annex-review

Rate ISO 27001 Annex A controls and generate a Markdown RAG report.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill annex-review
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: annex-review
Source: https://github.com/gombing/ISO27001Agent/tree/main/annex-review
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill annex-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This capability enables consistent, auditable assessment of ISO 27001 Annex A controls by providing a structured framework to rate control implementation and generate an actionable Annex A RAG report.

Core Features & Use Cases

  • Load engagement context and scope from client engagement briefs.
  • Guide a step-by-step assessment across A.5–A.8 controls, capturing Green/Amber/Red ratings with gap notes.
  • Produce a consolidated Annex A RAG report with per-control details and an executive summary.

Quick Start

Run the annex-review skill to begin evaluating Annex A controls and generate the RAG report.

Frequently Asked Questions about annex-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess ISO 27001 Annex A controls and generate a RAG report?▼

Assess ISO 27001 Annex A controls by guiding a step-by-step evaluation across 11 control groups from A.5 to A.8, capturing Green/Amber/Red ratings and gap notes to produce a consolidated RAG report.

What is a RAG report for ISO 27001 Annex A?▼

A RAG report for ISO 27001 Annex A is a consolidated document rating control implementation status as Red, Amber, or Green. It includes per-control details, gap notes, and a synthesized executive summary for actionable audit reporting.

How do I rate ISO 27001 Annex A control implementation status?▼

Rate ISO 27001 Annex A control implementation status by stepping through 11 control groups via interactive prompts, assigning a Green, Amber, or Red rating and documenting gap notes for each individual control.

Does the ISO 27001 Annex A audit review require a specific directory setup?▼

The ISO 27001 Annex A audit review requires a stable engagement directory for output. It uses Bash-based prompts and stores the final Markdown RAG report under the engagements folder with a date and client name.

Can I load client engagement briefs for ISO 27001 Annex A scope definition?▼

You can load engagement context and scope from client engagement briefs. The skill uses this input to frame the A.5 through A.8 control assessment and structure the final Annex A RAG report output.

What is the best way to document ISO 27001 Annex A gaps and evidence?▼

The best way to document ISO 27001 Annex A gaps is through a structured RAG framework that captures evidence ratings and gap notes during assessment, generating a client-facing Markdown document with a synthesized executive summary.