iso27001 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited iso27001 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Disclaimer: this skill supports technical and organizational implementation, not legal or certification advice. Final certification is an independent auditor's judgement; this skill helps you prepare but does not replace an accredited auditor.
ISO/IEC 27001:2022 is the international certifiable standard for an Information Security Management System (ISMS). The 2022 revision replaces 2013 with a revised Annex A (113 → 93 controls, regrouped into four themes). This skill helps with ISMS setup, control mapping, and Stage 1/Stage 2 audit preparation.
Triggers on:
nis2 or dora: both demand an ISMS and Annex A covers their technical-measures layer.soc2 context about mapping or dual-attestation strategy.soc2. Lots of overlap in controls, different audit model.risk-register. ISO 27001 demands risk management (Cl 6.1, 8.2-8.3); the methodology lives in that skill.policy-drafter.audit-evidence.Six phases. Phase 1 (scope) is the heaviest strategically; phases 3-4 (controls + risk) the heaviest operationally.
ISO 27001 Cl 4.3 demands a deliberately chosen ISMS scope. What sits inside the ISMS is audited and certified; what sits outside is not.
The out-of-scope argument must be defensible against an auditor. "Our R&D environment is out of scope because ..." — with a reason that is not Swiss-cheese.
Lock the scope down in a scope statement (documented information, Cl 4.3). One paragraph, publishable on your certificate.
The numbered chapters of the standard form the management system. Every clause demands documented information plus evidence of implementation.
Common gaps at Stage 2 audits: Cl 5.2 policy not visibly committed by top management, Cl 9.3 management review without evidence of the input items required, Cl 10 nonconformities register thin or missing.
ISO 27001:2022 Annex A groups controls into four themes:
Every control in A.5-A.8 has a control statement (what), purpose (why), and guidance (how). Guidance is not normative but strongly recommended for audit.
Risk assessment (Cl 6.1.2) requires:
See risk-register for methodology; ISO 27005 is the ISO-specific infosec risk-management standard that pairs with 27001.
Statement of Applicability (SoA) (Cl 6.1.3.d) is the central document: a list of all 93 Annex A controls with, per control:
The SoA is a living document. It changes on risk re-assessment, scope change, new threats. Versioning required.
Risk-treatment plan (Cl 6.1.3.e): per identified risk: chosen treatment (avoid/modify/share/retain — the ISO terms for avoid/mitigate/transfer/accept), Annex A controls applied, owner, deadline, status.
The external certification audit has two stages:
After certification:
Preparation discipline: an internal audit programme (Cl 9.2) plus management review (Cl 9.3) at least one cycle before Stage 2. Resolve internal-audit findings up front.
See audit-evidence for evidence packaging per control.
ISO 27001 is the foundation other frameworks build on:
Layer 1: scope statement unambiguous?, all 93 Annex A controls addressed in the SoA (yes/no)?, risk-treatment plan covers all above-tolerance risks?, internal-audit log complete for the cycle?. Layer 2: Annex A control numbers verified against the 2022 version (not 2013!), ISO clause references correct, NIS2/DORA mapping claims supported by ENISA documents or your own cross-walk, not improvised.
ISO 27001:2022 assessment — <entity/scope>
Goal: <certification Stage 1 | Stage 2 | surveillance | recertification | gap analysis without audit>
ISMS scope:
Organizational: <entity/unit/product>
Geographic: <locations>
Technological: <systems/clouds>
Interfaces: <mapped | gap>
Clauses 4-10 status:
Cl 4 Context: <complete | gaps: ...>
Cl 5 Leadership: ...
Cl 6 Planning: ...
Cl 7 Support: ...
Cl 8 Operation: ...
Cl 9 Performance: ...
Cl 10 Improvement: ...
Annex A 93 controls (SoA status):
A.5 Organizational: <N/37 implemented, N/37 partial, N/37 gap>
A.6 People: ...
A.7 Physical: ...
A.8 Technological: ...
Exclusions (not applicable): <N, rationale quality: strong/weak>
Risk management:
Methodology: <used + source>
Risk-treatment plan: <coverage, owners>
SoA version + date: <...>
Audit readiness:
Stage 1 ready: <yes/no with gaps>
Stage 2 ready: <yes/no with gaps>
Internal audit run: <date>
Management review: <date>
Mapping (optional):
NIS2 Art 21 coverage: <%>
SOC 2 TSC overlap: <summary>
Priorities:
<fix-now / fix-sprint / fix-quarter>
Verification-loop: ...~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.