iso-27001-internal-auditRun an ISO 27001 internal audit. Walk through controls by domain, identify gaps, collect evidence, and generate findings with corrective action recommendatio...
Install via ClawdBot CLI:
clawdbot install stevenobiajulu/iso-27001-internal-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://internalisoaudit.comAudited Apr 21, 2026 · audit v1.0
Generated May 21, 2026
A startup prepares for its ISO 27001 certification audit by running an internal audit 6 weeks prior. Uses the skill to scope controls, assess ISMS clauses, and collect evidence, ensuring gaps are fixed before the external auditor arrives.
An ISMS manager conducts quarterly internal audits to meet best-practice frequency. The skill guides assessment of 48 priority controls, with focus on critical tier controls like access management and incident response, producing findings and corrective actions.
After a security incident, a CISO uses the skill to assess whether relevant controls (e.g., A.8.12 logging, A.5.24 incident management) failed. The skill helps identify root causes and recommend corrective actions to prevent recurrence.
An organization adopting SOC 2 Type II uses the skill to map existing ISO 27001 controls to SOC 2 trust criteria. The skill's decision tree and domain tables simplify scoping and evidence collection for overlapping requirements.
A cloud-native startup validates that its cloud provider's SOC 2 covers physical controls (A.7 domain). The skill's startup scoping logic marks physical controls as satisfied by provider evidence, allowing focus on user endpoint security and supplier agreements.
Subscription-based software service needing ISO 27001 certification to close enterprise deals. The skill helps the lean compliance team conduct internal audits without a full-time auditor, reducing certification cost.
Provides outsourced ISMS audit services to multiple clients. Uses the skill as a standardized audit workflow for each client engagement, ensuring consistent coverage and evidence collection across diverse environments.
Non-profit foundation managing community projects with compliance requirements. The skill enables a lightweight internal audit process focused on essential controls, with minimal overhead and no licensing costs.
💬 Integration Tip
Pair with a compliance MCP server for live control dashboards; otherwise use the embedded reference files. Automate evidence collection by integrating with your existing monitoring and ticketing systems.
Scored May 21, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Helps verify that skill updates publish an auditable record of what changed — catching the gap between "the registry shows the new version" and "anyone can s...
Project health and best practices enforcer. Checks security, quality, documentation, CI/CD, and dependencies. Produces a letter grade (A-F) with actionable f...