information-security-manager-iso27001

Implements ISO 27001 ISMS frameworks and security risk assessments for healthcare organizations.

2|1|Updated Jan 29, 2026
One-click install
npx skills add https://github.com/bhaktofmahakal/ai-counsellor-hf --skill information-security-manager-iso27001-bhaktofmahakal
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: information-security-manager-iso27001
Source: https://github.com/bhaktofmahakal/ai-counsellor-hf/tree/main/.claude/skills/information-security-manager-iso27001
Command: npx skills add https://github.com/bhaktofmahakal/ai-counsellor-hf --skill information-security-manager-iso27001-bhaktofmahakal

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve? HealthTech and MedTech teams struggle to design, implement, and maintain an ISO 27001-compliant Information Security Management System while also meeting healthcare-specific requirements like HIPAA, FDA cybersecurity guidance, and GDPR. ## Core Features & Use Cases - ISMS Implementation: Guides the full ISO 27001:2022 lifecycle from scoping and policy development through risk assessment, control selection, and management review. - Security Risk Assessment: Applies structured asset identification, threat modeling, and risk treatment planning aligned with ISO 27001 Clause 6.1.2. - ISO 27002 Controls & Healthcare Security: Maps organizational, people, physical, and technological controls, plus medical device cybersecurity and cloud security evaluation. - Use Case: A HealthTech startup preparing for ISO 27001 certification uses this Skill to run a gap analysis, build its risk register, draft security policies, and prepare for Stage 1 and Stage 2 audits. ## Quick Start Ask the assistant to conduct an ISO 27001 risk assessment and draft an information security policy for your healthcare application.

Frequently Asked Questions about information-security-manager-iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement an ISO 27001 ISMS for a healthcare company?▼

Start by defining ISMS scope and security policies, then perform a risk assessment covering asset identification, threat analysis, and risk treatment. Select ISO 27002 controls across organizational, people, physical, and technological categories, and layer in HIPAA and FDA requirements.

How to conduct an ISO 27001 risk assessment under Clause 6.1.2?▼

Identify and classify information assets, analyze threats and vulnerabilities, then evaluate likelihood and impact to determine risk levels. Document risk treatment decisions and acceptance criteria, using healthcare-specific threat modeling where patient data or devices are involved.

What ISO 27002 controls apply to medical device cybersecurity?▼

Relevant controls include device authentication, encryption at rest and in transit, network segmentation, and secure update mechanisms. These align with FDA cybersecurity guidance and IEC 62304 integration for connected medical devices.

Does ISO 27001 certification require internal audits?▼

Yes, ISO 27001 requires risk-based internal audits covering technical testing, compliance verification, and process effectiveness before certification. Surveillance audits then verify ongoing compliance after certification is granted.

What are the limitations of this Skill for security work?▼

The bundled scripts and references are placeholders, so automated dashboards and assessment tooling are not functional out of the box. It provides expert guidance and frameworks rather than executable scanning or monitoring capabilities.