MR
Mayur Rathi
@sickn33
⭐ 47.3k GitHub stars

iso27001-compliance

iso27001-compliance is an code AI skill with a core value of Implement ISO 27001 Information Security Management System. It helps developers solve real-world problems in the code domain, boosting efficiency, automating repetitive tasks, and optimizing workflows.

Implement ISO 27001 Information Security Management System. Configure ISMS controls and risk management. Use when implementing enterprise security frameworks.

Last verified on: 2026-10-06

Quick Facts

Category code
Works With Claude
Source sickn33/antigravity-awesome-skills
Stars ⭐ 47.3k
Last Verified 2026-10-06
Risk Level Low
mkdir -p ./skills/iso27001-compliance && curl -sfL https://raw.githubusercontent.com/sickn33/antigravity-awesome-skills/main/skills/iso27001-compliance/SKILL.md -o ./skills/iso27001-compliance/SKILL.md

Run in terminal / PowerShell. Requires curl (Unix) or PowerShell 5+ (Windows).

Skill Content

# ISO 27001 Compliance


Implement an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022.


When to Use


- Establishing an ISMS for the first time in an organization

- Preparing for ISO 27001 certification audit

- Conducting risk assessments and developing risk treatment plans

- Creating the Statement of Applicability (SoA)

- Transitioning from ISO 27001:2013 to the 2022 revision

- Meeting customer or regulatory requirements for ISO 27001 certification


ISMS Plan-Do-Check-Act Cycle


yaml
pdca_cycle:
  plan:
    - Define ISMS scope and boundaries
    - Establish information security policy
    - Conduct risk assessment
    - Develop risk treatment plan
    - Produce Statement of Applicability
    - Obtain management approval and commitment
    - Define security objectives and metrics

  do:
    - Implement selected Annex A controls
    - Deploy technical security controls
    - Conduct security awareness training
    - Document all procedures and processes
    - Implement incident management process
    - Establish supplier security management

  check:
    - Conduct internal audits (at least annual)
    - Perform management review meetings
    - Monitor and measure control effectiveness
    - Review incident trends and near misses
    - Assess compliance with legal requirements
    - Evaluate security metrics against objectives

  act:
    - Address nonconformities with corrective actions
    - Implement continual improvement initiatives
    - Update risk assessment based on changes
    - Refine controls based on audit findings
    - Communicate improvements to stakeholders

ISMS Scope Definition


yaml
isms_scope:
  template:
    organization: "Company Name, Ltd."
    scope_statement: |
      The ISMS covers the design, development, operation, and support of
      the Company's cloud-based SaaS platform, including all supporting
      infrastructure, personnel, and processes at the following locations.

    included:
      locations:
        - "Primary office: 123 Main Street, City, Country"
        - "AWS us-east-1 and eu-west-1 regions"
        - "Remote workers accessing corporate systems"
      business_processes:
        - "Software development and deployment"
        - "Cloud infrastructure management"
        - "Customer data processing and storage"
        - "Customer support operations"
        - "Corporate IT and internal systems"
      information_assets:
        - "Customer data (PII, business data)"
        - "Source code and intellectual property"
        - "Employee personal data"
        - "Financial records"
        - "Security configurations and credentials"
      technology:
        - "AWS cloud infrastructure"
        - "SaaS application stack"
        - "Corporate IT systems (Google Workspace, Okta, Jira)"
        - "Development tools (GitHub, CI/CD pipelines)"

    excluded:
      - "Physical data center operations (inherited from AWS)"
      - "Third-party SaaS platforms beyond integration points"
    exclusion_justification: "Physical data center controls are inherited from AWS, which maintains its own ISO 27001 certification."

    interfaces:
      - "Customer API endpoints"
      - "Third-party integrations (payment processor, email provider)"
      - "AWS management plane"

Risk Assessment Process


yaml
risk_assessment:
  methodology:
    approach: "Asset-based risk assessment"
    risk_formula: "Risk = Likelihood x Impact"
    scale: "1-5 for both likelihood and impact (total 1-25)"

  likelihood_scale:
    1: "Rare - less than once per 5 years"
    2: "Unlikely - once per 2-5 years"
    3: "Possible - once per 1-2 years"
    4: "Likely - multiple times per year"
    5: "Almost Certain - monthly or more frequent"

  impact_scale:
    1: "Negligible - minimal operational impact, no data loss"
    2: "Minor - limited impact, small data exposure, <$10K cost"
    3: "Moderate - significant impact, data breach <1K records, <$100K cost"
    4: "Major 

🎯 Best For

  • Security auditors
  • DevSecOps teams
  • Compliance officers
  • Claude users
  • Software engineers

💡 Use Cases

  • Auditing dependencies for known CVEs
  • Scanning API endpoints for auth gaps
  • Code quality improvement
  • Best practice enforcement

📖 How to Use This Skill

  1. 1

    Install the Skill

    Copy the install command from the Terminal tab and run it. The SKILL.md file downloads to your local skills directory.

  2. 2

    Load into Your AI Assistant

    Open Claude and reference the skill. Paste the SKILL.md content or use the system prompt tab.

  3. 3

    Apply iso27001-compliance to Your Work

    Open your project in the AI assistant and ask it to apply the skill. Start with a small module to verify the output quality.

  4. 4

    Review and Refine

    Review AI suggestions before committing. Run tests, check for regressions, and iterate on the skill output.

❓ Frequently Asked Questions

Can this replace a dedicated SAST tool?

AI-based security review is complementary to SAST tools. Use it as a first-pass filter, not a replacement.

Is iso27001-compliance compatible with Cursor and VS Code?

Yes — this skill works with any AI coding assistant including Cursor, VS Code with Copilot, and JetBrains IDEs.

Do I need specific dependencies for iso27001-compliance?

Check the install command and Works With section. Most code skills only require the AI assistant and your codebase.

How do I install iso27001-compliance?

Copy the install command from the Terminal tab and run it. The skill downloads to ./skills/iso27001-compliance/SKILL.md, ready to use.

Can I customize this skill for my team?

Absolutely. Edit the SKILL.md file to add team-specific instructions, examples, or workflows.

⚠️ Common Mistakes to Avoid

Only scanning surface-level issues

Deep security review requires understanding your app architecture, not just regex patterns.

Skipping validation

Always test AI-generated code changes, even for simple refactors.

Missing dependency updates

Check if the skill requires updated dependencies or new packages.

🔗 Related Skills