neo-iso-27001

Solid

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27001 ISMS, perform information security risk discovery, define scope, create an evidence matrix, conduct a gap analysis, draft a Statement of Applicability, prepare for an internal audit, or create an improvement plan. Use neo-iso-27701 when the main concern is PII, privacy management, or PIMS. Do not use this skill for legal advice or certification guarantees.

Code & Development 7 stars 2 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 84/100

Stars 20%
30
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Neo ISO/IEC 27001 Provide evidence-based assistance for establishing, improving, or reviewing an information security management system (ISMS). Read `references/sources-and-scope.md` first, then follow the workflow below. ## Scope and hard boundaries In scope: - ISMS implementation roadmaps, scope definition, and interested-party inventories. - Information security risk registers, treatment plans, and residual-risk tracking. - Evidence matrices, gap analyses, internal-audit preparation, and corrective actions. - Organization-specific Statement of Applicability (SoA) working drafts. Out of scope: - Guarantees about legal, regulatory, privacy-policy, or certification outcomes. - Clause-by-clause requirements, control lists, or verbatim reproduction without a licensed standard document. - Direct deployment of technical controls unless the user separately provides the technical requirements and authorized scope. ## Version gate 1. Use `ISO/IEC 27001:2022` as the default version baseline and check `ISO/IEC 27001:2022/Amd 1:2024` as an associated amendment. 2. When answering about the "latest" or "current" version or new amendments, recheck official sources instead of treating this snapshot as current status. 3. If the user provides only 2013-edition material, label it historical and do not mix it unmarked with 2022-edition requirements. 4. Use precise clause-level analysis only with licensed local documents supplied by the user; otherwise provide only high-level workflow...

Details

Author
Benknightdark
Repository
Benknightdark/neo-skills
Created
7 months ago
Last Updated
5 days ago
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Code & Development Solid

neo-iso-27701

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27701 PIMS, inventory PII processing, analyze controller and processor responsibilities, create a privacy risk or evidence matrix, conduct a gap analysis, prepare for an audit, or create an improvement plan. Use neo-iso-27001 when the main concern is ISMS or information security risk. Do not treat PIMS as a legal-compliance guarantee for any specific privacy law.

7 Updated 5 days ago
Benknightdark
Data & Documents Featured

iso27001

Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.

890 Updated 5 days ago
Sushegaad
Data & Documents Listed

iso27001

Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.

3 Updated today
Jandyoverseas977