🛡️
AI EngineeringHTML

ISM

by Sushegaad

ISM is an AI Engineering skill for Claude Code, published by Sushegaad in Claude-Skills-Governance-Risk-and-Compliance.

850 stars174 forkson Sushegaad/Claude-Skills-Governance-Risk-and-ComplianceAdded 2026/08/22+1% in starsRepository updated 2026/08/16
claude-aiclaude-skillscompliancecsrddata-privacydpdpa-2023eu-ai-actfedrampgdprgovernancegrchipaaiso27001iso27701iso42001nist-csfpci-dssrisksecuritysoc2
Install in seconds
Install ISM
Copy ISM into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/main/plugins/ism/skills/ism ~/.claude/skills/ism

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
plugins/ism/skills/ism/SKILL.md in Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Installs to
~/.claude/skills/ism
Collection
One of 25 skills cataloged from this repository
Category
AI Engineering2451 skills

What ISM does

ISM advises Australian government entities and supply chains on ASD Information Security Manual controls, gap analysis, authorisation, and IRAP preparation. It is used for compliance questions, security documentation, and classification-specific control selection.

ISM is cataloged under AI Engineering on DirSkills. ISM comes from a repository tagged claude-ai, claude-skills, compliance, csrd and data-privacy.

Documentation

README

Australian Information Security Manual (ISM) Skill

Last verified: 2026-08-15

You are an expert ISM compliance advisor assisting Australian government entities, contractors, and their supply chains in applying the ASD Information Security Manual (June 2026 release — ASD updates the ISM quarterly; always state which release an answer assumes) using a risk-based approach. Your primary audience is CISOs, CIOs, cybersecurity professionals, and IT managers.


How to Respond

Clarify the system's classification level and architecture context if not stated. Default to OFFICIAL: Sensitive (OS) for unspecified government systems.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about ISM

  • What else does Sushegaad publish alongside ISM?

    ISM is one of 25 skills that DirSkills catalogs from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, the repository it ships in. Its siblings there include CCPA CPRA Compliance Advisor, CIS Controls and CMMC Governance And Risk. Each one is a separate skill with its own page in this directory, installs the same way ISM does, and is maintained by Sushegaad in that same repository. The rest of the collection is listed on the Sushegaad/Claude-Skills-Governance-Risk-and-Compliance page.

  • How does ISM compare to other AI Engineering skills?

    ISM ranks #1545 by stars among the 2451 AI Engineering skills in this catalog. The most-starred ones next to it are Architecture Decision Records, AI-First Engineering and Agentic OS. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of ISM against them. Open each page to compare what they document and how they install.

More from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

ISM is one of 25 skills cataloged on DirSkills from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance.

See all 25 skills
🔒
1w ago

CCPA CPRA Compliance Advisor

CCPA CPRA Compliance Advisor helps assess California privacy-law applicability, classify data recipients, and handle consumer rights requests. It is used for notices, opt-outs, SPI limits, ADMT obligations, and gap checks for businesses handling California residents' data.
Writing
850174
🛡️
1w ago

CIS Controls

CIS Controls advises on CIS Controls v8 implementation, gap assessments, and safeguard guidance for organizations. Use it to scope Implementation Groups and map CIS Controls to frameworks like NIST CSF, ISO 27001, SOC 2, and CMMC.
SEO
850174
🛡️
1w ago

CMMC Governance And Risk

CMMC Governance And Risk helps defense contractors map CMMC 2.0, NIST SP 800-171, and DFARS requirements to the right assessment track. It is used for gap analysis, SSPs, POA&Ms, SPRS scoring, and subcontractor compliance decisions.
AI Engineering
850174
🌿
1w ago

CSRD

CSRD helps answer questions about EU sustainability reporting under the Corporate Sustainability Reporting Directive and ESRS. Use it for scope checks, double materiality, disclosures, gap assessments, and related compliance timelines.
SEO
850174
🛡️
1w ago

DORA

DORA advises on Regulation (EU) 2022/2554 for EU financial entities. Use it for ICT risk management, incident reporting, third-party risk, TLPT, and other digital operational resilience obligations.
AI Engineering
850174
🛡️
1w ago

DPDPA Compliance Advisor

DPDPA Compliance Advisor helps answer questions about India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025. Use it for consent, notices, rights requests, breach notification, children’s data, cross-border transfers, and compliance gap analysis.
Writing
850174