Information security manager iso27001

ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies.

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/information-security-manager-iso27001, including the files SKILL.md points to.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit alirezarezvani/claude-skills/ra-qm-team/skills/information-security-manager-iso27001#main ~/.claude/skills/information-security-manager-iso27001

For one project only, change the path to .claude/skills/information-security-manager-iso27001. This skill also uses risk_register.json, gaps.md, risk_assessment.py, risks.json, compliance_checker.py, compliance_report.md — copying SKILL.md alone won't be enough. See the folder on GitHub.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Information security manager iso27001

Show the full text420 lines
namedescription
information-security-manager-iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.

Information Security Manager - ISO 27001

Implement and manage Information Security Management Systems (ISMS) aligned with ISO 27001:2022 and healthcare regulatory requirements.


Table of Contents


Trigger Phrases

Use this skill when you hear:

  • "implement ISO 27001"
  • "ISMS implementation"
  • "security risk assessment"
  • "information security policy"
  • "ISO 27001 certification"
  • "security controls implementation"
  • "incident response plan"
  • "healthcare data security"
  • "medical device cybersecurity"
  • "security compliance audit"

Quick Start

Run Security Risk Assessment
python scripts/risk_assessment.py --scope "patient-data-system" --output risk_register.json
Check Compliance Status
python scripts/compliance_checker.py --standard iso27001 --controls-file controls.csv
Generate Gap Analysis Report
python scripts/compliance_checker.py --standard iso27001 --gap-analysis --output gaps.md

Tools

risk_assessment.py

Automated security risk assessment following ISO 27001 Clause 6.1.2 methodology.

Usage:

# Full risk assessment
python scripts/risk_assessment.py --scope "cloud-infrastructure" --output risks.json

# Healthcare-specific assessment
python scripts/risk_assessment.py --scope "ehr-system" --template healthcare --output risks.json

# Quick asset-based assessment
python scripts/risk_assessment.py --assets assets.csv --output risks.json

Parameters:

Parameter Required Description
--scope Yes System or area to assess
--template No Assessment template: general, healthcare, cloud
--assets No CSV file with asset inventory
--output No Output file (default: stdout)
--format No Output format: json, csv, markdown

Output:

  • Asset inventory with classification
  • Threat and vulnerability mapping
  • Risk scores (likelihood × impact)
  • Treatment recommendations
  • Residual risk calculations
compliance_checker.py

Verify ISO 27001/27002 control implementation status.

Usage:

# Check all ISO 27001 controls
python scripts/compliance_checker.py --standard iso27001

# Gap analysis with recommendations
python scripts/compliance_checker.py --standard iso27001 --gap-analysis

# Check specific control domains
python scripts/compliance_checker.py --standard iso27001 --domains "access-control,cryptography"

# Export compliance report
python scripts/compliance_checker.py --standard iso27001 --output compliance_report.md

Parameters:

Parameter Required Description
--standard Yes Standard to check: iso27001, iso27002, hipaa
--controls-file No CSV with current control status
--gap-analysis No Include remediation recommendations
--domains No Specific control domains to check
--output No Output file path

Output:

  • Control implementation status
  • Compliance percentage by domain
  • Gap analysis with priorities
  • Remediation recommendations

Workflows

Workflow 1: ISMS Implementation

Step 1: Define Scope and Context

Document organizational context and ISMS boundaries:

  • Identify interested parties and requirements
  • Define ISMS scope and boundaries
  • Document internal/external issues

Validation: Scope statement reviewed and approved by management.

Step 2: Conduct Risk Assessment

python scripts/risk_assessment.py --scope "full-organization" --template general --output initial_risks.json
  • Identify information assets
  • Assess threats and vulnerabilities
  • Calculate risk levels
  • Determine risk treatment options

Validation: Risk register contains all critical assets with assigned owners.

Step 3: Select and Implement Controls

Map risks to ISO 27002 controls:

python scripts/compliance_checker.py --standard iso27002 --gap-analysis --output control_gaps.md

Control categories:

  • Organizational (policies, roles, responsibilities)
  • People (screening, awareness, training)
  • Physical (perimeters, equipment, media)
  • Technological (access, crypto, network, application)

Validation: Statement of Applicability (SoA) documents all controls with justification.

Step 4: Establish Monitoring

Define security metrics:

  • Incident count and severity trends
  • Control effectiveness scores
  • Training completion rates
  • Audit findings closure rate

Validation: Dashboard shows real-time compliance status.

