Isms Audit Expert

alirezarezvani/claude-skills/ra-qm-team/skills/isms-audit-expert

作者 alirezarezvani19392f7a0826无许可证27K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库5周前更新

Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.

AI 生成的概览

指导 ISO 27001 ISMS 审计、控制评估、不符合项分类与认证准备工作。

功能
该技能为规划和执行 ISO 27001 ISMS 审计提供结构化指导,包括基于风险的审计排期、审计前准备、证据收集和控制测试。它提供用于记录审计发现、分类不符合项和管理纠正措施的模板与流程。它还涵盖第一阶段和第二阶段认证准备以及监督审核周期。随附的 Python 脚本可生成 JSON 或 markdown 格式的基于风险的审计计划。
适用场景
适用于准备或执行 ISO 27001 内部审核、认证审核或监督审核。适合控制评估、差距分析、适用性声明审查和不符合项管理。也支持纠正措施跟踪和认证准备情况检查。
运行要求
运行随附的 isms_audit_scheduler.py 脚本需要 Python 运行时;该脚本接受年份、控制项 CSV 和输出格式参数。参考 markdown 文件由智能体读取。未说明需要凭据或网络访问。

ISMS Audit Expert

Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.

Table of Contents


Audit Program Management

Risk-Based Audit Schedule

Risk LevelAudit FrequencyExamples
CriticalQuarterlyPrivileged access, vulnerability management, logging
HighSemi-annualAccess control, incident response, encryption
MediumAnnualPolicies, awareness training, physical security
LowAnnualDocumentation, asset inventory

Annual Audit Planning Workflow

  1. Review previous audit findings and risk assessment results
  2. Identify high-risk controls and recent security incidents
  3. Determine audit scope based on ISMS boundaries
  4. Assign auditors ensuring independence from audited areas
  5. Create audit schedule with resource allocation
  6. Obtain management approval for audit plan
  7. Validation: Audit plan covers all Annex A controls within certification cycle

Auditor Competency Requirements

  • ISO 27001 Lead Auditor certification (preferred)
  • No operational responsibility for audited processes
  • Understanding of technical security controls
  • Knowledge of applicable regulations (GDPR, HIPAA)

Audit Execution

Pre-Audit Preparation

  1. Review ISMS documentation (policies, SoA, risk assessment)
  2. Analyze previous audit reports and open findings
  3. Prepare audit plan with interview schedule
  4. Notify auditees of audit scope and timing
  5. Prepare checklists for controls in scope
  6. Validation: All documentation received and reviewed before opening meeting

Audit Conduct Steps

  1. Opening Meeting

    • Confirm audit scope and objectives
    • Introduce audit team and methodology
    • Agree on communication channels and logistics
  2. Evidence Collection

    • Interview control owners and operators
    • Review documentation and records
    • Observe processes in operation
    • Inspect technical configurations
  3. Control Verification

    • Test control design (does it address the risk?)
    • Test control operation (is it working as intended?)
    • Sample transactions and records
    • Document all evidence collected
  4. Closing Meeting

    • Present preliminary findings
    • Clarify any factual inaccuracies
    • Agree on finding classification
    • Confirm corrective action timelines
  5. Validation: All controls in scope assessed with documented evidence


Control Assessment

Control Testing Approach

  1. Identify control objective from ISO 27002
  2. Determine testing method (inquiry, observation, inspection, re-performance)
  3. Define sample size based on population and risk
  4. Execute test and document results
  5. Evaluate control effectiveness
  6. Validation: Evidence supports conclusion about control status

For detailed technical verification procedures by Annex A control, see security-control-testing.md [blocked].


Finding Management

Finding Classification

SeverityDefinitionResponse Time
Major NonconformityControl failure creating significant risk30 days
Minor NonconformityIsolated deviation with limited impact90 days
ObservationImprovement opportunityNext audit cycle

Finding Documentation Template

Finding ID: ISMS-[YEAR]-[NUMBER]Control Reference: A.X.X - [Control Name]Severity: [Major/Minor/Observation]
Evidence:- [Specific evidence observed]- [Records reviewed]- [Interview statements]
Risk Impact:- [Potential consequences if not addressed]
Root Cause:- [Why the nonconformity occurred]
Recommendation:- [Specific corrective action steps]

Corrective Action Workflow

  1. Auditee acknowledges finding and severity
  2. Root cause analysis completed within 10 days
  3. Corrective action plan submitted with target dates
  4. Actions implemented by responsible parties
  5. Auditor verifies effectiveness of corrections
  6. Finding closed with evidence of resolution
  7. Validation: Root cause addressed, recurrence prevented

Certification Support

Stage 1 Audit Preparation

Ensure documentation is complete:

  • ISMS scope statement
  • Information security policy (management signed)
  • Statement of Applicability
  • Risk assessment methodology and results
  • Risk treatment plan
  • Internal audit results (past 12 months)
  • Management review minutes

Stage 2 Audit Preparation

Verify operational readiness:

  • All Stage 1 findings addressed
  • ISMS operational for minimum 3 months
  • Evidence of control implementation
  • Security awareness training records
  • Incident response evidence (if applicable)
  • Access review documentation

Surveillance Audit Cycle

PeriodFocus
Year 1, Q2High-risk controls, Stage 2 findings follow-up
Year 1, Q4Continual improvement, control sample
Year 2, Q2Full surveillance
Year 2, Q4Re-certification preparation

Validation: No major nonconformities at surveillance audits.


Tools

scripts/

ScriptPurposeUsage
isms_audit_scheduler.pyGenerate risk-based audit planspython scripts/isms_audit_scheduler.py --year 2025 --format markdown

Audit Planning Example

bash
# Generate annual audit planpython scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json
# With custom control risk ratingspython scripts/isms_audit_scheduler.py --controls controls.csv --format markdown

References

FileContent
iso27001-audit-methodology.md [blocked]Audit program structure, pre-audit phase, certification support
security-control-testing.md [blocked]Technical verification procedures for ISO 27002 controls
cloud-security-audit.md [blocked]Cloud provider assessment, configuration security, IAM review

Audit Performance Metrics

KPITargetMeasurement
Audit plan completion100%Audits completed vs. planned
Finding closure rate>90% within SLAClosed on time vs. total
Major nonconformities0 at certificationCount per certification cycle
Audit effectivenessIncidents preventedSecurity improvements implemented

来源与署名

来源:alirezarezvani/claude-skills位于ra-qm-team/skills/isms-audit-expert提交19392f7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架