Plugins
3 pluginscurated
ISO 27001 Audit Pipeline
Pressure-test an ISMS and generate audit evidence for ISO 27001 certification readiness.
9 skills · plugin
@alirezarezvani
Ra Qm Team
14 regulatory affairs & quality management skills for HealthTech/MedTech: ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, GDPR/DSGVO, ISO 27001 ISMS, CAPA management, risk management, clinical evaluation, SOC 2 compliance.
10 skills · plugin
@alirezarezvani
Compliance Os
Compliance OS — meta-orchestrator for multi-framework compliance programs spanning 9 frameworks (ISO 27001, ISO 13485, ISO 42001, ISO 14971, EU AI Act, MDR 745, GDPR, SOC 2, FDA QSR). Framework selector, cross-framework control mapper, audit simulator, and consolidated evidence-pool generator (stdlib Python), plus 3 cs-* compliance agents and 3 /cs:* readiness commands.
9 skills · plugin
Results for “iso-27001”
57 skillsiso-27001
Applies the ISO 27001 framework to identify, assess, and mitigate security risks in systems, processes, and data handling, providing structured analysis and recommendations.
2
iso27001-audit-prep
Pressure-tests an ISMS with six sample-driven questions to prepare for ISO 27001 internal, certification, or surveillance audits.
20.4k
implementing-iso-27001-information-security-management
Guides through the complete ISO/IEC 27001:2022 ISMS lifecycle from scoping and risk assessment to certification and continual improvement, including Annex A control selection and Statement of Applicability creation.
24.6k · bundle
ra-qm-skills
Routes compliance requests to the appropriate regulatory and quality-management skill among 15 bundled options, covering ISO 13485, EU MDR, FDA submissions, ISO 14971, CAPA, document control, ISO 27001, ISO 42001, EU AI Act, GDPR, SOC 2, and auditing.
20.4k
isms-audit-expert
Guides internal and external ISMS audits for ISO 27001 compliance, including audit planning, control assessment, finding management, and certification support.
20.4k · bundle
soc2-audit-prep
Guides SOC 2 Type II audit preparation with six forcing questions covering scope, control consistency, evidence tracking, and cross-walk to ISO 27001.
20.4k
More results
iso-27701-pims
Guides ISO 27701 Privacy Information Management System implementation extending ISO 27001/27002. Covers Clause 5 PIMS-specific requirements, Clause 6 PIMS guidance for ISO 27002, Clause 7 PII controller guidance (Annex A), Clause 8 PII processor guidance (Annex B), gap assessment, and certification path. Keywords: ISO 27701, PIMS, privacy management system, ISO 27001 extension, certification, Annex A, Annex B.
228 · bundle
iso27001
Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.
2 · bundle
threat-analyst
Monitors authorized threat intelligence feeds and maps adversary TTPs to MITRE ATT&CK, NIST CSF, and ISO 27001 frameworks to produce actionable intelligence reports with IOCs and defensive recommendations.
2
ra-qm-skills
12 regulatory & QM agent skills and plugins for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw. ISO 13485 QMS, MDR 2017/745, FDA 510(k)/PMA, ISO 27001 ISMS, GDPR/DSGVO, risk management (ISO 14971), CAPA, document control, auditing. Python tools (stdlib-only).
3 · bundle
compliance-readiness
Pressure-tests any compliance program with six forcing questions before adopting a new framework, planning an audit cycle, or signing off on certification readiness.
20.4k
isms-audit-expert
Information Security Management System (ISMS) audit expert for ISO 27001 compliance verification, security control assessment, and certification support. Use when the user mentions ISO 27001, ISMS audit, Annex A controls, Statement of Applicability (SOA), gap analysis, nonconformity management, internal audit, surveillance audit, or security certification preparation. Helps review control implementation evidence, document audit findings, classify nonconformities, generate risk-based audit plans, map controls to Annex A requirements, prepare Stage 1 and Stage 2 audit documentation, and support corrective action workflows.
0 · bundle
specialized-compliance-auditor
Expert technical compliance auditor specializing in SOC 2, ISO 27001, HIPAA, and PCI-DSS audits — from readiness assessment through evidence collection to certification.
2
iso27701
Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.
2 · bundle
compliance-os
Orchestrates multi-framework compliance programs by selecting applicable frameworks, mapping control overlaps, simulating audits, and consolidating evidence checklists.
20.4k · bundle
iso42001-specialist
Conduct internal audits against ISO/IEC 42001:2023 by identifying AIMS gaps, building an AI risk register with Annex A control mappings, and generating a 12-month Clause 9.2 audit plan.
