Agent skill

Iso 27001 Controls

by Hack23 in Hack23/cia

Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations

Apache-2.0Auto-check passedLegal & Compliance

Install Iso 27001 Controls

skills CLI
$ npx skills add Hack23/cia --skill iso-27001-controls -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia iso-27001-controls --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/iso-27001-controls .claude/skills/iso-27001-controls && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iso-27001-controls
GitHub stars
239
Token cost
~4.4k tokens
SKILL.md length
692 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations

  • Works in 6 steps: Security requirements gathering → Threat modeling (STRIDE) → Secure coding standards → …
  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Purpose, When to Use This Skill, Key ISO 27001:2022 Controls… and Control Implementation Checklist, plus 5 more sections
  • Calls mvn and docker-compose; needs SONAR_TOKEN

What it does

Iso 27001 Controls is an agent skill from Hack23/cia. Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/iso-27001-controls”

Requirements

  • Docker
  • A credential in SONAR_TOKEN

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Security requirements gathering
  2. Threat modeling (STRIDE)
  3. Secure coding standards
  4. Security testing (SAST, DAST)
  5. Security code reviews
  6. Vulnerability management

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn
    • docker-compose

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • iso.org
    • nist.gov
    • cisecurity.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iso 27001 Controls loads about 4.4k tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 692 words, ~4,414 tokens.

Download SKILL.mdSave it as .claude/skills/iso-27001-controls/SKILL.md (or your agent's skills folder).
name
iso-27001-controls
description
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
license
Apache-2.0

ISO 27001:2022 Controls Implementation Skill

Purpose

This skill provides guidance for implementing and verifying ISO 27001:2022 Annex A controls within the CIA platform, ensuring systematic information security management aligned with Hack23 ISMS framework.

When to Use This Skill

Apply this skill when:

  • ✅ Implementing new security controls
  • ✅ Conducting ISMS audits or reviews
  • ✅ Responding to security incidents
  • ✅ Preparing for ISO 27001 certification audits
  • ✅ Reviewing security architecture changes
  • ✅ Updating security documentation

Key ISO 27001:2022 Controls for Software Development

A.5 - Organizational Controls

A.5.10 - Acceptable Use of Information

  • ✅ Document acceptable use policy for CIA platform
  • ✅ Define data classification (Public, Internal, Confidential, Restricted)
  • ✅ Specify usage restrictions for political data

A.5.15 - Access Control

  • ✅ Implement RBAC (Role-Based Access Control)
  • ✅ Enforce least privilege principle
  • ✅ Regular access reviews (quarterly)

A.5.17 - Authentication Information

  • ✅ Strong password policy (12+ chars, complexity)
  • ✅ MFA for privileged accounts
  • ✅ Secure password storage (bcrypt, Argon2)

A.5.23 - Information Security for Cloud Services

  • ✅ AWS security configuration review
  • ✅ Cloud provider security assessment
  • ✅ Data sovereignty compliance (EU GDPR)
A.8 - Technical Controls

A.8.1 - User Endpoint Devices

  • ✅ Developer workstation security standards
  • ✅ Encrypted disks (BitLocker, FileVault)
  • ✅ Antivirus/EDR software required

A.8.2 - Privileged Access Rights

java
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class MethodSecurityConfig {
    
    @Bean
    public RoleHierarchy roleHierarchy() {
        RoleHierarchyImpl hierarchy = new RoleHierarchyImpl();
        hierarchy.setHierarchy("ROLE_ADMIN > ROLE_USER\n" +
                              "ROLE_USER > ROLE_GUEST");
        return hierarchy;
    }
}

@Service
public class PrivilegedOperationService {
    
    @PreAuthorize("hasRole('ADMIN')")
    @Audited
    public void modifySystemConfiguration(ConfigurationChange change) {
        // Log privileged action
        auditLogger.log("PRIVILEGED_ACTION", "System config modified", change);
        
        // Perform operation
        configurationRepository.save(change);
    }
}

A.8.3 - Information Access Restriction

java
@Entity
@Table(name = "document")
public class Document {
    @Id
    private String id;
    
    @Enumerated(EnumType.STRING)
    private DataClassification classification; // PUBLIC, INTERNAL, CONFIDENTIAL, RESTRICTED
    
    private String ownerId;
    
    @ElementCollection
    private Set<String> authorizedUserIds;
}

@Service
public class DocumentAccessService {
    
    public Document getDocument(String documentId, String userId) {
        Document doc = documentRepository.findById(documentId)
            .orElseThrow(() -> new ResourceNotFoundException("Document not found"));
        
