# Plan and Conduct ISO 27001 ISMS Audits

ISMS teams need consistent audit plans, evidence reviews, and control assessments. This skill structures ISO 27001 audit work and prepares clear findings and recommendations.

## Install

```bash
npx skillstore add davila7/isms-audit-expert
```

## Metadata

- Status: approved
- Slug: davila7-isms-audit-expert
- Skillstore revision: r2
- Version status: missing
- Tree hash: 0726f8df878b53fc7a969b896cd0bf8deed0f372bd9ffcd15130f6d778d17c6d
- Author: davila7
- GitHub username: davila7
- License: MIT
- Repository: https://github.com/davila7/claude-code-templates/tree/main/cli-tool/components/skills/enterprise-communication/isms-audit-expert
- Ref: c43861a65bb95efcae259cd161c9d6f4dc7eec6f
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 80
- Quality tier: silver
- Public page: https://skillstore.pages.dev/skills/davila7-isms-audit-expert
- Manifest: https://skillstore.pages.dev/api/skills/davila7-isms-audit-expert/manifest

## Capabilities

- Structures risk-based ISMS audit programs and schedules.
- Defines ISO 27001 audit scopes, priorities, and testing approaches.
- Organizes evidence collection and security control effectiveness assessments.
- Supports certification readiness, surveillance audits, and regulatory inspection preparation.
- Frames risk-ranked findings, compliance summaries, and improvement recommendations.

## Use Cases

- Build an Annual Audit Program: Prioritize audit topics, set frequencies, assign competencies, and connect the schedule to security risks.
- Assess Control Effectiveness: Prepare evidence requests, interviews, samples, and test criteria for technical and administrative controls.
- Prepare for Certification: Review readiness, organize Stage 1 evidence, identify gaps, and prioritize corrective actions before external assessment.

## Prompt Templates

### Create a Basic Audit Checklist

```
Create an ISO 27001 internal audit checklist for [scope]. Include objectives, evidence requests, interview roles, and expected control results.
```

### Develop a Risk-Based Audit Plan

```
Develop a risk-based ISMS audit plan for [organization]. Use [risk register details], prior findings, and audit frequency constraints.
```

### Design Control Effectiveness Tests

```
Design control effectiveness tests for [controls]. Separate design and operating effectiveness, then define samples, evidence, pass criteria, and finding severity.
```

### Evaluate Certification Readiness

```
Assess [organization] for ISO 27001 certification readiness using [evidence summary]. Identify gaps, root causes, risk, remediation owners, and Stage 1 priorities.
```

## Limitations

- Provides guidance only and does not replace an accredited certification body or qualified auditor.
- Does not execute vulnerability scans, penetration tests, or automated control checks.
- Included scripts, references, and assets are placeholders and do not implement the named audit resources.
- Requires organization-specific scope, risk, evidence, and regulatory context for reliable conclusions.

## Best Practices

- Provide the audit scope, applicable requirements, risk register, and prior findings before requesting a plan.
- Separate control design, implementation, and operating effectiveness when defining tests and conclusions.
- Validate generated findings against objective evidence and assign accountable remediation owners.

## Anti Patterns

- Do not claim certification or compliance from incomplete evidence.
- Do not run penetration tests or social engineering exercises without written authorization and an approved scope.
- Do not accept generic recommendations that lack risk, ownership, deadlines, or verification criteria.

## Security Audit

- Audited at: 2026-07-23T15:06:09.03\+00:00
- Summary: All 19 static findings are false positives because they identify Markdown formatting or an audit KPI. A separate low-severity finding notes that intrusive testing and phishing simulations lack explicit authorization and scope requirements.

## Stats

- Views: 265
- Downloads: 21
- Favorites: 0
- Popularity score: 0