Workflow 2: Security Risk Assessment

Step 1: Asset Identification

Create asset inventory:

Asset Type Examples Classification
Information Patient records, source code Confidential
Software EHR system, APIs Critical
Hardware Servers, medical devices High
Services Cloud hosting, backup High
People Admin accounts, developers Varies

Validation: All assets have assigned owners and classifications.

Step 2: Threat Analysis

Identify threats per asset category:

Asset Threats Likelihood
Patient data Unauthorized access, breach High
Medical devices Malware, tampering Medium
Cloud services Misconfiguration, outage Medium
Credentials Phishing, brute force High

Validation: Threat model covers top-10 industry threats.

Step 3: Vulnerability Assessment

python scripts/risk_assessment.py --scope "network-infrastructure" --output vuln_risks.json

Document vulnerabilities:

  • Technical (unpatched systems, weak configs)
  • Process (missing procedures, gaps)
  • People (lack of training, insider risk)

Validation: Vulnerability scan results mapped to risk register.

Step 4: Risk Evaluation and Treatment

Calculate risk: Risk = Likelihood × Impact

Risk Level Score Treatment
Critical 20-25 Immediate action required
High 15-19 Treatment plan within 30 days
Medium 10-14 Treatment plan within 90 days
Low 5-9 Accept or monitor
Minimal 1-4 Accept

Validation: All high/critical risks have approved treatment plans.

Workflow 3: Incident Response

Step 1: Detection and Reporting

Incident categories:

  • Security breach (unauthorized access)
  • Malware infection
  • Data leakage
  • System compromise
  • Policy violation

Validation: Incident logged within 15 minutes of detection.

Step 2: Triage and Classification

Severity Criteria Response Time
Critical Data breach, system down Immediate
High Active threat, significant risk 1 hour
Medium Contained threat, limited impact 4 hours
Low Minor violation, no impact 24 hours

Validation: Severity assigned and escalation triggered if needed.

Step 3: Containment and Eradication

Immediate actions:

  1. Isolate affected systems
  2. Preserve evidence
  3. Block threat vectors
  4. Remove malicious artifacts

Validation: Containment confirmed, no ongoing compromise.

Step 4: Recovery and Lessons Learned

Post-incident activities:

  1. Restore systems from clean backups
  2. Verify integrity before reconnection
  3. Document timeline and actions
  4. Conduct post-incident review
  5. Update controls and procedures

Validation: Post-incident report completed within 5 business days.


Reference Guides

When to Use Each Reference

references/iso27001-controls.md

  • Control selection for SoA
  • Implementation guidance
  • Evidence requirements
  • Audit preparation

references/risk-assessment-guide.md

  • Risk methodology selection
  • Asset classification criteria
  • Threat modeling approaches
  • Risk calculation methods

references/incident-response.md

  • Response procedures
  • Escalation matrices
  • Communication templates
  • Recovery checklists

Validation Checkpoints

ISMS Implementation Validation
Phase Checkpoint Evidence Required
Scope Scope approved Signed scope document
Risk Register complete Risk register with owners
Controls SoA approved Statement of Applicability
Operation Metrics active Dashboard screenshots
Audit Internal audit done Audit report
Certification Readiness

Before Stage 1 audit:

  • ISMS scope documented and approved
  • Information security policy published
  • Risk assessment completed
  • Statement of Applicability finalized
  • Internal audit conducted
  • Management review completed
  • Nonconformities addressed

Before Stage 2 audit:

  • Controls implemented and operational
  • Evidence of effectiveness available
  • Staff trained and aware
  • Incidents logged and managed
  • Metrics collected for 3+ months
Compliance Verification

Run periodic checks:

# Monthly compliance check
python scripts/compliance_checker.py --standard iso27001 --output monthly_$(date +%Y%m).md

# Quarterly gap analysis
python scripts/compliance_checker.py --standard iso27001 --gap-analysis --output quarterly_gaps.md

Worked Example: Healthcare Risk Assessment

Scenario: Assess security risks for a patient data management system.

Step 1: Define Assets
python scripts/risk_assessment.py --scope "patient-data-system" --template healthcare

Asset inventory output:

Asset ID Asset Type Owner Classification
A001 Patient database Information DBA Team Confidential
A002 EHR application Software App Team Critical
A003 Database server Hardware Infra Team High
A004 Admin credentials Access Security Critical
Step 2: Identify Risks

Risk register output:

Risk ID Asset Threat Vulnerability L I Score
R001 A001 Data breach Weak encryption 3 5 15
R002 A002 SQL injection Input validation 4 4 16
R003 A004 Credential theft No MFA 4 5 20
Step 3: Determine Treatment
Risk Treatment Control Timeline
R001 Mitigate Implement AES-256 encryption 30 days
R002 Mitigate Add input validation, WAF 14 days
R003 Mitigate Enforce MFA for all admins 7 days
Step 4: Verify Implementation
python scripts/compliance_checker.py --controls-file implemented_controls.csv

