跳到主要内容
知仓学习社ZHICANG

iso-27001-isms

Scope an ISO 27001 ISMS and build the Statement of Applicability across Annex A controls. Use when asked to implement ISO 27001, scope an ISMS, buil…

不碰外部(只输出文字)无严重或高危命中mohitagw15856/pm-claude-skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

ISO 27001 ISMS Skill

ISO 27001 certifies a system (the ISMS), not a checklist — auditors check that you scoped it, assessed

risk, and can justify which Annex A controls you applied or excluded (the Statement of Applicability).

This skill builds that backbone: scope, risk treatment, and a defensible SoA, so certification is a

documented management system rather than a scramble.

Required Inputs

Ask for these only if they aren't already provided:

  • ISMS scope — the products, locations, and information assets in scope (and what's deliberately out).
  • Context & interested parties — the business, its regulatory/customer security obligations, and key risks.
  • Risk approach — how you identify, assess, and treat information-security risk (the SoA flows from the risk assessment, not the other way round).
  • Current controls — what's already implemented across the Annex A domains.

Output Format

ISO 27001 ISMS: [organisation]

1. Scope statement — the boundary of the ISMS: assets, locations, exclusions and why.

2. Context & risk — interested parties and their requirements; the risk assessment method and risk acceptance criteria.

3. Statement of Applicability (SoA) — the heart of it: each Annex A control, applicable or not, status, and justification:

| Annex A control | Applicable? | Status | Justification |

|---|---|---|---|

| A.5 Access control policy | Yes | met | Required for customer data |

| A.8 Teleworking | No | n/a | No remote-access to in-scope systems — excluded with rationale |

(Excluding a control is fine — excluding it without a justification is an audit finding.)

4. Risk treatment plan — the top risks, the treatment (mitigate/accept/transfer/avoid), and the controls that address each.

5. Implementation roadmap — prioritised: mandatory clauses 4–10 (management system) first, then the highest-risk Annex A gaps, with owners and dates.

Programmatic Helper

scripts/soa_coverage.py (stdlib only) scores SoA coverage and flags controls excluded without a

justification (the classic finding):

# soa.json: [{"control":"A.5.1","applicable":true,"status":"met|partial|gap","justification":"..."}, ...]
python3 scripts/soa_coverage.py soa.json
python3 scripts/soa_coverage.py soa.json --json

Quality Checks

  • [ ] The ISMS scope is explicit, including deliberate exclusions
  • [ ] The SoA covers every Annex A control with an applicable/excluded decision
  • [ ] Every excluded control carries a justification (the most common audit finding)
  • [ ] The SoA traces to the risk assessment — controls exist to treat identified risks, not for show
  • [ ] Mandatory management-system clauses (4–10) are addressed, not just the Annex A controls

Anti-Patterns

  • [ ] Do not exclude a control without a written justification — silent exclusions are audit findings
  • [ ] Do not build the SoA before the risk assessment — applicability is derived from risk, not guessed
  • [ ] Do not treat Annex A as the whole standard — clauses 4–10 (the management system) are mandatory and where many fail
  • [ ] Do not mark controls "implemented" without evidence of operation — certification audits sample evidence
  • [ ] Do not present this as certification — only an accredited body certifies; this prepares the ISMS

Based On

ISO/IEC 27001 (ISMS clauses 4–10) and Annex A control set + the Statement of Applicability requirement.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 3 个不同仓库或目录里都有叫 iso-27001-isms 的技能。它们内容并不相同,别混用: