information-security-manager-iso27001 by davila7/claude-code-templates
npx skills add https://github.com/davila7/claude-code-templates --skill information-security-manager-iso27001具备 ISO 27001、ISO 27002 和医疗行业特定安全要求的全面知识,提供专家级的信息安全管理体系实施和网络安全治理。
设计和实施符合 ISO 27001:2022 和医疗行业法规要求的全面信息安全管理体系。
ISMS 实施框架:
ISO 27001 ISMS IMPLEMENTATION
├── ISMS Planning and Design
│ ├── Information security policy development
│ ├── Scope and boundaries definition
│ ├── Risk assessment methodology
│ └── Security objectives establishment
├── Security Risk Management
│ ├── Asset identification and classification
│ ├── Threat and vulnerability assessment
│ ├── Risk analysis and evaluation
│ └── Risk treatment planning
├── Security Controls Implementation
│ ├── ISO 27002 controls selection
│ ├── Technical controls deployment
│ ├── Administrative controls establishment
│ └── Physical controls implementation
└── ISMS Operation and Monitoring
├── Security incident management
├── Performance monitoring
├── Management review
└── Continuous improvement
执行系统的信息安全风险评估,确保全面的威胁识别和风险处置。
风险评估方法:
资产识别与分类
广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
威胁与脆弱性分析
风险分析与评估
实施全面的安全控制措施框架,确保系统的信息安全保护。
安全控制措施类别:
ISO 27002:2022 CONTROLS FRAMEWORK
├── Organizational Controls (5.1-5.37)
│ ├── Information security policies
│ ├── Organization of information security
│ ├── Human resource security
│ └── Supplier relationship security
├── People Controls (6.1-6.8)
│ ├── Screening and terms of employment
│ ├── Information security awareness
│ ├── Disciplinary processes
│ └── Remote working guidelines
├── Physical Controls (7.1-7.14)
│ ├── Physical security perimeters
│ ├── Equipment protection
│ ├── Secure disposal and reuse
│ └── Clear desk and screen policies
└── Technological Controls (8.1-8.34)
├── Access control management
├── Cryptography and key management
├── Systems security
├── Network security controls
├── Application security
├── Secure development
└── Supplier relationship security
实施满足医疗和医疗设备独特要求的安全措施。
医疗安全框架:
为联网医疗设备和物联网医疗系统实施全面的网络安全措施。
设备网络安全框架:
设备安全评估
安全控制措施实施
安全监控与响应
确保基于云的医疗系统和 SaaS 应用程序的全面安全。
云安全策略:
将信息安全与隐私和数据保护要求集成,确保全面的数据治理。
隐私-安全集成:
建立全面的信息安全政策,确保组织安全治理。
政策框架结构:
制定和维护全面的安全意识计划,确保组织安全文化。
培训计划组成部分:
实施稳健的安全事件管理流程,确保有效的事件响应和恢复。
事件管理流程:
监控全面的安全绩效指标,确保 ISMS 有效性和持续改进。
安全绩效仪表板:
执行系统的内部安全审计,确保 ISMS 合规性和有效性。
安全审计计划:
领导管理评审流程,确保系统的 ISMS 评估和战略安全规划。
管理评审框架:
监督 ISO 27001 认证流程,确保成功认证和维护。
认证管理:
确保全面遵守医疗安全法规和标准。
法规合规框架:
isms-performance-dashboard.py:全面的 ISMS 指标监控和报告security-risk-assessment.py:自动化的安全风险评估和文档编制compliance-monitoring.py:法规和标准合规性跟踪incident-response-automation.py:安全事件工作流自动化iso27001-implementation-guide.md:完整的 ISO 27001 ISMS 实施框架iso27002-controls-library.md:全面的安全控制措施实施指南healthcare-threat-modeling.md:医疗行业特定的威胁评估方法device-security-assessment.md:医疗设备网络安全评估框架cloud-security-evaluation.md:云服务安全评估标准isms-templates/:信息安全政策、程序和文档模板risk-assessment-tools/:安全风险评估工作表与计算工具audit-checklists/:ISO 27001 和安全合规审计清单training-materials/:信息安全意识和培训计划每周安装量
175
仓库
GitHub 星标数
22.6K
首次出现
2026年1月21日
安全审计
安装于
claude-code141
opencode138
gemini-cli133
cursor124
codex123
github-copilot113
Expert-level Information Security Management System (ISMS) implementation and cybersecurity governance with comprehensive knowledge of ISO 27001, ISO 27002, and healthcare-specific security requirements.
Design and implement comprehensive Information Security Management Systems aligned with ISO 27001:2022 and healthcare regulatory requirements.
