CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/iso27001-test-patterns

Reference catalog of ISO/IEC 27001:2022 Annex A test patterns: testable technical controls with code-level assertions for access control (A.8.2-A.8.5), logging and monitoring (A.8.15-A.8.16), cryptography (A.8.24), and secure development (A.8.25-A.8.31), plus evidence patterns for Stage 1 and Stage 2 certification audits and Statement of Applicability scoping. The full 93-control Annex A index (four themes: organizational A.5, people A.6, physical A.7, technological A.8) and the exhaustive per-control test code live in references/. Use when authoring ISMS test coverage for an ISO 27001:2022 certification engagement or gap assessment.

74

Quality

93%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured reference skill: executable worked example, clear sequenced workflow, an explicit validation gate, and textbook progressive disclosure into two real reference files. The only weakness is conciseness — repeated inline date citations and some background context Claude already knows.

Suggestions

Centralize the 'isms.online ... (fetched 2026-06-04)' provenance into a single References note instead of repeating the date inline six times; it adds tokens without aiding the task.

Trim the Overview's explanation of the 114-to-93 control restructuring — Claude already knows ISO 27001 history; keep the four-theme count table and drop the narrative around it.

Move the repeated 'API names are placeholders' caveat to the How-to-use step that introduces adaptation, so it is stated once rather than re-explained in the worked example and Limitations.

DimensionReasoningScore

Conciseness

Mostly efficient with actionable tables and executable code, but the Overview explains the 114-to-93-control restructuring (background Claude already knows) and the inline '(fetched 2026-06-04)' citation is repeated ~6 times rather than centralized. Not 3 because some tokens are spent on known context and repeated date stamps; not 1 because the core is lean and reference-driven.

2 / 3

Actionability

The A.8.5 worked example is fully executable Python (pyotp, real status-code/session-token assertions) and the summary table maps each control to a concrete assertion, with the per-control code offloaded to a real reference file. Placeholder API names are explicitly flagged as needing adaptation, which is justified flexibility.

3 / 3

Workflow Clarity

The 'How to use' section is a clearly sequenced 6-step process, the worked example follows an Arrange/Assert-negative/Assert-positive/Emit-evidence pattern, and the SoA section includes an explicit validation gate ('refuses to accept scope exclusions without all four required fields'). Not 2 because sequencing and a checkpoint are both present.

3 / 3

Progressive Disclosure

SKILL.md is a genuine overview — summary table plus one worked example — pointing one level deep to two real, clearly signaled reference files (annex-a-control-index.md, technical-control-test-patterns.md, both verified present). Navigation is easy and bulk is appropriately split.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that states concrete capabilities, names a precise niche, and gives an explicit 'Use when' trigger in third person. It is somewhat dense with control-ID enumerations but that density is specificity, not fluff.

DimensionReasoningScore

Specificity

Lists multiple concrete actions across named control clusters — 'testable technical controls with code-level assertions for access control (A.8.2-A.8.5), logging and monitoring (A.8.15-A.8.16), cryptography (A.8.24), and secure development (A.8.25-A.8.31)' plus 'evidence patterns for Stage 1 and Stage 2 certification audits and Statement of Applicability scoping'.

3 / 3

Completeness

Explicitly answers both what ('Reference catalog of ... test patterns') and when ('Use when authoring ISMS test coverage for an ISO 27001:2022 certification engagement or gap assessment'). Not 2 because the trigger clause is explicit, not merely implied.

3 / 3

Trigger Term Quality

Natural terms a certification user would say are well covered — 'ISO 27001', 'Annex A', 'ISMS test coverage', 'certification engagement', 'gap assessment', 'Statement of Applicability'. Not the level below because common variations are present rather than just one keyword.

3 / 3

Distinctiveness Conflict Risk

The ISO/IEC 27001:2022 Annex A test-pattern niche is highly specific and unlikely to trigger for the wrong skill; sister skills (soc2, gdpr) are named, reinforcing a clear boundary.

3 / 3

Total

12

/

12

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

Total

15

/

16

Passed

Reviewed

Table of Contents