Skip to content

[REVIEW] iso27001-gap: add internal-audit sampling and impartiality evidence gates#1639

Open
Desalzes wants to merge 1 commit into
UnitOneAI:mainfrom
Desalzes:codex/iso27001-internal-audit-gates
Open

[REVIEW] iso27001-gap: add internal-audit sampling and impartiality evidence gates#1639
Desalzes wants to merge 1 commit into
UnitOneAI:mainfrom
Desalzes:codex/iso27001-internal-audit-gates

Conversation

@Desalzes
Copy link
Copy Markdown

@Desalzes Desalzes commented Jun 7, 2026

Summary

Fixes #1633.

This strengthens iso27001-gap internal-audit readiness so a schedule plus summary report is not enough to pass Clause 9.2. The skill now requires retained evidence for audit criteria, scope, risk-based coverage, previous finding linkage, sampling, auditor impartiality, management reporting, and corrective-action closure.

Changes

  • Expanded Step 6 with Clause 9.2 evidence gates and Clause 10.2 corrective-action closure checks.
  • Added ISO-AUDIT-01 through ISO-AUDIT-06 finding/check IDs for weak audit programs, undefined scope, unevidenced independence, missing samples, missing management reporting, and incomplete corrective actions.
  • Added required output sections for Internal Audit Program Evidence and Corrective Action Closure.
  • Added a common pitfall for treating an audit calendar and final summary as full audit readiness.
  • Left the ISO 27001:2022 Annex A control list unchanged.

Validation

  • git diff --check
  • frontmatter required-field check
  • prompt-injection pattern scan for the modified skill
  • markdown fence balance check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] iso27001-gap: add internal-audit sampling and impartiality evidence gates

1 participant