Verification output:

Control Implementation Status
=============================
Cryptography (A.8.24): IMPLEMENTED
  - AES-256 at rest: YES
  - TLS 1.3 in transit: YES

Access Control (A.8.5): IMPLEMENTED
  - MFA enabled: YES
  - Admin accounts: 100% coverage

Application Security (A.8.26): PARTIAL
  - Input validation: YES
  - WAF deployed: PENDING

Overall Compliance: 87%
1---
2name: "information-security-manager-iso27001"
3description: ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use when designing an ISMS, running security risk assessments, implementing controls, pursuing ISO 27001 certification, preparing security audits, responding to security incidents, or verifying compliance. Covers ISO 27001, ISO 27002, healthcare security, and medical device cybersecurity.
4---
5 
6# Information Security Manager - ISO 27001
7 
8Implement and manage Information Security Management Systems (ISMS) aligned with ISO 27001:2022 and healthcare regulatory requirements.
9 
10---
11 
12## Table of Contents
13 
14- [Trigger Phrases](#trigger-phrases)
15- [Quick Start](#quick-start)
16- [Tools](#tools)
17- [Workflows](#workflows)
18- [Reference Guides](#reference-guides)
19- [Validation Checkpoints](#validation-checkpoints)
20 
21---
22 
23## Trigger Phrases
24 
25Use this skill when you hear:
26- "implement ISO 27001"
27- "ISMS implementation"
28- "security risk assessment"
29- "information security policy"
30- "ISO 27001 certification"
31- "security controls implementation"
32- "incident response plan"
33- "healthcare data security"
34- "medical device cybersecurity"
35- "security compliance audit"
36 
37---
38 
39## Quick Start
40 
41### Run Security Risk Assessment
42 
43```bash
44python scripts/risk_assessment.py --scope "patient-data-system" --output risk_register.json
45```
46 
47### Check Compliance Status
48 
49```bash
50python scripts/compliance_checker.py --standard iso27001 --controls-file controls.csv
51```
52 
53### Generate Gap Analysis Report
54 
55```bash
56python scripts/compliance_checker.py --standard iso27001 --gap-analysis --output gaps.md
57```
58 
59---
60 
61## Tools
62 
63### risk_assessment.py
64 
65Automated security risk assessment following ISO 27001 Clause 6.1.2 methodology.
66 
67**Usage:**
68 
69```bash
70# Full risk assessment
71python scripts/risk_assessment.py --scope "cloud-infrastructure" --output risks.json
72 
73# Healthcare-specific assessment
74python scripts/risk_assessment.py --scope "ehr-system" --template healthcare --output risks.json
75 
76# Quick asset-based assessment
77python scripts/risk_assessment.py --assets assets.csv --output risks.json
78```
79 
80**Parameters:**
81 
82| Parameter | Required | Description |
83|-----------|----------|-------------|
84| `--scope` | Yes | System or area to assess |
85| `--template` | No | Assessment template: `general`, `healthcare`, `cloud` |
86| `--assets` | No | CSV file with asset inventory |
87| `--output` | No | Output file (default: stdout) |
88| `--format` | No | Output format: `json`, `csv`, `markdown` |
89 
90**Output:**
91- Asset inventory with classification
92- Threat and vulnerability mapping
93- Risk scores (likelihood × impact)
94- Treatment recommendations
95- Residual risk calculations
96 
97### compliance_checker.py
98 
99Verify ISO 27001/27002 control implementation status.
100 
101**Usage:**
102 
103```bash
104# Check all ISO 27001 controls
105python scripts/compliance_checker.py --standard iso27001
106 
107# Gap analysis with recommendations
108python scripts/compliance_checker.py --standard iso27001 --gap-analysis
109 
110# Check specific control domains
111python scripts/compliance_checker.py --standard iso27001 --domains "access-control,cryptography"
112 
113# Export compliance report
114python scripts/compliance_checker.py --standard iso27001 --output compliance_report.md
115```
116 
117**Parameters:**
118 
119| Parameter | Required | Description |
120|-----------|----------|-------------|
121| `--standard` | Yes | Standard to check: `iso27001`, `iso27002`, `hipaa` |
122| `--controls-file` | No | CSV with current control status |
123| `--gap-analysis` | No | Include remediation recommendations |
124| `--domains` | No | Specific control domains to check |
125| `--output` | No | Output file path |
126 
127**Output:**
128- Control implementation status
129- Compliance percentage by domain
130- Gap analysis with priorities
131- Remediation recommendations
132 
133---
134 
