research
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Generate complete ISO 27001 ISMS documentation pack including mandatory and supporting documents
> /plugin marketplace add GRCEngClub/claude-grc-engineeringHow it fires
How this command gets triggered: by you, by Claude, or both.
/isms-documentation-packContext preview
What this command does when you run it.
Generate complete ISO 27001 ISMS documentation pack including mandatory and supporting documents
description: Generate complete ISO 27001 ISMS documentation pack including mandatory and supporting documents
Generates the complete set of ISO 27001:2022 Information Security Management System (ISMS) documentation, including all mandatory documents required by the standard and comprehensive supporting policies and procedures.
/iso:isms-documentation-pack [package-type] [options]
# Generate full ISMS documentation pack /iso:isms-documentation-pack full # Mandatory documents only (6 core documents) /iso:isms-documentation-pack mandatory-only # Export as Word documents /iso:isms-documentation-pack full --format=docx # Customize for organization /iso:isms-documentation-pack full --organization="Acme Corp" --scope="AWS cloud platform"
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ISO 27001:2022 ISMS DOCUMENTATION PACK ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Organization: Your Company, Inc. Generation Date: 2025-01-28 ISO Version: ISO/IEC 27001:2022 Package Type: Full (mandatory + supporting) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PACKAGE CONTENTS ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Mandatory Documents (6): Required by ISO 27001 standard Supporting Policies (15): Core security policies Supporting Procedures (25): Operational procedures Total Documents: 46 Output Directory: ./isms-documentation/ Format: Markdown (convertible to Word/PDF) Customization: Templates with [PLACEHOLDERS] to fill in ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ PART 1: MANDATORY ISMS DOCUMENTS (ISO Required) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ These 6 documents are explicitly required by ISO 27001:2022. 1. ISMS Scope Statement (Clause 4.3) ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ File: 01-ISMS-Scope-Statement.md Purpose: Define the boundaries and applicability of the ISMS Required By: Clause 4.3 - Determining the scope of the ISMS Content: ```markdown # ISO 27001:2022 ISMS Scope Statement Organization: [Your Company, Inc.] Version: 1.0 Date: [2025-01-28] Approved By: [CEO Name], Chief Executive Officer ## 1. Scope Definition The Information Security Management System (ISMS) of [Your Company] covers: ### 1.1 Organizational Boundaries - [Your Company, Inc.] (legal entity) - Locations: - Corporate Headquarters: [123 Main St, City, State, ZIP] - AWS Cloud Infrastructure: us-east-1, us-west-2 regions - Remote workforce (142 employees across [states/countries]) ### 1.2 Systems and Processes In Scope Information Systems: - Production infrastructure (AWS) - Application servers (ECS, EC2) - Databases (RDS PostgreSQL) - Object storage (S3) - Networking (VPC, CloudFront, Route 53) - Identity and access management (Okta, AWS IAM) - Development infrastructure (GitHub, CI/CD) - Monitoring and logging (CloudWatch, GuardDuty) - Business applications (Jira, Slack, Office 365) Business Processes: - Software development (SDLC) - Cloud infrastructure operations - Customer onboarding and support - Incident response - Change management - Vendor management Data Types: - Customer data (PII, business data) - Application source code - System configuration data - Security logs and monitoring data ### 1.3 Out of Scope (Exclusions) The following are explicitly excluded from the ISMS scope: - Marketing website (hosted separately by [vendor name]) - Mobile application infrastructure (separate ISMS/audit) - Corporate office IT infrastructure (no customer data processing) - [Company] subsidiary operations (separate legal entity) Justification for Exclusions: - Marketing website: Separate infrastructure, no customer data, managed by external vendor - Mobile app: Covered under separate security assessment - Office IT: No processing of customer data, no sensitive systems ### 1.4 Services Provided to Customers Within the scope of this ISMS: - [Product Name] SaaS Application - Cloud-based data processing and storage - Application programming interfaces (APIs) - 24/7 customer support (email, chat) ### 1.5 Geographic Coverage - Primary data centers: AWS us-east-1 (Virginia), us-west-2 (Oregon) - Service availability: Global (all countries except [embargoed countries]) - Data residency: United States only ### 1.6 Interested Parties Internal: - Employees (142 FTE) - Contractors (5-10 on average) - Board of Directors - Shareholders External: - Customers (10,000+ active users) - Regulatory authorities (FTC, state data protection authorities) - Cloud service providers (AWS, Okta, GitHub) - Certification body ([BSI, NQA, etc.]) ## 2. External and Internal Issues External Issues: - Increasing cyber threats (ransomware, data breaches) - Regulatory requirements (GDPR, CCPA, state privacy laws) - Customer security expectations (ISO 27001, SOC 2) - Cloud provider security (shared responsibility model) Internal Issues: - Remote workforce security (BYOD, home networks) - Rapid growth (scaling security controls) - Limited security staffing (3 FTE security team) - Cloud-native architecture (traditional controls don't apply) ## 3. Information Security Requirements Legal/Regulatory: - GDPR (EU customers) - CCPA (California customers) - GLBA (if applicable) - Contract obligations (customer DPAs) Business: - Protect customer data confidentiality, integrity, availability - Maintain service availability (99.9% SLA) - Respond to security incidents within defined timeframes - Demonstrate compliance to customers ## 4. Scope Review Review Frequency: Annually or upon significant changes Next Review: [Date 1 year from approval] Review Triggers: - New services or products launched - Significant infrastructure changes - Reg
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Start or resume an academic research project — idea through literature, methodology, writing, feedback, and publishing
Query AWS for compliance-relevant configuration across IAM, S3, CloudTrail, EBS, and emit findings conforming to the v1 contract.
Install the frdocx-to-froscal-ssp Python pipeline and verify its dependencies. Idempotent.
Retrieve a single AWS Secrets Manager secret value to stdout or a 0600-permission file. Opt-in retrieval mode — never writes to the findings cache.
Run testssl.sh against one or more HTTPS endpoints and emit v1 Findings mapped to SOC 2, NIST 800-53, PCI DSS 4.0.1, ISO 27001, and SCF controls.