{"id":"8aa7e3e7-e394-43f8-aca9-9472c5ab79b6","entityType":"agent","slug":"clawhub-skills-alirezarezvani-isms-audit-expert","name":"isms-audit-expert","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-alirezarezvani-isms-audit-expert","canonicalPath":"/agent/clawhub-skills-alirezarezvani-isms-audit-expert","generatedAt":"2026-10-09T17:08:30.538Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support --- name: isms-audit-expert description: Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support triggers: - ISMS audit - ISO 27001 audit - security audit - internal audit ISO 27001 - security control assessment - certification audit - surveillance audit - audit finding - nonconformity --- ISMS Audit Expert Internal and external ISMS audit manag","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:alirezarezvani:isms-audit-expert","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/alirezarezvani/isms-audit-expert","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/alirezarezvani/isms-audit-expert","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support --- name: isms-audit-expert des"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"conclusion","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":2,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"conclusion","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:conclusion|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T05:59:25.155Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T05:59:25.155Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T05:59:25.155Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:alirezarezvani:isms-audit-expert","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T17:08:30.538Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-alirezarezvani-isms-audit-expert/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: isms-audit-expert\ndescription: Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support\ntriggers:\n  - ISMS audit\n  - ISO 27001 audit\n  - security audit\n  - internal audit ISO 27001\n  - security control assessment\n  - certification audit\n  - surveillance audit\n  - audit finding\n  - nonconformity\n---\n\n# ISMS Audit Expert\n\nInternal and external ISMS audit management for ISO 27001 compliance verification, security control assessment, and certification support.\n\n## Table of Contents\n\n- [Audit Program Management](#audit-program-management)\n- [Audit Execution](#audit-execution)\n- [Control Assessment](#control-assessment)\n- [Finding Management](#finding-management)\n- [Certification Support](#certification-support)\n- [Tools](#tools)\n- [References](#references)\n\n---\n\n## Audit Program Management\n\n### Risk-Based Audit Schedule\n\n| Risk Level | Audit Frequency | Examples |\n|------------|-----------------|----------|\n| Critical | Quarterly | Privileged access, vulnerability management, logging |\n| High | Semi-annual | Access control, incident response, encryption |\n| Medium | Annual | Policies, awareness training, physical security |\n| Low | Annual | Documentation, asset inventory |\n\n### Annual Audit Planning Workflow\n\n1. Review previous audit findings and risk assessment results\n2. Identify high-risk controls and recent security incidents\n3. Determine audit scope based on ISMS boundaries\n4. Assign auditors ensuring independence from audited areas\n5. Create audit schedule with resource allocation\n6. Obtain management approval for audit plan\n7. **Validation:** Audit plan covers all Annex A controls within certification cycle\n\n### Auditor Competency Requirements\n\n- ISO 27001 Lead Auditor certification (preferred)\n- No operational responsibility for audited processes\n- Understanding of technical security controls\n- Knowledge of applicable regulations (GDPR, HIPAA)\n\n---\n\n## Audit Execution\n\n### Pre-Audit Preparation\n\n1. Review ISMS documentation (policies, SoA, risk assessment)\n2. Analyze previous audit reports and open findings\n3. Prepare audit plan with interview schedule\n4. Notify auditees of audit scope and timing\n5. Prepare checklists for controls in scope\n6. **Validation:** All documentation received and reviewed before opening meeting\n\n### Audit Conduct Steps\n\n1. **Opening Meeting**\n   - Confirm audit scope and objectives\n   - Introduce audit team and methodology\n   - Agree on communication channels and logistics\n\n2. **Evidence Collection**\n   - Interview control owners and operators\n   - Review documentation and records\n   - Observe processes in operation\n   - Inspect technical configurations\n\n3. **Control Verification**\n   - Test control design (does it address the risk?)\n   - Test control operation (is it working as intended?)\n   - Sample transactions and records\n   - Document all evidence collected\n\n4. **Closing Meeting**\n   - Present preliminary findings\n   - Clarify any factual inaccuracies\n   - Agree on finding classification\n   - Confirm corrective action timelines\n\n5. **Validation:** All controls in scope assessed with documented evidence\n\n### Evidence Collection Methods\n\n| Method | Use Case | Example |\n|--------|----------|---------|\n| Inquiry | Process understanding | Interview Security Manager about incident response |\n| Observation | Operational verification | Watch visitor sign-in process |\n| Inspection | Documentation review | Check access approval records |\n| Re-performance | Control testing | Attempt login with weak password |\n\n---\n\n## Control Assessment\n\n### ISO 27002 Control Categories\n\n**Organizational Controls (A.5):**\n- Information security policies\n- Roles and responsibilities\n- Segregation of duties\n- Contact with authorities\n- Threat intelligence\n- Information security in projects\n\n**People Controls (A.6):**\n- Screening and background checks\n- Employment terms and conditions\n- Security awareness and training\n- Disciplinary process\n- Remote working security\n\n**Physical Controls (A.7):**\n- Physical security perimeters\n- Physical entry controls\n- Securing offices and facilities\n- Physical security monitoring\n- Equipment protection\n\n**Technological Controls (A.8):**\n- User endpoint devices\n- Privileged access rights\n- Access