135## Workflows
136 
137### Workflow 1: ISMS Implementation
138 
139**Step 1: Define Scope and Context**
140 
141Document organizational context and ISMS boundaries:
142- Identify interested parties and requirements
143- Define ISMS scope and boundaries
144- Document internal/external issues
145 
146**Validation:** Scope statement reviewed and approved by management.
147 
148**Step 2: Conduct Risk Assessment**
149 
150```bash
151python scripts/risk_assessment.py --scope "full-organization" --template general --output initial_risks.json
152```
153 
154- Identify information assets
155- Assess threats and vulnerabilities
156- Calculate risk levels
157- Determine risk treatment options
158 
159**Validation:** Risk register contains all critical assets with assigned owners.
160 
161**Step 3: Select and Implement Controls**
162 
163Map risks to ISO 27002 controls:
164 
165```bash
166python scripts/compliance_checker.py --standard iso27002 --gap-analysis --output control_gaps.md
167```
168 
169Control categories:
170- Organizational (policies, roles, responsibilities)
171- People (screening, awareness, training)
172- Physical (perimeters, equipment, media)
173- Technological (access, crypto, network, application)
174 
175**Validation:** Statement of Applicability (SoA) documents all controls with justification.
176 
177**Step 4: Establish Monitoring**
178 
179Define security metrics:
180- Incident count and severity trends
181- Control effectiveness scores
182- Training completion rates
183- Audit findings closure rate
184 
185**Validation:** Dashboard shows real-time compliance status.
186 
187### Workflow 2: Security Risk Assessment
188 
189**Step 1: Asset Identification**
190 
191Create asset inventory:
192 
193| Asset Type | Examples | Classification |
194|------------|----------|----------------|
195| Information | Patient records, source code | Confidential |
196| Software | EHR system, APIs | Critical |
197| Hardware | Servers, medical devices | High |
198| Services | Cloud hosting, backup | High |
199| People | Admin accounts, developers | Varies |
200 
201**Validation:** All assets have assigned owners and classifications.
202 
203**Step 2: Threat Analysis**
204 
205Identify threats per asset category:
206 
207| Asset | Threats | Likelihood |
208|-------|---------|------------|
209| Patient data | Unauthorized access, breach | High |
210| Medical devices | Malware, tampering | Medium |
211| Cloud services | Misconfiguration, outage | Medium |
212| Credentials | Phishing, brute force | High |
213 
214**Validation:** Threat model covers top-10 industry threats.
215 
216**Step 3: Vulnerability Assessment**
217 
218```bash
219python scripts/risk_assessment.py --scope "network-infrastructure" --output vuln_risks.json
220```
221 
222Document vulnerabilities:
223- Technical (unpatched systems, weak configs)
224- Process (missing procedures, gaps)
225- People (lack of training, insider risk)
226 
227**Validation:** Vulnerability scan results mapped to risk register.
228 
229**Step 4: Risk Evaluation and Treatment**
230 
231Calculate risk: `Risk = Likelihood × Impact`
232 
233| Risk Level | Score | Treatment |
234|------------|-------|-----------|
235| Critical | 20-25 | Immediate action required |
236| High | 15-19 | Treatment plan within 30 days |
237| Medium | 10-14 | Treatment plan within 90 days |
238| Low | 5-9 | Accept or monitor |
239| Minimal | 1-4 | Accept |
240 
241**Validation:** All high/critical risks have approved treatment plans.
242 
243### Workflow 3: Incident Response
244 
245**Step 1: Detection and Reporting**
246 
247Incident categories:
248- Security breach (unauthorized access)
249- Malware infection
250- Data leakage
251- System compromise
252- Policy violation
253 
254**Validation:** Incident logged within 15 minutes of detection.
255 
256**Step 2: Triage and Classification**
257 
258| Severity | Criteria | Response Time |
259|----------|----------|---------------|
260| Critical | Data breach, system down | Immediate |
261| High | Active threat, significant risk | 1 hour |
262| Medium | Contained threat, limited impact | 4 hours |
263| Low | Minor violation, no impact | 24 hours |
264 
265**Validation:** Severity assigned and escalation triggered if needed.
266 
267**Step 3: Containment and Eradication**
268 
269Immediate actions:
2701. Isolate affected systems
2712. Preserve evidence
2723. Block threat vectors
2734. Remove malicious artifacts
274 