        // Enforce access control based on classification
        if (!canAccess(doc, userId)) {
            auditLogger.logAccessDenied(userId, documentId);
            throw new AccessDeniedException("Insufficient permissions");
        }
        
        return doc;
    }
    
    private boolean canAccess(Document doc, String userId) {
        switch (doc.getClassification()) {
            case PUBLIC:
                return true;
            case INTERNAL:
                return userService.isInternalUser(userId);
            case CONFIDENTIAL:
                return doc.getAuthorizedUserIds().contains(userId);
            case RESTRICTED:
                return doc.getOwnerId().equals(userId) || 
                       userService.isAdmin(userId);
            default:
                return false;
        }
    }
}

A.8.8 - Management of Technical Vulnerabilities

  • ✅ Weekly vulnerability scans (OWASP Dependency Check)
  • ✅ CodeQL analysis on every PR
  • ✅ SonarCloud quality gates enforced
  • ✅ Security patches applied within 30 days

A.8.9 - Configuration Management

yaml
# Document all configuration in Infrastructure as Code
# Store in version control (git)
# Example: AWS CloudFormation for infrastructure

AWSTemplateFormatVersion: '2010-09-09'
Description: 'CIA Platform Infrastructure - ISO 27001 Compliant'

Resources:
  # Database with encryption enabled (A.8.24)
  CIADatabase:
    Type: AWS::RDS::DBInstance
    Properties:
      Engine: postgres
      StorageEncrypted: true
      KmsKeyId: !Ref DatabaseEncryptionKey
      BackupRetentionPeriod: 30
      EnableCloudwatchLogsExports:
        - postgresql
      DeletionProtection: true
  
  # Application servers with security group restrictions
  AppSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: CIA Application Security Group
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 0.0.0.0/0  # HTTPS only
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          DestinationSecurityGroupId: !Ref DatabaseSecurityGroup

A.8.11 - Data Masking

java
@Component
public class DataMaskingService {
    
    public String maskPersonalId(String personalId) {
        if (personalId == null || personalId.length() < 12) return "***";
        return personalId.substring(0, 4) + "****" + personalId.substring(8);
    }
    
    public String maskEmail(String email) {
        if (email == null || !email.contains("@")) return "***@***";
        int atIndex = email.indexOf('@');
        String prefix = email.substring(0, Math.min(2, atIndex));
        String suffix = email.substring(atIndex);
        return prefix + "***" + suffix;
    }
    
    public String maskPhoneNumber(String phone) {
        if (phone == null || phone.length() < 8) return "***";
        return phone.substring(0, 3) + "****" + phone.substring(phone.length() - 2);
    }
}

// Use in logging
log.info("User accessed document: userId={}, documentId={}", 
    dataMaskingService.maskPersonalId(userId), documentId);

A.8.23 - Web Filtering

  • ✅ Implement Content Security Policy (CSP)
  • ✅ Configure CORS restrictions
  • ✅ Enable XSS protection headers
java
@Configuration
public class SecurityHeadersConfig {
    
    @Bean
    public SecurityFilterChain securityHeaders(HttpSecurity http) throws Exception {
        http.headers(headers -> headers
            .contentSecurityPolicy("default-src 'self'; " +
                                 "script-src 'self'; " +
                                 "style-src 'self'; " +
                                 "img-src 'self' data: https:; " +
                                 "font-src 'self'; " +
                                 "connect-src 'self'; " +
                                 "frame-ancestors 'none';")
            .xssProtection()
            .frameOptions().deny()
            .httpStrictTransportSecurity()
                .maxAgeInSeconds(31536000)
                .includeSubDomains(true)
                .preload(true)
        );
        return http.build();
    }
}

A.8.24 - Use of Cryptography

  • ✅ TLS 1.2+ for all communications
  • ✅ AES-256-GCM for data encryption
  • ✅ bcrypt/Argon2 for password hashing
  • ✅ RSA-4096 or Ed25519 for digital signatures

A.8.28 - Secure Coding

  • ✅ Follow OWASP Top 10 guidelines
  • ✅ Conduct security code reviews
  • ✅ Use static analysis tools (SonarCloud, CodeQL)
  • ✅ Input validation on all user inputs
A.14 - System Acquisition, Development, and Maintenance

A.14.2.1 - Secure Development Policy

Required elements:

  1. Security requirements gathering
  2. Threat modeling (STRIDE)
  3. Secure coding standards
  4. Security testing (SAST, DAST)
  5. Security code reviews
  6. Vulnerability management