restriction\n- Secure authentication\n- Malware protection\n- Vulnerability management\n- Backup and recovery\n- Logging and monitoring\n- Network security\n- Cryptography\n\n### Control Testing Approach\n\n1. Identify control objective from ISO 27002\n2. Determine testing method (inquiry, observation, inspection, re-performance)\n3. Define sample size based on population and risk\n4. Execute test and document results\n5. Evaluate control effectiveness\n6. **Validation:** Evidence supports conclusion about control status\n\n---\n\n## Finding Management\n\n### Finding Classification\n\n| Severity | Definition | Response Time |\n|----------|------------|---------------|\n| Major Nonconformity | Control failure creating significant risk | 30 days |\n| Minor Nonconformity | Isolated deviation with limited impact | 90 days |\n| Observation | Improvement opportunity | Next audit cycle |\n\n### Finding Documentation Template\n\n```\nFinding ID: ISMS-[YEAR]-[NUMBER]\nControl Reference: A.X.X - [Control Name]\nSeverity: [Major/Minor/Observation]\n\nEvidence:\n- [Specific evidence observed]\n- [Records reviewed]\n- [Interview statements]\n\nRisk Impact:\n- [Potential consequences if not addressed]\n\nRoot Cause:\n- [Why the nonconformity occurred]\n\nRecommendation:\n- [Specific corrective action steps]\n```\n\n### Corrective Action Workflow\n\n1. Auditee acknowledges finding and severity\n2. Root cause analysis completed within 10 days\n3. Corrective action plan submitted with target dates\n4. Actions implemented by responsible parties\n5. Auditor verifies effectiveness of corrections\n6. Finding closed with evidence of resolution\n7. **Validation:** Root cause addressed, recurrence prevented\n\n---\n\n## Certification Support\n\n### Stage 1 Audit Preparation\n\nEnsure documentation is complete:\n- [ ] ISMS scope statement\n- [ ] Information security policy (management signed)\n- [ ] Statement of Applicability\n- [ ] Risk assessment methodology and results\n- [ ] Risk treatment plan\n- [ ] Internal audit results (past 12 months)\n- [ ] Management review minutes\n\n### Stage 2 Audit Preparation\n\nVerify operational readiness:\n- [ ] All Stage 1 findings addressed\n- [ ] ISMS operational for minimum 3 months\n- [ ] Evidence of control implementation\n- [ ] Security awareness training records\n- [ ] Incident response evidence (if applicable)\n- [ ] Access review documentation\n\n### Surveillance Audit Cycle\n\n| Period | Focus |\n|--------|-------|\n| Year 1, Q2 | High-risk controls, Stage 2 findings follow-up |\n| Year 1, Q4 | Continual improvement, control sample |\n| Year 2, Q2 | Full surveillance |\n| Year 2, Q4 | Re-certification preparation |\n\n**Validation:** No major nonconformities at surveillance audits.\n\n---\n\n## Tools\n\n### scripts/\n\n| Script | Purpose | Usage |\n|--------|---------|-------|\n| `isms_audit_scheduler.py` | Generate risk-based audit plans | `python scripts/isms_audit_scheduler.py --year 2025 --format markdown` |\n\n### Audit Planning Example\n\n```bash\n# Generate annual audit plan\npython scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json\n\n# With custom control risk ratings\npython scripts/isms_audit_scheduler.py --controls controls.csv --format markdown\n```\n\n---\n\n## References\n\n| File | Content |\n|------|---------|\n| [iso27001-audit-methodology.md](references/iso27001-audit-methodology.md) | Audit program structure, pre-audit phase, certification support |\n| [security-control-testing.md](references/security-control-testing.md) | Technical verification procedures for ISO 27002 controls |\n| [cloud-security-audit.md](references/cloud-security-audit.md) | Cloud provider assessment, configuration security, IAM review |\n\n---\n\n## Audit Performance Metrics\n\n| KPI | Target | Measurement |\n|-----|--------|-------------|\n| Audit plan completion | 100% | Audits completed vs. planned |\n| Finding closure rate | >90% within SLA | Closed on time vs. total |\n| Major nonconformities | 0 at certification | Count per certification cycle |\n| Audit effectiveness | Incidents prevented | Security improvements implemented |\n\n---\n\n## Compliance Framework Integration\n\n| Framework | ISMS Audit Relevance |\n|-----------|---------------------|\n| GDPR | A.5.34 Privacy, A.8.10 Information deletion |\n| HIPAA | Access controls, audit logging, encryption |\n| PCI DSS | Network security, access control, monitoring |\n| SOC 2 | Trust Services Criteria mapped to ISO 27002 |\n","readmeExcerpt":"--- name: isms-audit-expert description: Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support triggers: - ISMS audit - ISO 27001 audit - security audit - internal audit ISO 27001 - security control assessment - certification audit - surveillance audit - audit finding - nonconformity --- ISMS Audit Expert Internal and external ISMS audit manag","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Finding ID: ISMS-[YEAR]-[NUMBER]\nControl Reference: A.X.X - [Control Name]\nSeverity: [Major/Minor/Observation]\n\nEvidence:\n- [Specific evidence observed]\n- [Records reviewed]\n- [Interview statements]\n\nRisk Impact:\n- [Potential consequences if not addressed]\n\nRoot Cause:\n- [Why the nonconformity occurred]\n\nRecommendation:\n- [Specific corrective action steps]"},{"language":"bash","snippet":"# Generate annual audit plan\npython scripts/isms_audit_scheduler.py --year 2025 --output audit_plan.json\n\n# With custom control risk ratings\npython scripts/isms_audit_scheduler.py --controls controls.csv --format markdown"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support --- name: isms-audit-expert description: Information Security Management System auditing for ISO 27001 compliance, security control assessment, and certification support triggers: - ISMS audit - ISO 27001 audit - security audit - internal audit ISO 27001 - security control assessment - certification audit - surveillance audit - audit finding - nonconformity --- ISMS Audit Expert Internal and external ISMS audit manag","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":376,"uniquenessScore":61,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T17:08:30.538Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}