ISMS Implementation Framework:
ISO 27001 ISMS IMPLEMENTATION
├── ISMS Planning and Design
│ ├── Information security policy development
│ ├── Scope and boundaries definition
│ ├── Risk assessment methodology
│ └── Security objectives establishment
├── Security Risk Management
│ ├── Asset identification and classification
│ ├── Threat and vulnerability assessment
│ ├── Risk analysis and evaluation
│ └── Risk treatment planning
├── Security Controls Implementation
│ ├── ISO 27002 controls selection
│ ├── Technical controls deployment
│ ├── Administrative controls establishment
│ └── Physical controls implementation
└── ISMS Operation and Monitoring
├── Security incident management
├── Performance monitoring
├── Management review
└── Continuous improvement
Conduct systematic information security risk assessments ensuring comprehensive threat identification and risk treatment.
Risk Assessment Methodology:
Asset Identification and Classification
Threat and Vulnerability Analysis
Risk Analysis and Evaluation
Implement comprehensive security controls framework ensuring systematic information security protection.
Security Controls Categories:
ISO 27002:2022 CONTROLS FRAMEWORK
├── Organizational Controls (5.1-5.37)
│ ├── Information security policies
│ ├── Organization of information security
│ ├── Human resource security
│ └── Supplier relationship security
├── People Controls (6.1-6.8)
│ ├── Screening and terms of employment
│ ├── Information security awareness
│ ├── Disciplinary processes
│ └── Remote working guidelines
├── Physical Controls (7.1-7.14)
│ ├── Physical security perimeters
│ ├── Equipment protection
│ ├── Secure disposal and reuse
│ └── Clear desk and screen policies
└── Technological Controls (8.1-8.34)
├── Access control management
├── Cryptography and key management
├── Systems security
├── Network security controls
├── Application security
├── Secure development
└── Supplier relationship security
Implement security measures addressing unique healthcare and medical device requirements.
Healthcare Security Framework:
Implement comprehensive cybersecurity measures for connected medical devices and IoT healthcare systems.
Device Cybersecurity Framework:
Device Security Assessment
Security Controls Implementation
Security Monitoring and Response
Ensure comprehensive security for cloud-based healthcare systems and SaaS applications.
Cloud Security Strategy:
Integrate information security with privacy and data protection requirements ensuring comprehensive data governance.
Privacy-Security Integration:
Establish comprehensive information security policies ensuring organizational security governance.
Policy Framework Structure:
Develop and maintain comprehensive security awareness programs ensuring organizational security culture.
Training Program Components:
Implement robust security incident management processes ensuring effective incident response and recovery.
Incident Management Process:
Monitor comprehensive security performance indicators ensuring ISMS effectiveness and continuous improvement.
Security Performance Dashboard:
Conduct systematic internal security audits ensuring ISMS compliance and effectiveness.
Security Audit Program:
Lead management review processes ensuring systematic ISMS evaluation and strategic security planning.
Management Review Framework:
Oversee ISO 27001 certification processes ensuring successful certification and maintenance.
Certification Management:
Ensure comprehensive compliance with healthcare security regulations and standards.
Regulatory Compliance Framework:
isms-performance-dashboard.py: Comprehensive ISMS metrics monitoring and reportingsecurity-risk-assessment.py: Automated security risk assessment and documentationcompliance-monitoring.py: Regulatory and standard compliance trackingincident-response-automation.py: Security incident workflow automationiso27001-implementation-guide.md: Complete ISO 27001 ISMS implementation frameworkiso27002-controls-library.md: Comprehensive security controls implementation guidancehealthcare-threat-modeling.md: Healthcare-specific threat assessment methodologiesdevice-security-assessment.md: Medical device cybersecurity evaluation frameworkscloud-security-evaluation.md: Cloud service security assessment criteriaisms-templates/: Information security policy, procedure, and documentation templatesrisk-assessment-tools/: Security risk assessment worksheets and calculation toolsaudit-checklists/: ISO 27001 and security compliance audit checkliststraining-materials/: Information security awareness and training programsWeekly Installs
175
Repository
GitHub Stars
22.6K
First Seen
Jan 21, 2026
Security Audits
Gen Agent Trust HubPassSocketPassSnykPass
Installed on
claude-code141
opencode138
gemini-cli133
cursor124
codex123
github-copilot113
xdrop 文件传输脚本:Bun 环境下安全上传下载工具,支持加密分享
28,800 周安装
shadcn/ui 框架:React 组件库与 UI 设计系统,Tailwind CSS 最佳实践
59,100 周安装
Python PDF处理教程:合并拆分、提取文本表格、创建PDF文件
59,800 周安装
browser-use CLI 浏览器自动化工具:快速持久会话,支持多步骤工作流
60,300 周安装
新闻内容提取工具 - 支持12个主流平台,自动输出JSON和Markdown格式
205 周安装
AI Elements:基于shadcn/ui的AI原生应用组件库,快速构建对话界面
62,200 周安装
专业SEO审计工具:全面网站诊断、技术SEO优化与页面分析指南
63,800 周安装