Skip to content

About

Agent-driven kit to start or extend an ISMS and get audit-ready for CyFun or ISO 27001. Works best with CISO Assistant.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

Repository files navigation

agentic-isms

An agent-driven starter kit for building an ISO 27001 ISMS or a CyFun implementation, run from Claude Code. It exists to give a security lead a consistent, risk-based starting point for taking an organisation from nothing documented, or from whatever it already has, to audit-ready, whether the driver is voluntary certification or NIS2.

How it works

Everything runs inside Claude Code, driven by CLAUDE.md (the working method) plus a set of role agents and skills under .claude/. One engagement, per entity, moves through a fixed order, because policies are the treatment of identified risks, not the starting point:

  1. Kickoff - organisation name, size, target framework (and CyFun assurance level if relevant), language, and what already exists.
  2. Context and scope - the ISO clause 4 document; also the evidence base for CyFun's Identify function.
  3. Gap assessment - baseline current implementation against the target framework's controls, using whatever the client already has.
  4. Risk assessment and treatment - gaps and threats become risk scenarios; every risk above appetite gets a treatment decision.
  5. Policies - drafted only for what the risk assessment or a specific driver actually requires, downscaled to the client's real size.
  6. Applied controls and evidence - implemented and evidenced in a GRC tool.
  7. Statement of Applicability - every control traced back to the risk assessment.
  8. Management review and internal audit - human-led, not automated by this repo; tracked as milestones.
  9. External verification or certification audit.

Each phase after kickoff has a role agent (gap-assessor, risk-assessor, policy-writer, evidence-collector, auditor) that loads the matching skill and the reference material it needs. entities/<entity>/ holds one organisation's working documents (context, gap assessment, risk register, roadmap); templates/ holds the blank documents each phase fills in; reference/ holds the standards, control lists, and mappings everything cites back to.

What is inside

  • CLAUDE.md: the working method and principles that apply to every entity.
  • .claude/agents/: five role agents (gap-assessor, policy-writer, risk-assessor, evidence-collector, auditor).
  • .claude/skills/: reusable know-how the agents, and the main session, load (context analysis, gap assessment, policy authoring, risk scenarios, evidence and SoA, tracker hygiene).
  • templates/: empty fill-in documents (context intake, context analysis, roadmap, policy, risk register, SoA, management review).
  • reference/: knowledge to consult (policy set, threat catalogue, ISO 27001 Annex A, NIS2 reference and mapping, CyFun 2025 control booklets and CCB self-assessment tools under cyfun/).
  • entities/: one subfolder per entity (entities/<entity>/), for example separate legal entities within a larger group. Each holds that entity's CONTEXT.md, roadmap, context analysis, gap assessment, and risk register. Gitignored except entities/README.md.

Setup per entity

  1. Kickoff: on first run for an entity, before anything else, Claude Code asks for the organisation name, team size (FTEs), target framework (ISO 27001, CyFun with its assurance level, or both), language for deliverables, and what already exists in the ISMS, then creates entities/<entity>/CONTEXT.md and entities/<entity>/roadmap.md from their templates. If more than one entity could apply, it first confirms which one this session is for.
  2. Kickoff also asks whether a GRC tool (for example CISO Assistant) is already running to connect to. .mcp.json is committed as a generic template pointing at the CISO Assistant MCP server; see "Connecting a GRC tool" in CLAUDE.md for the exact steps (token, local checkout, config), and use environment variables for any credentials a GRC tool needs, never literal values in this tracked file. No GRC tool yet is fine: work proceeds via the local markdown fallback until one exists.
  3. entities/* is gitignored except entities/README.md. Never commit entity data.

Human-led steps

Management review and internal audit are deliberately not automated here. An internal audit performed by AI does not satisfy ISO 27001 clause 9.2, which requires independence from whoever built the ISMS; management review is a leadership decision process, not a document-generation task. The auditor agent is a quality aid that prepares for both, never a substitute for either. See CLAUDE.md and entities/<entity>/roadmap.md.

Licence and references

This repository's own content (agents, skills, templates, documentation) is MIT-licensed; see LICENSE. CyFun material under reference/cyfun/ belongs to the Centre for Cybersecurity Belgium (CCB) and is used here as working reference material; the control booklets are converted from CCB's original PDFs to Markdown, which can introduce transcription artifacts, see reference/cyfun/README.md. The ISO 27001:2022 Annex A list (reference/iso27001/) and the NIS2 reference and mapping (reference/nis2/) are adapted from the Claude Skills for Governance, Risk & Compliance project by Hemant Naik (MIT License). The generic threats in reference/threat-catalogue.md and the mapping table in reference/cyfun-iso-mapping.md are adapted from CISO Assistant Community Edition by intuitem (AGPLv3 License) — a genuinely excellent, free, open-source GRC tool that this starter kit also connects to directly via MCP; well worth a look on its own, and worth paying for if you need their enterprise tier. Reference policy content otherwise is distilled into generic templates, not copied from any client or third-party source.

Disclaimer

This is a working aid, not a compliance guarantee. Using this repository does not certify, verify, or guarantee compliance with ISO 27001, CyFun, NIS2, or any other framework or regulation, and creates no assurance that an audit will pass. It provides general guidance and working structure only, not legal advice, and does not replace a qualified compliance professional or an accredited certification or verification body. Management review and internal audit must be performed by humans, per the boundary above. Treat every agent and skill output as a draft for a competent person to review and decide on, never as a final answer, and provided as-is with no warranty, per LICENSE.

About

Agent-driven kit to start or extend an ISMS and get audit-ready for CyFun or ISO 27001. Works best with CISO Assistant.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors