neo-iso-27701

Solid

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27701 PIMS, inventory PII processing, analyze controller and processor responsibilities, create a privacy risk or evidence matrix, conduct a gap analysis, prepare for an audit, or create an improvement plan. Use neo-iso-27001 when the main concern is ISMS or information security risk. Do not treat PIMS as a legal-compliance guarantee for any specific privacy law.

Code & Development 7 stars 2 forks Updated 5 days ago MIT

Install

View on GitHub

Quality Score: 84/100

Stars 20%
30
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Neo ISO/IEC 27701 Provide evidence-based assistance for establishing, improving, or reviewing a privacy information management system (PIMS). Read `references/sources-and-scope.md` first, then follow the workflow below. ## Scope and hard boundaries In scope: - PIMS implementation, scope definition, and PII processing-context inventories. - Responsibilities, accountability, and evidence for PII controllers and PII processors. - Privacy risk registers, processing-activity worksheets, supplier evidence, and gap analyses. - Privacy-audit preparation, corrective actions, and continual-improvement plans. Out of scope: - Legal advice, legal-basis determinations, or compliance guarantees for any specific jurisdiction. - Clause-by-clause requirements, control lists, or verbatim reproduction without a licensed standard document. - Treating an ISO/IEC 27701 certificate or PIMS implementation as direct proof of GDPR or other privacy-law compliance. - Exposing raw personal data, passwords, tokens, or unnecessary sensitive data in the output. ## Version gate 1. Use `ISO/IEC 27701:2025`, Edition 2, as the default version baseline; treat `ISO/IEC 27701:2019` as historical material only. 2. The 2025 edition can operate as an independent management-system standard; do not assume that the organization has established or must first establish ISO/IEC 27001. 3. When answering about the "latest" or "current" version or differences between 2019 and 2025, recheck official sources instead of...

Details

Author
Benknightdark
Repository
Benknightdark/neo-skills
Created
7 months ago
Last Updated
5 days ago
Language
JavaScript
License
MIT

Similar Skills

Semantically similar based on skill content — not just same category

Code & Development Solid

neo-iso-27001

Use this skill when the user needs to establish, review, or improve an ISO/IEC 27001 ISMS, perform information security risk discovery, define scope, create an evidence matrix, conduct a gap analysis, draft a Statement of Applicability, prepare for an internal audit, or create an improvement plan. Use neo-iso-27701 when the main concern is PII, privacy management, or PIMS. Do not use this skill for legal advice or certification guarantees.

7 Updated 5 days ago
Benknightdark
Data & Documents Featured

iso27701

Expert ISO 27701 Privacy Information Management System (PIMS) compliance advisor. Use this skill whenever a user asks about ISO/IEC 27701:2025, ISO/IEC 27701:2019, privacy information management, PIMS certification, PII controller or processor obligations, privacy risk assessment, Statement of Applicability for privacy, privacy by design, data subject rights, DPIA, records of processing activities, transitioning from ISO 27701:2019, GDPR alignment with ISO 27701, or any privacy management system topic. Also trigger for questions about Annex A.1 (controller controls), A.2 (processor controls), A.3 (shared security controls), or implementing a standalone PIMS without ISO 27001. When in doubt, use this skill — it covers the full ISO 27701 lifecycle from gap assessment through certification.

890 Updated 5 days ago
Sushegaad
Data & Documents Featured

iso27001

Expert ISO 27001 compliance assistant for security and compliance teams. Use this skill whenever a user asks about ISO 27001 or ISO/IEC 27001, including any of the following: gap analysis, auditing, compliance assessments, control checklists, policy writing, document generation, Statement of Applicability (SoA), risk assessment, risk registers, risk treatment plans, Annex A controls, ISMS implementation, clause requirements, certification readiness, transitioning from 2013 to 2022, control implementation guidance, incident response policies, access control policies, supplier security, or any information security management system (ISMS) topic. Trigger even if the user doesn't say "skill" — any ISO 27001 or ISMS question should use this skill.

890 Updated 5 days ago
Sushegaad