ISO 27001 AI Security MCP

by csoai-org

Not rated
GitHub

About

ISO 27001 information security compliance — control assessment, risk treatment, SoA generation by MEOK AI Labs

Details

Author
csoai-org
Categories
Other, Security

Setup

Install ISO 27001 AI Security MCP in your MCP client (Claude Desktop, Cursor, Windsurf, and others).

Repository: https://github.com/csoai-org/iso-27001-ai-mcp

Follow the installation instructions in the repository README, then restart your MCP client.

ISO 27001 information security compliance — control assessment, risk treatment, SoA generation by MEOK AI Labs

⚖️ Built byMEOK AI Labs/CSOAI.Need this applied toyoursystem fast? Book a 30-min Founder Office Hour (£29) →https://meok.ai/work· Full governance platform →https://meok.ai

# Install via pip pip install iso_27001_ai_mcp # Or install via Smithery npx -y @smithery/cli@latest install iso-27001-ai-mcp --client claude

- MCP protocol compliant
- Easy installation
- Well-documented API
- Production-ready
- Active maintenance

- Full Documentation
-
API Reference
-
EU AI Act Compliance Guide

This MCP server is built withEU AI Act compliancebuilt-in:

- ✅ Article 9 — Risk Management System
- ✅ Article 13 — Transparency & Instructions for Use
- ✅ Article 15 — Bias Detection & Testing
- ✅ Article 26 — FRIA Support (where applicable)
- ✅ Article 50 — AI Content Watermarking (where applicable)

Need help getting compliant?Book a free 15-min diagnostic →

Need custom development, SLA guarantees, or white-label deployment?

- Pro:$99/mo — Full MCP suite + EU AI Act tracking
- Enterprise:$499/mo — Custom dev + SLA + Dedicated support

This server is part of theMEOK AI Labsecosystem — 300+ MCP servers for sovereign AI governance.

Built with 💜 byMEOK AI Labs· UK Companies House 16939677

ISO/IEC 27001:2022 compliance assessment for AI systems — 93 Annex A controls across 4 themes, ISO 27005 risk assessment, Statement of Applicability generation, incident classification, and ISO 42001 bridge.

ISO/IEC 27001:2022 is the international standard for Information Security Management Systems (ISMS). Its Annex A contains93 controlsorganized into4 themes: Organizational (37 controls), People (8), Physical (14), and Technological (34). Certification requires demonstrating that your ISMS meets clauses 4–10 and that your Statement of Applicability (SoA) addresses all relevant controls.

For AI systems, ISO 27001 is foundational — but it needs extension. This server audits your ISMS against all 93 controls, performs ISO 27005 risk assessments with AI-specific threat scenarios, generates gap analyses with prioritized remediation roadmaps, produces SoAs, classifies security incidents, and bridges to ISO 42001 for AI-specific governance.

Use the audit_isms tool with: organization_context: "AI startup with 150 employees building ML models for healthcare diagnostics. Uses AWS for infrastructure, processes patient data, has a small security team." scope_description: "All AI systems, ML pipelines, patient data processing, cloud infrastructure, and development environments" controls_implemented: ["A.5.1", "A.5.9", "A.5.12", "A.5.15", "A.5.24", "A.6.3", "A.8.5", "A.8.7", "A.8.8", "A.8.15", "A.8.24"]

Expected output:Overall coverage ~12% (11/93 controls). Critical gaps flagged in A.5.34 (PII protection), A.8.12 (data leakage prevention), A.8.25 (secure SDLC). Certification NOT ready — 82 gaps to address.

Use the risk_assessment tool with: system_description: "Production ML pipeline processing financial data for fraud detection. Uses gradient boosting models trained on 10M+ transaction records. Served via REST API with 99.9% SLA." assets: ["training data", "ML model weights", "feature store", "API keys", "model serving infrastructure", "customer transaction data"] existing_controls: ["A.5.15", "A.8.5", "A.8.15", "A.8.24"]

Expected output:Risk register with 10 threat assessments. Highest risks: training data breach (likely × high = risk score 16), model theft (possible × critical = 20). Treatment plan recommends implementing A.8.12, A.8.16, A.5.12 for the highest-priority gaps.