275**Validation:** Containment confirmed, no ongoing compromise.
276 
277**Step 4: Recovery and Lessons Learned**
278 
279Post-incident activities:
2801. Restore systems from clean backups
2812. Verify integrity before reconnection
2823. Document timeline and actions
2834. Conduct post-incident review
2845. Update controls and procedures
285 
286**Validation:** Post-incident report completed within 5 business days.
287 
288---
289 
290## Reference Guides
291 
292### When to Use Each Reference
293 
294**references/iso27001-controls.md**
295- Control selection for SoA
296- Implementation guidance
297- Evidence requirements
298- Audit preparation
299 
300**references/risk-assessment-guide.md**
301- Risk methodology selection
302- Asset classification criteria
303- Threat modeling approaches
304- Risk calculation methods
305 
306**references/incident-response.md**
307- Response procedures
308- Escalation matrices
309- Communication templates
310- Recovery checklists
311 
312---
313 
314## Validation Checkpoints
315 
316### ISMS Implementation Validation
317 
318| Phase | Checkpoint | Evidence Required |
319|-------|------------|-------------------|
320| Scope | Scope approved | Signed scope document |
321| Risk | Register complete | Risk register with owners |
322| Controls | SoA approved | Statement of Applicability |
323| Operation | Metrics active | Dashboard screenshots |
324| Audit | Internal audit done | Audit report |
325 
326### Certification Readiness
327 
328Before Stage 1 audit:
329- [ ] ISMS scope documented and approved
330- [ ] Information security policy published
331- [ ] Risk assessment completed
332- [ ] Statement of Applicability finalized
333- [ ] Internal audit conducted
334- [ ] Management review completed
335- [ ] Nonconformities addressed
336 
337Before Stage 2 audit:
338- [ ] Controls implemented and operational
339- [ ] Evidence of effectiveness available
340- [ ] Staff trained and aware
341- [ ] Incidents logged and managed
342- [ ] Metrics collected for 3+ months
343 
344### Compliance Verification
345 
346Run periodic checks:
347 
348```bash
349# Monthly compliance check
350python scripts/compliance_checker.py --standard iso27001 --output monthly_$(date +%Y%m).md
351 
352# Quarterly gap analysis
353python scripts/compliance_checker.py --standard iso27001 --gap-analysis --output quarterly_gaps.md
354```
355 
356---
357 
358## Worked Example: Healthcare Risk Assessment
359 
360**Scenario:** Assess security risks for a patient data management system.
361 
362### Step 1: Define Assets
363 
364```bash
365python scripts/risk_assessment.py --scope "patient-data-system" --template healthcare
366```
367 
368**Asset inventory output:**
369 
370| Asset ID | Asset | Type | Owner | Classification |
371|----------|-------|------|-------|----------------|
372| A001 | Patient database | Information | DBA Team | Confidential |
373| A002 | EHR application | Software | App Team | Critical |
374| A003 | Database server | Hardware | Infra Team | High |
375| A004 | Admin credentials | Access | Security | Critical |
376 
377### Step 2: Identify Risks
378 
379**Risk register output:**
380 
381| Risk ID | Asset | Threat | Vulnerability | L | I | Score |
382|---------|-------|--------|---------------|---|---|-------|
383| R001 | A001 | Data breach | Weak encryption | 3 | 5 | 15 |
384| R002 | A002 | SQL injection | Input validation | 4 | 4 | 16 |
385| R003 | A004 | Credential theft | No MFA | 4 | 5 | 20 |
386 
387### Step 3: Determine Treatment
388 
389| Risk | Treatment | Control | Timeline |
390|------|-----------|---------|----------|
391| R001 | Mitigate | Implement AES-256 encryption | 30 days |
392| R002 | Mitigate | Add input validation, WAF | 14 days |
393| R003 | Mitigate | Enforce MFA for all admins | 7 days |
394 
395### Step 4: Verify Implementation
396 
397```bash
398python scripts/compliance_checker.py --controls-file implemented_controls.csv
399```
400 
401**Verification output:**
402 
403```
404Control Implementation Status
405=============================
406Cryptography (A.8.24): IMPLEMENTED
407 - AES-256 at rest: YES
408 - TLS 1.3 in transit: YES
409 
410Access Control (A.8.5): IMPLEMENTED
411 - MFA enabled: YES
412 - Admin accounts: 100% coverage
413 
414Application Security (A.8.26): PARTIAL
415 - Input validation: YES
416 - WAF deployed: PENDING
417 
418Overall Compliance: 87%
419```
420 

Discussion

Alternatives

Also in SecuritySee all 533 in Development →