smithery/hack23

isms-compliance

Hack23 ISMS alignment — ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, EU CRA — with policy citations

Installation

$ npx skills add smithery/hack23 --skill isms-compliance

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery/hack23 · top by installs.

npx skills add smithery/hack23

Browse all from smithery/hack23

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

LicenseMIT

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 5,269 B
  • docs SUMMARY.md 150 B

History

  1. First recorded snapshot · 0 installs

SKILL.md

ISMS Compliance Skill

Context

Applies when adding features, dependencies, or security controls; editing security code; documenting architecture; touching CI/CD; or handling any sensitive data.

All practices align with Hack23 AB's ISMS-PUBLIC, implementing ISO 27001:2022, NIST CSF 2.0, CIS Controls v8.1, GDPR, NIS2, and EU CRA readiness.

Policy Catalogue (cite the one that applies)

Concern Policy
Overarching governance / incident / transparency Information Security Policy
SDLC / CI / testing / deployment / threat modeling Secure Development Policy
Dependencies / licenses / SBOM / supply chain Open Source Policy
Auth / identity / access Access Control Policy
Encryption / keys / hashing Cryptography Policy
Data handling / classification Data Classification Policy
Personal data / GDPR Privacy Policy
STRIDE / abuse cases / MITRE ATT&CK Threat Modeling
Vulnerability triage + patch SLAs Vulnerability Management
Copilot / LLM / MCP governance AI Policy
Agent / MCP / workflow edits Change Management
BCP / DR / backup Business Continuity / Disaster Recovery / Backup Recovery

Rules

  1. Reference ISMS Policies — security-relevant code, docs, and PRs must cite the applicable policy (e.g., "ISMS: SDP §Phase 3")
  2. Defense in Depth — stack validation + sanitization + encoding + CSP + headers
  3. Document Decisions — ADRs and threat models cite ISMS policies
  4. Verify Dependencies — npm audit + npm run test:licenses + GitHub Advisory DB before adding
  5. Security Headers — CSP, HSTS, X-Frame-Options, X-Content-Type-Options (see SECURITY_HEADERS.md)
  6. Secure Defaults — unused features off; risky options explicit opt-in
  7. Least Privilege — minimum token scopes, minimum workflow permissions, minimum tool scopes
  8. Validate All Inputs — never trust user input (validate / sanitize / encode)
  9. Encrypt Sensitive Data — AES-256 at rest, TLS 1.3+ in transit, SHA-256+ hashing
  10. Log Security Events — auth, authorization failures, security-relevant events; never secrets/PII
  11. Secure SDLC — security baked into design → dev → test → deploy → operate
  12. Test Security Controls — ≥ 95 % coverage on security-sensitive paths
  13. Patch within SLA — Critical ≤ 7 d, High ≤ 30 d, Medium ≤ 90 d
  14. No Production Data in Tests — anonymize / synthesize

Secure SDLC Phase Gates (per SDP)

Phase Gate
Plan & Design Classification (CIA triad) + threat model + policy links
Develop OWASP-aligned, typed, no hardcoded secrets, least-privilege tokens
Test CodeQL clean, npm audit clean, coverage ≥ 80 / 70 (≥ 95 % security)
Deploy SHA-pinned Actions, SLSA L3 attestations, SBOM + SBOMQS ≥ 7.0
Operate Scorecard ≥ 8.0, Dependabot green, patch SLAs honored, incident drills

Compliance Framework Mapping

ISO 27001:2022 — A.5.23, A.5.30, A.8.25, A.8.28, A.8.29, A.8.30, A.8.31, A.8.32

NIST CSF 2.0 — GV (govern), ID.AM, PR.DS, PR.IR, DE.CM, RS.AN, RC.RP

CIS Controls v8.1 — 2, 3, 4, 6, 7, 8, 11, 16, 18

EU CRA — SBOM, CVE handling, security updates, conformity self-assessment

Example: ISMS-Cited Code

/**
 * Persist the high score.
 * ISMS: Secure Development Policy §Phase 2 — Secure Coding (input validation)
 * ISMS: Data Classification Policy — local-only, non-PII
 * Compliance: ISO 27001:2022 A.8.28, NIST CSF PR.DS-1
 */
export function saveHighScore(score: number): void {
  if (!Number.isFinite(score) || score < 0) {
    throw new RangeError('Invalid score value');
  }
  localStorage.setItem('highScore', String(Math.floor(score)));
}

Validation Checklist

  • Applicable ISMS policy cited in code, commit, or PR description
  • Threat model reviewed if attack surface changed (STRIDE)
  • Dependency audit clean; licenses approved
  • Security coverage ≥ 95 % on changed security code
  • CodeQL + Scorecard + Dependabot status green
  • No PII / production data in code, fixtures, or tests
  • Docs updated (README / ISMSPOLICYMAPPING.md / SECURITY.md as applicable)