Pricing Strategy
Choose packages, value metrics, price points, margin guardrails, and a measurable test without turning assumptions into validated demand.
quorin
Updated Jul 23, 2026
Run evidence-bound ISMS audits with controlled criteria, defensible samples, traceable findings, and verified corrective-action follow-up.
An ISMS audit can look complete while its conclusion rests on a convenient screenshot, an interview nobody corroborated, or a severity label borrowed from another program. This skill keeps the audit tied to the actual mandate, controlled criteria, sampled population, and evidence available.
It builds the scope and criteria register, maps risk-based coverage, separates control design from implementation and operation, preserves contradictory evidence, and drafts findings that trace from requirement to condition to consequence. Corrective actions stay open until implementation, retest, effectiveness, residual issues, and approval support closure.
Use it for ISO/IEC 27001 internal audits, supplier ISMS audits, certification-readiness work, control sampling, finding review, or corrective-action follow-up. It does not reproduce licensed standards, conduct an external certification audit, or promise certification. A bundled read-only checker validates the structure and cross-references of a JSON audit record without deciding conformity.
Input
Run an internal ISMS audit of privileged-access reviews for January through June. The procedure requires quarterly review, but we have exports for Q1 and Q2 from two of three business units. One Q2 export was selected by the control owner and has no generation timestamp. The security manager who designed the process is also the proposed auditor. Use our audit procedure AP-4 rev 7 for classifications. Do not invent missing standard text or decide certification readiness.
Output
A bounded audit mandate; independence conflict and reviewer requirement; criteria and coverage register; population and evidence requests; separate design, implementation, and operation tests; sampling limitations for the curated export; traceable finding drafts or unresolved states; and a blocked or complete-with-limitations verdict that names the missing unit and evidence provenance.
Provide the audit type, objective, scope, period, controlled criteria and revisions, Statement of Applicability or risk-treatment context, prior findings, available evidence, classification authority, and closure approver. The skill returns the narrowest supportable audit record and keeps missing criteria, access, independence, contradictions, and open verification visible.
The licensed standard clauses, organizational policies, procedures, Statement of Applicability, contracts, or other controlled requirements for the defined audit. Missing criteria limit the result to a plan or bounded review.
Audit type, objectives, scope, period, exclusions, sponsor, auditee, report recipients, classification scheme, closure approver, and any confidentiality or evidence-handling constraints.
Relevant policies, records, exports, configurations, interviews, observations, prior findings, incidents, risk records, action evidence, and known gaps. Sensitive material should be minimized or redacted.
Required only for the optional read-only JSON audit-record checker. It uses the standard library, reads one local file, and writes findings to stdout.
SKILL.md; evidence, sampling, finding, classification, corrective-action, and closure rubric; human-readable and JSON audit-record templates; read-only structured audit-record checker; Agent Skills interface metadata
No reviews yet.
Input
Assess our SaaS supplier's incident-management control. Their policy says every security incident receives a post-incident review. The supplier supplied six closed tickets, but the incident register lists eight events. Two high-severity events have no review record. An interviewee says they were service outages, while customer notices call them security incidents. The contract, supplier audit criteria, and our classification scheme are attached. Build the evidence record and findings without setting arbitrary response deadlines.
Output
A supplier-audit scope and criteria map; eight-event population with the six supplied records kept distinct; contradictory classification evidence preserved; test records for design and operation; findings tied to contract and audit criteria rather than preference; an explicit classification-authority step; corrective-action requests; and follow-up gates without invented deadlines or a certification claim.
Input
Review finding IA-25-17 about joiner-mover-leaver access. The owner revised the procedure, trained 42 staff, and sent a screenshot of the workflow. A sample of five recent leavers found one account disabled nine days late; the approved corrective-action plan requires same-day disablement and effectiveness over a representative period. The owner wants closure before next week's management review. Determine the record state, but do not approve closure.
Output
Correction, cause, action, implementation, and effectiveness kept separate; the procedure, attendance, screenshot, and five-record sample classified by what each can prove; the late account preserved as contrary effectiveness evidence; sampling and exposure limits; required retest and residual-issue review; and a verification-pending verdict with the named closure authority still in control.
Creator
Rromvex0