/ismap-expert
Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill ismap-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ismap-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.
SKILL.md
ismap-expert.SKILL.mdname: ismap-expert
description: Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions.
allowed-tools: Read, Glob, Grep, Write
ISMAP Expert
Expertise in Japanese government cloud security program based on ISO 27001/27017/27018.
Expertise Areas
ISMAP Overview
**Authority**: Digital Agency of Japan **Base Standards**:
- ISO/IEC 27001:2013 (ISMS)
- ISO/IEC 27017:2015 (Cloud security)
- ISO/IEC 27018:2019 (PII protection)
**Scope**: Cloud services for Japanese government agencies
ISO 27001 Annex A (114 Controls)
14 control domains for information security management.
ISO 27017 Cloud Controls
Additional cloud-specific controls (CLD prefix) for providers and customers.
ISO 27018 Privacy Controls
PII protection requirements for public cloud services.
Japanese Data Residency
**Regions**: ap-northeast-1 (Tokyo), ap-northeast-3 (Osaka) **Requirement**: Government data in Japanese regions only
Registration Process
1. ISO certification 2. Application submission 3. Technical assessment 4. Registry listing
**Timeline**: 6-12 months
Capabilities
- ISO 27001/27017/27018 control mapping and implementation
- ISMAP registration process guidance
- Japanese data residency verification (Tokyo/Osaka regions)
- Cloud service provider assessment preparation
- Privacy Impact Assessment for Japanese requirements
- ISMS documentation (ISO 27001 compliance)
- Cloud-specific security control implementation (ISO 27017)
- PII protection controls (ISO 27018)
Read more
name: ismap-expert description: Japanese ISMAP (Information System Security Management and Assessment Program) expert. Provides guidance on ISO 27001/27017/27018 compliance, Japanese government cloud requirements, and data residency in Tokyo/Osaka regions. allowed-tools: Read, Glob, Grep, Write
ISMAP Expert
Expertise in Japanese government cloud security program based on ISO 27001/27017/27018.
Expertise Areas
ISMAP Overview
**Authority**: Digital Agency of Japan **Base Standards**:
- ISO/IEC 27001:2013 (ISMS)
- ISO/IEC 27017:2015 (Cloud security)
- ISO/IEC 27018:2019 (PII protection)
**Scope**: Cloud services for Japanese government agencies
ISO 27001 Annex A (114 Controls)
14 control domains for information security management.
ISO 27017 Cloud Controls
Additional cloud-specific controls (CLD prefix) for providers and customers.
ISO 27018 Privacy Controls
PII protection requirements for public cloud services.
Japanese Data Residency
**Regions**: ap-northeast-1 (Tokyo), ap-northeast-3 (Osaka) **Requirement**: Government data in Japanese regions only
Registration Process
1. ISO certification 2. Application submission 3. Technical assessment 4. Registry listing
**Timeline**: 6-12 months
Capabilities
- ISO 27001/27017/27018 control mapping and implementation
- ISMAP registration process guidance
- Japanese data residency verification (Tokyo/Osaka regions)
- Cloud service provider assessment preparation
- Privacy Impact Assessment for Japanese requirements
- ISMS documentation (ISO 27001 compliance)
- Cloud-specific security control implementation (ISO 27017)
- PII protection controls (ISO 27018)
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

