Agent skill · Workflow & Productivity

iso-27001-isms

Scope an ISO 27001 ISMS and build the Statement of Applicability across Annex A controls. Use when asked to implement ISO 27001, scope an ISMS, build a Statement of Applicability (SoA), or prepare for ISO 27001 certification. Produces an ISMS plan — scope & context, risk-treatment approach, an Annex A control applicability table (the SoA), and a prioritised implementation roadmap.

mohitagw15856github.com/mohitagw15856GitHub ↗
claude-codecursorships scriptsMIT
Install
npx skills add mohitagw15856/pm-claude-skills --skill iso-27001-isms --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 2
SKILL.md size: 4 KB
Bundled scripts: yes
Path: skills/iso-27001-isms/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 1,255
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

From the SKILL.md

# ISO 27001 ISMS Skill ISO 27001 certifies a *system* (the ISMS), not a checklist — auditors check that you scoped it, assessed risk, and can justify which Annex A controls you applied or excluded (the Statement of Applicability). This skill builds that backbone: scope, risk treatment, and a defensible SoA, so certification is a documented management system rather than a scramble. ## Required Inputs Ask for these only if they aren't already provided: - **ISMS scope** — the products, locations, and information assets in scope (and what's deliberately out). - **Context & interested parties** — the business, its regulatory/customer security obligations, and key risks. - **Risk approach** — how you identify, assess, and treat information-security risk (the SoA flows from the risk assessment, not the other way round). - **Current controls** — what's already implemented across the Annex A domains. ## Output Format ### ISO 27001 ISMS: [organisation] **1. Scope statement** — the boundary of the ISMS: assets, locations, exclusions and why. **2. Context & risk** — interested parties and their requirements; the risk assessment method and risk acceptance criteria. **3. Statement of Applicabili

What's inside
Steps it walks through
  1. Required Inputs
  2. Output Format
  3. ISO 27001 ISMS: [organisation]
  4. Programmatic Helper
  5. Quality Checks
  6. Anti-Patterns
  7. Based On
Ships with 1 file
  • scripts/soa_coverage.py
Commands it runs
python3 scripts/soa_coverage.py soa.json
python3 scripts/soa_coverage.py soa.json --json
More from pm-claude-skills
All skills →
About this skill
What does the iso-27001-isms skill do?

Scope an ISO 27001 ISMS and build the Statement of Applicability across Annex A controls. Use when asked to implement ISO 27001, scope an ISMS, build a Statement of Applicability (SoA), or prepare for ISO 27001 certification. Produces an ISMS plan — scope & context, risk-treatment approach, an Annex A control applicability table (the SoA), and a prioritised implementation roadmap.

How do I install it?

Run `npx skills add mohitagw15856/pm-claude-skills --skill iso-27001-isms --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From mohitagw15856/pm-claude-skills, a repository with 1,255 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going