ISO/IEC 27001:2022 Information Security Management System (ISMS) implementation patterns — Annex A 93 controls in 4 themes (Organizational, People, Physical, Technological), Statement of Applicability, risk assessment / treatment, and the engineering-side controls that auditors actually verify.
Installs into .claude/skills of the current project.
Are you the author of Iso27001 Controls?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/nmor-iso27001-controls-the-council)
---
name: iso27001-controls
description: ISO/IEC 27001:2022 Information Security Management System (ISMS) implementation patterns — Annex A 93 controls in 4 themes (Organizational, People, Physical, Technological), Statement of Applicability, risk assessment / treatment, and the engineering-side controls that auditors actually verify.
disable-model-invocation: true
---
# ISO/IEC 27001 Controls
> **Size budget: 8 KB** — `token-budget.mjs --check`.
ISO/IEC 27001:2022 Information Security Management System (ISMS) implementation patterns — Annex A 93 controls in 4 themes (Organizational, People, Physical, Technological), Statement of Applicability, risk assessment / treatment, and the engineering-side controls that auditors actually verify.
## Working procedure
1. Establish the relevant mode and existing evidence; do not repeat completed intake.
2. Define the requested scope, baseline, success criteria and evidence before choosing a procedure. Verify current external requirements from primary sources. Distinguish observed facts from hypotheses and implemented controls from tested outcomes. Preserve user authorization, sensitive data, rollback options and the existing plan.
3. Read only the corresponding sections below before applying their examples.
4. Verify the result with meaningful positive, negative and failure controls. Record actual outcomes, limitations and next action.
## Selected references
- [Purpose](references/procedure.md#purpose) — read when this part of the task applies.
- [Standards Cited](references/procedure.md#standards-cited) — read when this part of the task applies.
- [When to Fire](references/procedure.md#when-to-fire) — read when this part of the task applies.
- [Core Patterns](references/procedure.md#core-patterns) — read when this part of the task applies.
- [Anti-Patterns](references/procedure.md#anti-patterns) — read when this part of the task applies.
- [Verification Checklist](references/procedure.md#verification-checklist) — read when this part of the task applies.
- [Cross-References](references/procedure.md#cross-references) — read when this part of the task applies.
- [Why This Skill Exists](references/procedure.md#why-this-skill-exists) — read when this part of the task applies.
- [Learning hooks](references/procedure.md#learning-hooks) — read when this part of the task applies.
The [full procedure](references/procedure.md) preserves detailed examples and standards.
Load relevant excerpts rather than the entire reference. Runtime capabilities and higher-priority instructions govern imported templates.