A.14.2.5 - Secure System Engineering Principles

  • ✅ Defense in depth
  • ✅ Least privilege
  • ✅ Fail securely
  • ✅ Separation of duties
  • ✅ Economy of mechanism
  • ✅ Complete mediation

A.14.2.8 - System Security Testing

bash
# Automated security testing pipeline
# .github/workflows/security-testing.yml

name: Security Testing

on:
  pull_request:
  push:
    branches: [main]

jobs:
  sast:
    name: Static Application Security Testing
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      
      # CodeQL SAST
      - name: Initialize CodeQL
        uses: github/codeql-action/init@v3
        with:
          languages: java
          queries: security-and-quality
      
      - name: Build
        run: mvn clean compile -DskipTests
      
      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@v3
      
      # SonarCloud
      - name: SonarCloud Scan
        env:
          SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
        run: mvn sonar:sonar -Dsonar.qualitygate.wait=true
      
      # OWASP Dependency Check
      - name: OWASP Dependency Check
        run: mvn org.owasp:dependency-check-maven:check
      
      - name: Upload Dependency Check Report
        uses: actions/upload-artifact@v4
        with:
          name: dependency-check-report
          path: target/dependency-check-report.html
  
  dast:
    name: Dynamic Application Security Testing
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      
      # Start application
      - name: Start Application
        run: |
          docker-compose up -d
          sleep 30
      
      # OWASP ZAP scan
      - name: ZAP Scan
        uses: zaproxy/action-baseline@v0.7.0
        with:
          target: 'http://localhost:8080'
          rules_file_name: '.zap/rules.tsv'
          cmd_options: '-a'

A.14.2.9 - System Acceptance Testing

Security acceptance criteria:

  • ✅ All critical/high vulnerabilities resolved
  • ✅ Security test cases passed
  • ✅ Penetration testing completed
  • ✅ Security documentation updated
  • ✅ ISMS compliance verified
A.16 - Information Security Incident Management

A.16.1.4 - Assessment and Decision of Information Security Events

java
@Service
public class SecurityIncidentService {
    
    public void reportIncident(SecurityIncident incident) {
        // Assess severity
        IncidentSeverity severity = assessSeverity(incident);
        
        // Log to SIEM
        siemLogger.log(severity, incident);
        
        // Notify security team for high/critical incidents
        if (severity.isHighOrCritical()) {
            notificationService.notifySecurityTeam(incident);
        }
        
        // Create incident record
        incidentRepository.save(incident);
        
        // Initiate incident response if needed
        if (severity == IncidentSeverity.CRITICAL) {
            incidentResponseService.initiate(incident);
        }
    }
    
    private IncidentSeverity assessSeverity(SecurityIncident incident) {
        // Classify based on impact and likelihood
        if (incident.involvesDataBreach()) {
            return IncidentSeverity.CRITICAL;
        }
        if (incident.affectsAvailability()) {
            return IncidentSeverity.HIGH;
        }
        if (incident.involvesUnauthorizedAccess()) {
            return IncidentSeverity.MEDIUM;
        }
        return IncidentSeverity.LOW;
    }
}

Control Implementation Checklist

Use this checklist for each ISO 27001 control:

  1. Control Identification

    • ✅ Control reference (e.g., A.8.24)
    • ✅ Control objective documented
    • ✅ Applicability determined
  2. Implementation

    • ✅ Technical controls implemented
    • ✅ Procedural controls documented
    • ✅ Responsibilities assigned
  3. Evidence Collection

    • ✅ Configuration screenshots
    • ✅ Code samples
    • ✅ Policy documents
    • ✅ Audit logs
  4. Testing & Verification

    • ✅ Control effectiveness tested
    • ✅ Gaps identified and remediated
    • ✅ Penetration testing results
  5. Documentation

    • ✅ Statement of Applicability (SOA) updated
    • ✅ Risk treatment plan updated
    • ✅ ISMS documentation current
Show full SKILL.md (248 more words)Show less

Compliance Verification Scripts

bash
#!/bin/bash
# iso27001-compliance-check.sh

echo "=== ISO 27001 Compliance Verification ==="

# A.8.8 - Check for known vulnerabilities
echo "Checking for vulnerabilities (A.8.8)..."
mvn org.owasp:dependency-check-maven:check
if [ $? -ne 0 ]; then
    echo "❌ FAIL: Vulnerabilities detected"
else
    echo "✅ PASS: No vulnerabilities"
fi

# A.8.24 - Verify TLS configuration
echo "Checking TLS configuration (A.8.24)..."
if grep -q "TLSv1.3,TLSv1.2" server.xml; then
    echo "✅ PASS: TLS 1.2+ configured"
else
    echo "❌ FAIL: Weak TLS configuration"
fi

