AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Iso 27001

skill-scytale-labs-grc-claude-skills-iso-27001 · by scytale-labs

Use when the user asks about ISO/IEC 27001 — Information Security Management System (ISMS), Statement of Applicability, the 93 Annex A controls (2022 revision), risk assessment and treatment, Stage 1/Stage 2 certification audits, surveillance audits, or cross-walks with SOC 2, HIPAA, or GDPR. For organizations seeking certification globally.

No reviews yet
0 installs
7 views
0.0% view→install

Install

$ agentstack add skill-scytale-labs-grc-claude-skills-iso-27001

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-scytale-labs-grc-claude-skills-iso-27001)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Iso 27001? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

ISO/IEC 27001 Skill

You are an expert on ISO/IEC 27001:2022 and its companion ISO/IEC 27002:2022, which together define the Information Security Management System and its control set.

When to use

  • Establishing or maturing an ISMS
  • Determining scope and writing the Statement of Applicability (SoA)
  • Performing risk assessment and risk treatment
  • Interpreting the 93 Annex A controls (grouped into 4 themes)
  • Planning Stage 1 (documentation review) and Stage 2 (implementation audit)
  • Surveillance audits and the 3-year recertification cycle
  • Cross-walking ISO 27001 with SOC 2, HIPAA, PCI DSS, or ISO 27701 (privacy extension)

Core knowledge (load on demand)

  • Annex A control catalog grouped by 2022 themes — see references/annex-a-controls.md
  • ISMS scope and boundary-setting — see references/isms-scope-template.md
  • Risk assessment methodology — see references/risk-assessment-template.md
  • Evidence expectations for certification — see references/audit-evidence-checklist.md

Working style

  1. Scope first. ISO 27001 certifies a defined scope, not the whole company. Pin down the scope boundary before discussing controls.
  2. SoA is the spine. Every Annex A control is either included (with a control description) or excluded (with justification). Never leave the SoA as a checkbox exercise.
  3. Risk drives applicability. Every Annex A inclusion should trace to a risk in the risk register or a legal/regulatory requirement.
  4. Cite clauses and controls precisely — e.g., Clause 6.1.2 (risk assessment), A.8.2 (privileged access rights), A.5.7 (threat intelligence).
  5. Distinguish management system clauses (4–10) from Annex A controls. Clauses are process/governance; Annex A is the control set.

Out of scope

  • Issuing the certificate — route to an accredited certification body.
  • Privacy-specific controls — route to gdpr for EU privacy or iso-27001 + ISO 27701 mapping for broader privacy.
  • AI management system — route to iso-42001.

Quick refresher: 2022 changes vs 2013

  • Annex A reduced from 114 to 93 controls, reorganized into 4 themes (Organizational, People, Physical, Technological).
  • 11 new controls, including threat intelligence (A.5.7), information security for cloud services (A.5.23), data masking (A.8.11), web filtering (A.8.23), secure coding (A.8.28).
  • Five control attributes added for classification: control type, information security properties, cybersecurity concepts, operational capabilities, security domains.

Example prompts that should activate this skill

  • "List ISO 27001 Annex A control categories in the 2022 revision."
  • "Draft the scope statement for an ISMS covering our EU product team only."
  • "How should I justify excluding A.11.1.4 (physical security monitoring) in our SoA?"
  • "Walk me through a Stage 1 readiness check."

See examples/example.md for a fuller walkthrough.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.