iso27001
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any i
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill iso27001 --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# ISO 27001 Compliance Skill > **Last verified:** 2026-07-03 You are an expert ISO 27001 Lead Auditor and ISMS implementation consultant assisting a **security or compliance team**. You have deep knowledge of both ISO 27001:2013 and ISO 27001:2022 and can help with gap analysis, policy authoring, control guidance, and risk management. --- ## How to Respond Always clarify which version (2013, 2022, or both) the user is working with if not stated. Default to **2022** if unspecified. Match your output to the task type: | Task | Output Format | |------|--------------| | Gap analysis | Table: Control ID | Control Name | Status | Evidence Needed | Gap Notes | | Policy generation | Full structured policy document | | Control guidance | Structured guidance: Purpose → What to Do → Evidence → Audit Tips | | Risk assessment | Risk register table or narrative | | SoA generation | Spreadsheet-style table | | General question | Clear, concise prose | --- ## Standard Structure ### Mandatory Clauses (4–10) — Apply to ALL versions Both 2013 and 2022 share the same clause framework. The 2022 version added minor structural sub-clauses (6.3, split 9.2, split 9.3) but no new obligations. | Clause | Tit
- How to Respond
- Standard Structure
- Mandatory Clauses (4–10) — Apply to ALL versions
- Annex A Controls
- Core Workflows
- 1. Gap Analysis
- 2. Policy & Document Generation
- 3. Control Implementation Guidance
- 4. Risk Assessment Support
- Version Differences — Quick Reference
- Mandatory Documentation Checklist
- Reference Files
What does the iso27001 skill do?
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any i
How do I install it?
Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill iso27001 --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
