Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Scope an ISO 27001 ISMS and build the Statement of Applicability across Annex A controls. Use when asked to implement ISO 27001, scope an ISMS, build a Statement of Applicability (SoA), or prepare for ISO 27001 certification. Produces an ISMS plan — scope & context, risk-treatment approach, an Annex A control applicability table (the SoA), and a prioritised implementation roadmap.
.claude/skills/mohitagw15856-iso-27001-isms/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-03 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 8% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 25% | 0% |
| case-05 | ✓→✓ | = Same ✓ | 11% | 0% |
ISO 27001 certifies a system (the ISMS), not a checklist — auditors check that you scoped it, assessed risk, and can justify which Annex A controls you applied or excluded (the Statement of Applicability). This skill builds that backbone: scope, risk treatment, and a defensible SoA, so certification is a documented management system rather than a scramble.
Ask for these only if they aren't already provided:
1. Scope statement — the boundary of the ISMS: assets, locations, exclusions and why.
2. Context & risk — interested parties and their requirements; the risk assessment method and risk acceptance criteria.
3. Statement of Applicability (SoA) — the heart of it: each Annex A control, applicable or not, status, and justification:
| Annex A control | Applicable? | Status | Justification | |---|---|---|---| | A.5 Access control policy | Yes | met | Required for customer data | | A.8 Teleworking | No | n/a | No remote-access to in-scope systems — excluded with rationale |
(Excluding a control is fine — excluding it without a justification is an audit finding.)
4. Risk treatment plan — the top risks, the treatment (mitigate/accept/transfer/avoid), and the controls that address each.
5. Implementation roadmap — prioritised: mandatory clauses 4–10 (management system) first, then the highest-risk Annex A gaps, with owners and dates.
scripts/soa_coverage.py (stdlib only) scores SoA coverage and flags controls excluded without a justification (the classic finding):
bash# soa.json: [{"control":"A.5.1","applicable":true,"status":"met|partial|gap","justification":"..."}, ...] python3 scripts/soa_coverage.py soa.json python3 scripts/soa_coverage.py soa.json --json
ISO/IEC 27001 (ISMS clauses 4–10) and Annex A control set + the Statement of Applicability requirement.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 29,797 | 24,035 | -19% | 1 | 1 | 0% | 6,261 | 5,536 | -12% | 0 | 0 | — |
case-02 | fail→fail | 30,671 | 33,840 | +10% | 1 | 1 | 0% | 6,248 | 7,082 | +13% | 0 | 0 | — |
case-03 | fail→pass | 31,391 | 26,556 | -15% | 1 | 1 | 0% | 6,241 | 5,463 | -12% | 0 | 0 | — |
case-04 | pass→pass | 15,868 | 14,681 | -7% | 1 | 1 | 0% | 2,986 | 3,743 | +25% | 0 | 0 | — |
case-05 | pass→pass | 18,933 | 15,760 | -17% | 1 | 1 | 0% | 3,326 | 3,687 | +11% | 0 | 0 | — |
case-06 | fail→fail | 19,859 | 20,627 | +4% | 1 | 1 | 0% | 3,511 | 4,601 | +31% | 0 | 0 | — |
case-07 | pass→pass | 12,755 | 19,458 | +53% | 1 | 1 | 0% | 2,145 | 4,173 | +95% | 0 | 0 | — |
case-08 | pass→pass | 16,713 | 16,344 | -2% | 1 | 1 | 0% | 2,768 | 3,783 | +37% | 0 | 0 | — |
case-09 | pass→pass | 13,814 | 17,520 | +27% | 1 | 1 | 0% | 2,684 | 3,829 | +43% | 0 | 0 | — |
case-10 | pass→pass | 19,156 | 15,481 | -19% | 1 | 1 | 0% | 3,651 | 3,935 | +8% | 0 | 0 | — |
case-11 | pass→pass | 23,928 | 21,101 | -12% | 1 | 1 | 0% | 4,250 | 4,624 | +9% | 0 | 0 | — |
case-12 | pass→pass | 27,061 | 18,391 | -32% | 1 | 1 | 0% | 4,986 | 4,162 | -17% | 0 | 0 | — |
case-13 | pass→pass | 12,187 | 12,226 | +0% | 1 | 1 | 0% | 2,199 | 3,078 | +40% | 0 | 0 | — |
case-14 | pass→pass | 17,365 | 15,427 | -11% | 1 | 1 | 0% | 3,288 | 3,590 | +9% | 0 | 0 | — |
case-15 | pass→pass | 22,258 | 14,050 | -37% | 1 | 1 | 0% | 4,163 | 3,668 | -12% | 0 | 0 | — |
case-16 | pass→pass | 12,991 | 14,478 | +11% | 1 | 1 | 0% | 2,887 | 4,100 | +42% | 0 | 0 | — |
case-17 | pass→pass | 16,092 | 15,570 | -3% | 1 | 1 | 0% | 2,873 | 3,838 | +34% | 0 | 0 | — |
case-22 | fail→fail | 32,750 | 23,156 | -29% | 1 | 1 | 0% | 6,191 | 5,332 | -14% | 0 | 0 | — |
case-18 | pass→pass | 11,614 | 16,206 | +40% | 1 | 1 | 0% | 2,176 | 3,795 | +74% | 0 | 0 | — |
case-19 | pass→pass | 15,222 | 16,091 | +6% | 1 | 1 | 0% | 2,873 | 3,763 | +31% | 0 | 0 | — |
case-20 | pass→pass | 7,715 | 6,997 | -9% | 1 | 1 | 0% | 1,441 | 2,250 | +56% | 0 | 0 | — |
case-21 | fail→pass | 19,045 | 16,065 | -16% | 1 | 1 | 0% | 3,630 | 3,924 | +8% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.