Back to skills
Regulatory & Quality

Isms Audit Expert

Isms Audit Expert: Review an information security management system. Review the ISMS scope, controls, risk treatment, policies, and evidence and produce an ISMS audit report with traceable findings.

---
name: ra-qm-team-isms-audit-expert
description: Use for isms audit expert when asked to review an information security management system; produce an ISMS audit report with traceable findings.
license: MIT
metadata:
  author: Thrive
  category: ra-qm-team
---

# Isms Audit Expert

## When to use

Use this skill for isms audit expert when you need to review an information security management system. The expected result is an ISMS audit report with traceable findings.

## Boundaries

Work within the requested task and its stated acceptance criteria. Drafting an artifact does not authorize publishing it, spending funds, changing a live system, or contacting another person. Identify any such action separately before taking it.

## Inputs

Inspect the ISMS scope, controls, risk treatment, policies, and evidence. Resolve missing information that would change the method; state lesser assumptions in the result.

## Method

1. **Diagnose.** Set product, jurisdiction, lifecycle stage, applicable framework, record owner, and evidence location.
2. **Decide.** Map each audit question to a control owner and operating proof.
3. **Produce.** Build an ISMS audit report with traceable findings from the inspected material; keep assumptions distinguishable from observed facts.

## Decision rules

- Trace each requirement to the risk it controls and the documented proof that the control works. Mark missing or outdated evidence.
- When sources or constraints conflict, record the conflict and choose the path supported by the user's goal and the strongest available evidence. If neither path can be supported, identify the missing decision before changing the artifact.

## Domain rules

- Preserve traceability between requirement, risk, control, and validation evidence.
- Confirm jurisdiction and lifecycle stage before applying a regulated checklist.

## Verification

Confirm current ISO 27001 requirements and document exceptions. Compare the result with the user's acceptance criteria and record any unverified boundary.

Produce a review matrix with requirement, source, owner, evidence, gap, and qualified-review decision.

## Evidence and stop conditions

- Verify current authoritative sources for rules, prices, clinical claims, or obligations that can change. Distinguish fact, interpretation, and assumption.
- Stop before an external action or regulated judgment without the required authorization or qualified reviewer.
- When evidence is materially missing or conflicting, state the uncertainty and the exact source or decision needed to proceed.

## Stop conditions

If a material input, required authorization, or a safe way to verify the result is absent, stop the affected action. Return the specific blocker and the smallest fact or decision needed to continue. Do not report an unrun check as passed.

## Output

Provide an ISMS audit report with traceable findings. Include the decisive evidence and actual verification result. Name any artifact location and unresolved issue that affects its use.

<!--
MIT License

Copyright (c) 2026 Thrive

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
-->