information-security-manager-iso27001

Designs and assesses ISO 27001-aligned information security management systems for HealthTech organizations.

1|Updated Aug 7, 2025
One-click install
npx skills add https://github.com/zzafergok/arktos --skill information-security-manager-iso27001-zzafergok
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: information-security-manager-iso27001
Source: https://github.com/zzafergok/arktos/tree/main/.agent/skills/information-security-manager-iso27001
Command: npx skills add https://github.com/zzafergok/arktos --skill information-security-manager-iso27001-zzafergok

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve? Building and maintaining an ISO 27001-aligned Information Security Management System (ISMS) is complex, especially for HealthTech and MedTech teams that must also address HIPAA, GDPR, and FDA cybersecurity requirements. This Skill provides structured expert guidance for risk assessment, control selection, governance, and audit preparation. ## Core Features & Use Cases - ISMS Design & Risk Assessment: Guides ISO 27001:2022 implementation including asset classification, threat analysis, and risk treatment planning per Clause 6.1.2. - ISO 27002 Controls Implementation: Covers organizational, people, physical, and technological control categories with healthcare-specific adaptations. - Audit & Certification Preparation: Supports gap analysis, Stage 1/Stage 2 audit coordination, surveillance audits, and security metrics dashboards. - Use Case: A HealthTech startup preparing for ISO 27001 certification uses this Skill to build its risk assessment methodology, select applicable Annex A controls, and draft its information security policy framework. ## Quick Start Ask the assistant to design an ISO 27001 risk assessment and control implementation plan for your healthcare SaaS platform.

Frequently Asked Questions about information-security-manager-iso27001

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement an ISO 27001 ISMS for a healthcare company?▼

ISO 27001 ISMS implementation starts with defining scope, developing an information security policy, and conducting a risk assessment per Clause 6.1.2. This Skill guides control selection from ISO 27002:2022 and integrates healthcare requirements like HIPAA technical safeguards.

How to conduct an ISO 27001 risk assessment?▼

An ISO 27001 risk assessment involves asset identification and classification, threat and vulnerability analysis, then risk evaluation and treatment planning. For healthcare data, include sector-specific threats; for medical devices, include safety impact and product-security lifecycle risks.

What ISO 27002 controls apply to medical device cybersecurity?▼

Medical device cybersecurity uses technological controls including device authentication, encryption at rest and in transit, network segmentation, and secure update mechanisms. The Skill aligns these with FDA cybersecurity guidance and IEC 62304 integration.

Does this Skill provide ISO 27001 certification?▼

No, this Skill does not establish compliance or grant certification. It helps with pre-certification readiness, gap analysis, and Stage 1/Stage 2 audit coordination, but certification requires an accredited external certification body.

Can ISO 27001 controls be combined with HIPAA and GDPR compliance?▼

Yes, the Skill maps ISO 27002 controls to HIPAA Security Rule safeguards and GDPR technical and organizational measures. It supports privacy by design, data minimization, and cross-border transfer controls within a unified ISMS framework.