isms-audit-expert
Plan and Conduct ISO 27001 ISMS Audits
ISMS teams need consistent audit plans, evidence reviews, and control assessments. This skill structures ISO 27001 audit work and prepares clear findings and recommendations.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "isms-audit-expert" from https://skillstore.io/skills/davila7-isms-audit-expert.md and its manifest at https://skillstore.io/api/skills/davila7-isms-audit-expert/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "isms-audit-expert". Create a risk-based audit plan for a cloud service provider with unresolved access control findings.
Expected outcome:
- Quarterly access control and identity governance audits receive the highest priority.
- Evidence includes privileged access reviews, joiner and leaver records, authentication settings, and prior corrective actions.
- The plan assigns independent technical reviewers and tracks closure against defined deadlines.
Using "isms-audit-expert". Write a finding for inconsistent quarterly access reviews.
Expected outcome:
Access reviews were completed for two of four sampled quarters. This weakens timely privilege removal. Assign an owner and verify complete reviews monthly.
Using "isms-audit-expert". Summarize certification readiness from an evidence review with missing internal audit records.
Expected outcome:
Readiness is incomplete because the organization cannot demonstrate an effective internal audit program. Complete the audit cycle and retain findings, actions, and closure evidence.
Security Audit
Low RiskAll 19 static findings are false positives because they identify Markdown formatting or an audit KPI. A separate low-severity finding notes that intrusive testing and phishing simulations lack explicit authorization and scope requirements.
Confirmed security concerns (1)
Risk Factors
โ๏ธ External commands (18)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/davila7-isms-audit-expert/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/davila7-isms-audit-expert?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/davila7-isms-audit-expert?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/davila7-isms-audit-expert/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/davila7-isms-audit-expert.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
davila7. (2026). isms-audit-expert security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/davila7-isms-audit-expert/audits/9BibTeX citation
@techreport{davila7-davila7-isms-audit-expert-2026,
author = {davila7},
title = {isms-audit-expert security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/davila7-isms-audit-expert/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "isms-audit-expert security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "davila7"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/davila7-isms-audit-expert/audits/9"
identifiers:
- type: other
value: "skillstore:davila7-isms-audit-expert:audit:9"
description: "Skillstore immutable audit report identifier"
Compare variants
2 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
alirezarezvani-isms-audit-expert
2026-08-21
davila7-isms-audit-expert
2026-08-21
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Build an Annual Audit Program
Prioritize audit topics, set frequencies, assign competencies, and connect the schedule to security risks.
Assess Control Effectiveness
Prepare evidence requests, interviews, samples, and test criteria for technical and administrative controls.
Prepare for Certification
Review readiness, organize Stage 1 evidence, identify gaps, and prioritize corrective actions before external assessment.
Try These Prompts
Create an ISO 27001 internal audit checklist for [scope]. Include objectives, evidence requests, interview roles, and expected control results.
Develop a risk-based ISMS audit plan for [organization]. Use [risk register details], prior findings, and audit frequency constraints.
Design control effectiveness tests for [controls]. Separate design and operating effectiveness, then define samples, evidence, pass criteria, and finding severity.
Assess [organization] for ISO 27001 certification readiness using [evidence summary]. Identify gaps, root causes, risk, remediation owners, and Stage 1 priorities.
Best Practices
- Provide the audit scope, applicable requirements, risk register, and prior findings before requesting a plan.
- Separate control design, implementation, and operating effectiveness when defining tests and conclusions.
- Validate generated findings against objective evidence and assign accountable remediation owners.
Avoid
- Do not claim certification or compliance from incomplete evidence.
- Do not run penetration tests or social engineering exercises without written authorization and an approved scope.
- Do not accept generic recommendations that lack risk, ownership, deadlines, or verification criteria.
Frequently Asked Questions
Does this skill certify an organization to ISO 27001?
Can it create an internal audit plan?
Does it perform technical security testing?
Which standards does it cover?
What information improves the audit output?
Can it prepare certification audit materials?
Developer Details
Author
davila7License
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Ref
c43861a65bb95efcae259cd161c9d6f4dc7eec6f
Maintenance freshness
7/24/2026
Usage
17 downloads ยท 265 views
File structure
๐ assets/
๐ example_asset.txt
๐ references/
๐ api_reference.md
๐ scripts/
๐ example.py
๐ SKILL.md