Generate a gap analysis for AI-focused certification

Use the gap_analysis tool with: current_controls: ["A.5.1", "A.5.2", "A.5.15", "A.5.24", "A.6.3", "A.8.5", "A.8.7", "A.8.15", "A.8.16", "A.8.24"] target_certification: "ai-focused"

Expected output:25 AI-critical controls evaluated. ~40% coverage. Phase 1 critical gaps: A.8.8 (vulnerability management), A.8.12 (data leakage), A.5.34 (PII protection). Estimated remediation: 3–6 months.

Classify a security incident involving AI

Use the incident_classification tool with: incident_description: "Adversarial evasion attack detected on production fraud detection model. Attackers crafted transactions that bypassed ML model scoring. Approximately 200 fraudulent transactions processed before detection." affected_assets: ["fraud detection model", "transaction processing system", "customer accounts"] detection_method: "automated" data_breach: false ai_system_involved: true

Expected output:Severity HIGH (P1), AI incident category: adversarial attack. Immediate response: activate incident plan (A.5.24), contain model, preserve inference logs, assess model integrity. AI-specific controls: A.5.7, A.8.8, A.8.16.

{ "mcpServers": { "iso-27001-ai": { "command": "npx", "args": ["-y", "meok-iso-27001-ai-mcp"] } } }
npx smithery mcp add nicholastempleman/iso-27001-ai-mcp
{ "mcpServers": { "iso-27001-ai": { "command": "npx", "args": ["-y", "meok-iso-27001-ai-mcp"] } } }
{ "servers": { "iso-27001-ai": { "command": "npx", "args": ["-y", "meok-iso-27001-ai-mcp"] } } }

- Free tier:10 calls/day per tool
- Pro:£79/mo — unlimited calls + cryptographically signed compliance attestations

💸 Try MEOK in 30 seconds — instant buy ladder

Refundable. UK Stripe — VAT-clean. Builds on the 81-MCP MEOK fleet. Verify any signed report athttps://meok.ai/verify.

KHEPRA MCP Server smithery badge MCP Registry License Container PQC Sovereign compliance engine with 36,195 STIG/CCI/NIST/CMMC mappings. Air-gappable. Zero token costs. Run ert_scan → get a Godfather Report with dollar-denominated business impact. The only MCP compliance server that runs on your metal — with the World's First DoD PQC STIG built in. PQC-01-STIG-V1R1 — Full Whitepaper → 17 controls covering CNSA 2.0, FIPS 203/204/205, and the NSA's May 2026 MCP security advisory. The world's first DoD-style Post-Quantum Cryptography STIG, including the first PQC controls for agentic AI and MCP deployments.

Comprehensive audit logging for agent-to-agent interactions — immutable event trails, tamper-evident hashing, structured log export (SIEM-compatible), and compliance-grade retention for regulated industries.

Cryptographic runtime governance for AI agents. 20 tools. Sealed policy artifacts, continuous measurement, tamper-evident proof. Ed25519 + SHA-256.

AI Agent Supply Chain Security - Intercepts and validates every package installation, git clone, and script download triggered by AI coding agents before it executes.

AI Bill of Materials generation — model cards, dataset provenance, supply chain transparency, CycloneDX format by MEOK AI Labs

Structured AI incident reporting for EU AI Act Article 62 — generates mandatory incident reports, severity classification, root cause analysis, and regulator-ready submissions for serious AI incidents.

AI incident detection, classification, and regulatory reporting — covers EU AI Act Article 62, NIST AI RMF, and OECD frameworks

Enforces organisational AI usage policies at the agent layer — blocks prohibited model calls, enforces data residency rules, logs policy violations, and ensures AI governance policies are machine-executable.

AI agent governance with quantum-safe audit trails and three-tier policy enforcement

Verify HMAC-signed compliance attestations from any MEOK MCP server — checks cryptographic signatures, validates timestamps, and produces verifiable trust chains for AI compliance audits.

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.