ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete
Implementing ISO 27001 Information Security Management
Overview
ISO/IEC 27001:2022 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). This skill covers the complete lifecycle from scoping through certification, including Annex A control selection, risk assessment methodology, Statement of Applicability (SoA) creation, and continuous improvement processes.
When to Use
When deploying or configuring implementing iso 27001 information security management capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Common Misconfigurations & Verification
ISMS audits most often fail where the Statement of Applicability claims a
control is implemented but the operating evidence does not exist:
SoA vs. reality gap: the SoA marks an Annex A control "implemented" with
no artifact behind it (e.g., A.8.16 Monitoring Activities ticked but no log
source list or alert rules). Verify by sampling each "applicable" control for
a dated record of operation, not just a policy reference.
Scope gerrymandering (Clause 4): the ISMS scope excludes the systems that
actually process the data, so the certificate is meaningless. Confirm the
scope statement covers the in-scope assets in the risk register.
Risk treatment plan not closed: risks accepted on paper but no owner or
due date; cross-check the RTP against the risk register for orphaned items.
2022 transition controls missed: A.5.7 (Threat Intelligence), A.5.23
(Cloud), A.8.28 (Secure Coding) silently left at "not applicable" without
justification. Verify each exclusion has a documented rationale.
Internal audit / management review (Clause 9) are stale: confirm dated
audit reports and review minutes exist within the certification cycle.
Prerequisites
Understanding of information security principles and risk management concepts
Familiarity with organizational governance structures and business processes
Knowledge of IT infrastructure, network architecture, and data flows
Access to ISO/IEC 27001:2022 and ISO/IEC 27002:2022 standards documents
Core Concepts
ISMS Clauses (4-10)
The management system requirements define what must be done:
Clause 4 - Context of the Organization: Define scope, interested parties, and internal/external issues
Clause 5 - Leadership: Top management commitment, information security policy, roles and responsibilities