20.4k · bundle
aims-audit
Pressure-tests AI Management Systems against ISO 42001 with six forcing questions for certification readiness, internal audits, and new-system onboarding.
20.4k
performing-soc-tabletop-exercise
Facilitates discussion-based tabletop exercises for SOC teams to test incident response procedures, communication workflows, and decision-making under pressure without impacting production systems.
24.6k · bundle
quality-manager-qmr
Provides quality system governance, management review leadership, regulatory compliance oversight, and quality performance monitoring per ISO 13485 Clause 5.5.2 for HealthTech and MedTech companies.
20.4k · bundle
qms-audit-expert
Provides ISO 13485 internal audit methodology for medical device quality management systems, covering audit planning, execution, nonconformity classification, and external audit preparation.
20.4k · bundle
comply
Regulatory compliance and audit agent. Maps business regulatory requirements (SOC2/PCI-DSS/HIPAA/ISO 27001), checks control implementations, designs audit trails, and implements Policy as Code. Use when compliance auditing is needed.
65 · bundle
information-disclosure-deep-dive
Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
21 · bundle
csharp-mstest
Write effective unit tests with modern MSTest 3.x/4.x, covering assertion APIs, data-driven tests, and test lifecycle best practices.
36.2k
iso-13485-certification
Prepare ISO 13485:2016 certification documentation for medical device Quality Management Systems, including gap analysis, template-based document creation, and compliance checklists.
30.2k · bundle
dmbok
Applies the DMBOK framework to design scalable, maintainable, and interoperable enterprise systems, guiding analysis and recommendations.
2
accessibility
Design, implement, and audit inclusive digital products using WCAG 2.2 Level AA standards, with guidance for Web, iOS, and Android platforms.
226k
ciso-advisor
Quantify security risks in dollars, build compliance roadmaps (SOC 2, ISO 27001, HIPAA, GDPR), and justify security budgets for growth-stage companies.
20.4k · bundle
managing-drata
Monitors Drata compliance posture by querying the Drata public API for control status, evidence collection, personnel compliance, and asset inventory, then produces a structured audit-readiness report.
7
harden
Strengthen interfaces against edge cases, errors, internationalization issues, and real-world usage scenarios that break idealized designs.
61
design-information-architecture-rules
Trigger: sitemap, navigation, menu structure, wayfinding, labeling, search facets, routing links. Scope: Visual hierarchies, wayfinding, navigation model, sitemaps. Boundary: Excludes backend route handlers or page performance tuning.
1 · bundle
dora
Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework", "Art. 17 incident reporting", "Art. 26 TLPT", "Art. 28 third-party policy", "Art. 30 contractual provisions", "Register of Information CIR 2024/2956", "critical TPSP designation", "DORA vs NIS2", "DORA simplified framework", or EBA/ESMA/EIOPA digital resilience guidance.
2 · bundle
cmmc
Expert CMMC 2.0 (Cybersecurity Maturity Model Certification) advisor for US defense contractors and subcontractors in the Defense Industrial Base (DIB). Use this skill whenever a user asks about CMMC 2.0, CMMC Level 1, Level 2, or Level 3, DoD cybersecurity compliance, NIST SP 800-171, CUI (Controlled Unclassified Information) protection, System Security Plan (SSP), Plan of Action & Milestones (POA&M), C3PAO assessments, DIBCAC audits, self-assessment, SPRS score, or any requirement under DFARS 252.204-7012 or 7021. Also trigger for: "CMMC gap analysis", "CMMC readiness", "FCI protection", "CUI scoping", "CMMC practices", "DoD contract cybersecurity", "defense supply chain security", or "prime contractor flow-down requirements".
3 · bundle
conducting-cyber-risk-assessment-with-nist-800-30
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology, from scoping and threat identification to risk determination and communication.
24.6k · bundle
cuijian-skill
崔健(摇滚)认知与表达框架(压缩蒸馏):地下与现场感、隐喻与直白并置… 触发:一块红布 等。非煽动违法
9 · bundle
dpia-risk-scoring
Provides a structured risk scoring methodology for Data Protection Impact Assessments aligned with ENISA threat taxonomy and ISO 29134. Covers likelihood and severity assessment, risk matrix construction, inherent vs residual risk calculation, and risk appetite thresholds per EDPB WP248rev.01 guidance. Keywords: risk scoring, DPIA risk matrix, likelihood, severity, ENISA, ISO 29134, residual risk, risk appetite.
228 · bundle
continuous-improvement
Use when identifying opportunities for incremental improvements in processes, systems, or practices. This skill provides a Kaizen-style framework for ongoing improvement across all areas of operation.
0