isms-audit-expert
Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support. Use when planning ISMS audit programs, executing internal or external ISO 27001 audits, testing ISO 27002 Annex A controls, managing audit findings and corrective actions, or preparing for Stage 1/Stage 2 certification and surveillance audits.
What this skill does
# ISMS Audit Expert
Internal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.
---
## Audit Program Management
### Risk-Based Audit Schedule
| Risk Level | Audit Frequency | Examples |
|------------|-----------------|----------|
| Critical | Quarterly | Privileged access, vulnerability management, logging |
| High | Semi-annual | Access control, incident response, encryption |
| Medium | Annual | Policies, awareness training, physical security |
| Low | Annual | Documentation, asset inventory |
### Workflow: Annual Audit Planning
1. **Review prior audit results** -- analyze previous findings, open items, and risk assessment outputs from the most recent cycle.
2. **Identify high-risk controls** -- flag controls involved in recent security incidents or with outstanding nonconformities.
3. **Determine audit scope** -- define ISMS boundaries, confirm Statement of Applicability (SoA) coverage for the certification cycle.
4. **Assign auditors** -- ensure independence from audited areas; verify auditor competency (ISO 27001 Lead Auditor certification preferred).
5. **Create audit schedule** -- allocate resources, assign dates, and distribute across the year by risk priority.
6. **Obtain management approval** for the finalized audit plan.
7. **Validation checkpoint:** Audit plan covers all 93 Annex A controls within the certification cycle; schedule approved by management; auditor independence confirmed.
### Example: Annual Audit Plan Output
```
ISMS AUDIT PLAN 2026
Prepared by: Information Security Manager
Approved by: CISO
Date: 2026-01-15
Q1 2026 (January-March)
Scope: Privileged access (A.8.2, A.8.18), Logging (A.8.15, A.8.16)
Auditor: External consultant (independence required)
Risk level: Critical
Q2 2026 (April-June)
Scope: Access control (A.8.3-A.8.5), Incident response (A.5.24-A.5.28)
Auditor: Internal audit team
Risk level: High
Q3 2026 (July-September)
Scope: Physical security (A.7.1-A.7.14), HR security (A.6.1-A.6.8)
Auditor: Internal audit team
Risk level: Medium
Q4 2026 (October-December)
Scope: Policies (A.5.1-A.5.8), Asset management (A.5.9-A.5.14)
Auditor: Internal audit team
Risk level: Medium-Low
Coverage: 93/93 Annex A controls scheduled across 4 quarters
```
---
## Audit Execution
### Workflow: Pre-Audit Preparation
1. **Review ISMS documentation** -- policies, Statement of Applicability, risk assessment, and risk treatment plan.
2. **Analyze previous audit reports** -- note open findings and areas requiring follow-up.
3. **Prepare audit plan** -- define interview schedule, control sample, and evidence requirements.
4. **Notify auditees** -- communicate scope, timing, and documentation needed at least 2 weeks in advance.
5. **Prepare control-specific checklists** for all controls in scope.
6. **Validation checkpoint:** All documentation received and reviewed before the opening meeting.
### Workflow: Audit Conduct
1. **Opening Meeting** -- confirm scope, introduce audit team, agree on communication channels and logistics.
2. **Evidence Collection** -- interview control owners, review documentation and records, observe processes in operation, inspect technical configurations.
3. **Control Verification** -- test control design (does it address the risk?), test control operation (is it working as intended?), sample transactions and records, document all evidence.
4. **Closing Meeting** -- present preliminary findings, clarify factual inaccuracies, agree on finding classification, confirm corrective action timelines.
5. **Validation checkpoint:** All controls in scope assessed with documented evidence; findings classified and communicated.
### Evidence Collection Methods
| Method | Use Case | Example |
|--------|----------|---------|
| Inquiry | Process understanding | Interview Security Manager about incident response |
| Observation | Operational verification | Watch visitor sign-in process at reception |
| Inspection | Documentation review | Check access approval records for last quarter |
| Re-performance | Control testing | Attempt login with weak password to verify policy enforcement |
---
## Control Assessment
### ISO 27002 Control Categories
**Organizational Controls (A.5):** Information security policies, roles and responsibilities, segregation of duties, contact with authorities, threat intelligence, information security in projects.
**People Controls (A.6):** Screening and background checks, employment terms, security awareness and training, disciplinary process, remote working security.
**Physical Controls (A.7):** Physical security perimeters, entry controls, securing offices and facilities, physical security monitoring, equipment protection.
**Technological Controls (A.8):** User endpoint devices, privileged access rights, access restriction, secure authentication, malware protection, vulnerability management, backup and recovery, logging and monitoring, network security, cryptography.
### Workflow: Control Testing
1. **Identify control objective** from the relevant ISO 27002 clause.
2. **Determine testing method** -- inquiry, observation, inspection, or re-performance based on control type.
3. **Define sample size** -- base on population size and risk level (e.g., 25 samples for quarterly access reviews, 5 for annual policy reviews).
4. **Execute test** and document results with specific evidence references.
5. **Evaluate control effectiveness** -- effective, partially effective, or ineffective.
6. **Validation checkpoint:** Evidence supports conclusion; finding documented if control is not fully effective.
### Example: Control Test Working Paper
```
CONTROL TEST WORKING PAPER
Control: A.8.2 - Privileged access rights
Objective: Privileged access is restricted and managed
Test date: 2026-03-10
Auditor: J. Smith
Test procedure:
1. Obtained list of privileged accounts from IAM system (42 accounts)
2. Selected sample of 10 accounts (25% sample rate)
3. For each account, verified:
- Documented business justification exists
- Manager approval on file
- Quarterly access review completed
- No dormant accounts (last login within 90 days)
Results:
- 8/10 accounts: All criteria met (PASS)
- 1/10: Missing quarterly review for Q4 2025 (MINOR NC)
- 1/10: No documented business justification (MINOR NC)
Conclusion: Control partially effective - minor nonconformity raised
Finding reference: ISMS-2026-007
```
---
## Finding Management
### Finding Classification
| Severity | Definition | Response Time |
|----------|------------|---------------|
| Major Nonconformity | Control failure creating significant risk | 30 days |
| Minor Nonconformity | Isolated deviation with limited impact | 90 days |
| Observation | Improvement opportunity | Next audit cycle |
### Finding Documentation Template
```
Finding ID: ISMS-2026-007
Control Reference: A.8.2 - Privileged access rights
Severity: Minor Nonconformity
Evidence:
- 1 of 10 sampled privileged accounts missing Q4 2025 review
- 1 of 10 sampled accounts lacks documented business justification
- Screenshots of IAM records and review log exported 2026-03-10
Risk Impact:
- Unreviewed privileged access increases insider threat exposure
- Non-justified accounts may represent unnecessary attack surface
Root Cause:
- Access review process relies on manual tracking; no automated reminder
Recommendation:
- Implement automated quarterly review reminders via IAM platform
- Require business justification field as mandatory in provisioning workflow
- Backfill missing reviews within 14 days
```
### Workflow: Corrective Action
1. **Auditee acknowledges** finding and severity classification.
2. **Root cause analysis** completed within 10 business days.
3. **Corrective action plan** submitted with target dates and responsible owners.
4. **Actions implemented** by responsible parties per the plan.
5. **Auditor verifies effectiveness** --Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.