliance-checklists/: ISO 27001 and regulatory compliance verification checklists
  • training-materials/: Security auditor training and competency development programs

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references, assets) in cli-tool/components/skills/enterprise-communication/isms-audit-expert of davila7/claude-code-templates.

  • SKILL.md
  • assets/example_asset.txt
  • references/api_reference.md
  • scripts/example.py

Open the folder on GitHubat commit c0ca7da

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in davila7/claude-code-templates, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Isms Audit Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Isms Audit Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Isms Audit Expert this skilldavila7/claude-code-templates33k1 repos~3.1kAutomated safety check: PassMIT
Xray Pre Auditccashwell/evm-cortex131—~25kAutomated safety check: PassMIT
Fp Checkvibeeval/vibecosystem532—~1.6kAutomated safety check: PassMIT
Senior Secopsalirezarezvani/claude-skills28k1 repos~4kAutomated safety check: PassMIT
Vendor Security Reviewmohitagw15856/pm-claude-skills1.4k—~1.1kAutomated safety check: PassMIT
Infrastructure Compliance Auditorborghei/Claude-Skills891—~2.1kAutomated safety check: PassMIT

Similar skills

  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    532 GitHub stars~1.6k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Senior Secops

    alirezarezvani/claude-skills

    Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices.

    28k GitHub starsUsed in 1 repo~4k tokens
    SecurityAuto-check passed
  • Vendor Security Review

    mohitagw15856/pm-claude-skills

    Run a third-party / vendor security review and assign a risk tier with required controls.

    1.4k GitHub stars~1.1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cross-framework infrastructure security audit across cloud, network, and CI/CD.

    891 GitHub stars~2.1k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Find Cybersecurity Firm

    jeremylongshore/tons-of-skills-marketplace

    A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…

    2.8k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes

More from davila7/claude-code-templates

All 479 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    33k GitHub starsUsed in 11 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    33k GitHub starsUsed in 9 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    33k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    33k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    33k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Questions about Isms Audit Expert

What does Isms Audit Expert do?

Senior ISMS Audit Expert for internal and external information security management system auditing. Isms Audit Expert is an agent skill from davila7/claude-code-templates. Senior ISMS Audit Expert for internal and external information security management system auditing.

When should I use Isms Audit Expert?

Isms Audit Expert fits situations like: ISMS internal auditing; external audit preparation; security control testing; ISO 27001 certification support.

How do I install Isms Audit Expert in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill isms-audit-expert -a claude-code`. Or copy the skill folder (cli-tool/components/skills/enterprise-communication/isms-audit-expert in davila7/claude-code-templates) into .claude/skills/isms-audit-expert in your project. Claude Code loads it when a task matches its description.

How do I install Isms Audit Expert in Codex?

Run `npx skills add davila7/claude-code-templates --skill isms-audit-expert -a codex`. Or copy the skill folder (cli-tool/components/skills/enterprise-communication/isms-audit-expert in davila7/claude-code-templates) into .agents/skills/isms-audit-expert in your project. Codex loads it when a task matches its description.

Can I use Isms Audit Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill isms-audit-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/isms-audit-expert, .gemini/skills/isms-audit-expert, .github/skills/isms-audit-expert and .opencode/skills/isms-audit-expert in your project.

What does Isms Audit Expert need to run?

Going by SKILL.md and its folder, Isms Audit Expert needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Isms Audit Expert access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Isms Audit Expert safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Isms Audit Expert use?

Isms Audit Expert is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Isms Audit Expert use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 242 tokens, read only when the agent opens those files.

What are the alternatives to Isms Audit Expert?

Skills that share tags, products or a category with Isms Audit Expert: Xray Pre Audit (ccashwell/evm-cortex, 131 stars), Fp Check (vibeeval/vibecosystem, 532 stars), Senior Secops (alirezarezvani/claude-skills, 28k stars) and Vendor Security Review (mohitagw15856/pm-claude-skills, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Isms Audit Expert?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,512 GitHub stars. The repository holds 479 skills in this directory. The repository was last updated on October 10, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.