# A.8.28 - Run security scans
echo "Running SAST scans (A.8.28)..."
mvn sonar:sonar -Dsonar.qualitygate.wait=true
if [ $? -eq 0 ]; then
    echo "✅ PASS: Code quality gate passed"
else
    echo "❌ FAIL: Code quality issues"
fi

# A.14.2.8 - Security test coverage
echo "Checking security test coverage..."
mvn test
coverage=$(grep -oP 'Coverage: \K[0-9]+' target/site/jacoco/index.html)
if [ "$coverage" -ge 80 ]; then
    echo "✅ PASS: Test coverage ${coverage}%"
else
    echo "❌ FAIL: Test coverage below 80%"
fi

echo "=== Compliance Check Complete ==="

ISMS Documentation Requirements

Maintain these documents for ISO 27001 compliance:

  1. ISMS Policy (✅ Required)

    • Information Security Policy
    • Purpose and scope
    • Management commitment
  2. Risk Assessment (✅ Required)

    • Asset inventory
    • Threat analysis
    • Risk treatment plan
  3. Statement of Applicability (SOA) (✅ Required)

    • List all Annex A controls
    • Justification for inclusion/exclusion
    • Implementation status
  4. Procedures (✅ Required)

    • Access control procedure
    • Incident response procedure
    • Change management procedure
    • Backup and recovery procedure
  5. Records (✅ Required)

    • Audit logs
    • Training records
    • Incident reports
    • Risk assessments
    • Management reviews

Hack23 ISMS Policy References

Comprehensive ISO 27001 Implementation Documentation:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/iso-27001-controls of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Iso 27001 Controls next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iso 27001 Controls compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iso 27001 Controls this skillHack23/cia239—~4.4kAutomated safety check: PassApache-2.0
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repos~2.7kAutomated safety check: PassMIT
Grc Knowledgemlunato47/claude-grc-plugin183—~6.1kAutomated safety check: PassMIT
Information Security Manager Iso27001davila7/claude-code-templates32k1 repos~2.9kAutomated safety check: PassMIT
Audit Frameworkscartography-cncf/cartography4.1k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    942 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    942 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    183 GitHub stars~6.1k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Information Security Manager Iso27001

    davila7/claude-code-templates

    Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies.

    32k GitHub starsUsed in 1 repo~2.9k tokens
    Legal & ComplianceAuto-check passed
  • Audit Frameworks

    cartography-cncf/cartography

    Audit Cartography's rules and compliance frameworks under cartography/rules/data/rules/.

    4.1k GitHub stars~2.8k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Iso 27001 Controls

What does Iso 27001 Controls do?

Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations. Iso 27001 Controls is an agent skill from Hack23/cia.

When should I use Iso 27001 Controls?

Iso 27001 Controls fits situations like: tasks that involve SOC 2 and security compliance.

How do I install Iso 27001 Controls in Claude Code?

Run `npx skills add Hack23/cia --skill iso-27001-controls -a claude-code`. Or copy the skill folder (.github/skills/iso-27001-controls in Hack23/cia) into .claude/skills/iso-27001-controls in your project. Claude Code loads it when a task matches its description.

How do I install Iso 27001 Controls in Codex?

Run `npx skills add Hack23/cia --skill iso-27001-controls -a codex`. Or copy the skill folder (.github/skills/iso-27001-controls in Hack23/cia) into .agents/skills/iso-27001-controls in your project. Codex loads it when a task matches its description.

Can I use Iso 27001 Controls in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill iso-27001-controls -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iso-27001-controls, .gemini/skills/iso-27001-controls, .github/skills/iso-27001-controls and .opencode/skills/iso-27001-controls in your project.

What does Iso 27001 Controls need to run?

Going by SKILL.md and its folder, Iso 27001 Controls needs the command-line tools its instructions call (mvn and docker-compose) and credentials named SONAR_TOKEN. Our summary lists: Docker; A credential in SONAR_TOKEN.

Does Iso 27001 Controls access the network?

SKILL.md names 4 domains. As links in the text: github.com, iso.org, nist.gov and cisecurity.org. This is read from the text; nothing was executed.

Is Iso 27001 Controls safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iso 27001 Controls use?

Iso 27001 Controls is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iso 27001 Controls use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iso 27001 Controls?

Skills that share tags, products or a category with Iso 27001 Controls: Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Soc2 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 942 stars), Grc Knowledge (mlunato47/claude-grc-plugin, 183 stars) and Information Security Manager Iso27001 (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iso 27001 Controls?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.