Atlassian app by maplee

ISMS with Jira & Confluence

The app sets up a complete information security management system in your Atlassian Cloud: a Jira project for risks, assets, actions, requirements, audits and nonconformities, plus a Confluence space with controlled documents. Designed for ISO 27001, with catalogs for GDPR and BSI IT-Grundschutz. Your data stays in Jira and Confluence.

Runs in your Atlassian Cloud on

JiraConfluenceAtlassian Rovo
"ISMS team" dashboard: tiles per work area, current/target risk matrix, SoA progress and action center. Screenshot from the development environment with sample data.

1 Jira project — 17 issue types, 51 fields, 10 workflows

92 pages — Confluence space "ISMS Home"

13 automations — plus 3 reports on demand

01

What does the app set up in Jira and Confluence?

The app creates the project "ISMS Home" in your Jira Cloud with 17 issue types, 51 fields, 10 workflows and 30 filters. In Confluence it optionally creates the space "ISMS Home" with 92 prepared pages. Setup runs as a server-side job with a progress indicator and can be resumed after a failed step.

ComponentScope
Jira project "ISMS Home" (key ISMS)1 project, as a Jira business project or as a Jira Service Management project
Issue types17: Epic, Requirement, Partial Requirement, Major Nonconformity, Minor Nonconformity, Opportunity for Improvement, Audit, Action, Corrective action, Risk Scenario, Information, Process, Supplier, ICT Asset, Infrastructure, Document, Control Round
Fields51 predefined fields with option values, protection-needs and risk logic
Workflows and statuses10 workflows with 32 statuses, distributed across the issue types
Screens and filters7 screens, 30 Jira filters
Confluence space "ISMS Home" (key ISMSTK)92 prepared pages: policy templates, controlled documents, registers, live Jira views
Automations13 in 4 groups, plus "Review Status & Escalation"
Reports3: Risk Report, Management Review, Statement of Applicability (SoA)
Content packsISO 27001 requirements catalog, GDPR core requirements, BSI IT-Grundschutz modules (demo selection), demo content, CSV import

All objects are ordinary Jira issues and Confluence pages. They work with the permissions, search, filters and notifications your team already knows. The ISMS Hub, the app's user interface, is available in Jira, in Confluence and as a full-screen page; navigation runs from Dashboard and Explorer through the work areas to Automations, Notifications, Reports and Setup & Configuration.

Setup & Configuration: language, project type, installation of "ISMS Home", modules and content packs (interface shown in German).

Screenshots from the development environment with sample data.

02

Which work areas does the app cover?

Six work areas cover the core ISMS process: Risk Management, Asset Management, Measures Management, Requirements Management with the Statement of Applicability (SoA), Audit Management and Nonconformity Management. Each work area shows a "Needs attention" bar, tabs for open items, inline status transitions and multi-select with "Link items".

Risk Management. Risk Scenarios are rated by likelihood × impact (each 1 to 4), as a current and a target value. The risk category follows from the product: 12 and above very high, 6 and above high, 3 and above medium, below that low. Risk treatment (avoidance, reduction, acceptance) and next review are fields on the issue.

Asset Management. The inventory covers processes, information, ICT assets, infrastructure, suppliers and BSI modules. Each asset carries protection needs (C/I/A) and a flag for whether personal data is involved.

Measures Management. Actions and corrective actions are planned, implemented and tracked through to the effectiveness review. An automation with escalation stages monitors due dates.

Requirements Management. Requirements are structured by ISO clause and Annex A (A5 — Organisational controls, A6 — People controls, A7 — Physical controls, A8 — Technological controls). The Statement of Applicability (SoA) with review cycles is part of the work area; catalogs are imported with one click.

Audit Management. The audit programme under ISO 27001 §9.2 shows a calendar (quarter, year, 3 years) and a coverage matrix of ISO clauses × Annex A with the state planned, in progress or completed. Internal, external, certification and surveillance audits are managed together with their requests.

Nonconformity Management. Major nonconformities, minor nonconformities and opportunities for improvement are tracked through to closure. Their status is synchronised with the linked corrective actions, and deadlines are flagged 30 and 14 days ahead.

Risk Management: "Needs attention" bar, tabs and inline status transitions for Risk Scenarios.
Asset Management: inventory with asset category, protection needs (C/I/A) and personal data.
Measures Management: actions and corrective actions through to the effectiveness review.
Requirements Management: structure by standard, tabs for Review due, SoA pending and Renewal due.
Audit Management: coverage matrix ISO clauses × Annex A (interface shown in German).
Nonconformity Management: major and minor nonconformities plus opportunities for improvement through to closure.

Screenshots from the development environment with sample data.

03

How do you keep the overview?

The dashboard has three views: "Top management" for the risk exposure, "ISMS team" as the full cockpit and "My view" for your own open items and documents. Every issue has a control detail page with RACI owners, review status and fulfilment; the Relationship Explorer shows the dependencies as a graph.

ViewContent
Top managementRisk exposure, risk trend, top risks, non-conformities & audits
ISMS teamTiles per work area, Statement of Applicability in %, 4×4 risk matrix current/target, review cycle, action center, recent activity
My viewMy open items and documents

The control detail page summarises each issue: purpose & description, RACI owners (R/A/C/I), review & fulfilment with a traffic-light status, next review, fulfilment in percent, SoA applicability with justification, standard clause and Annex A. Control health is derived from review, evidence and fulfilment. Linked issues and the "Next action" sit directly below.

The Relationship Explorer shows the graph around an issue with selectable depth and the relationship types endangers, mitigates, protects, addresses, implements, uses, contains and parent of. A list view, zoom and search complement the graph.

The global search covers all ISMS issues. With "+ New ISMS item" you create any issue type from a single dialog, with search across all types and the most recently used types first.

"Top management" view: risk exposure and trend without operational detail (interface shown in German).
Control detail page: RACI, review & fulfilment, SoA applicability, linked issues.
Relationship Explorer: dependencies between risks, assets, requirements and actions.

Screenshots from the development environment with sample data.

04

What runs automatically?

13 automations in four groups calculate risk categories, inherit protection needs and personal-data flags, synchronise statuses and monitor deadlines. On top of that come the "Review Status & Escalation" automation, role-based RACI notifications and three reports generated as Confluence pages with one click. Jira admins enable or disable each rule individually and can start it manually.

GroupExamples
Risk & Asset ManagementCalculate risk category (likelihood × impact, current/target); inherit protection needs (C/I/A) by the maximum principle; inherit personal data; aggregate current/target
Measures ManagementDue-date monitoring with escalation after 1, 3, 7 and 30 days, then monthly; reminder for the effectiveness review
Audit NonconformitiesStatus sync action ↔ nonconformity; deadline monitoring 30 and 14 days before due
Requirements ManagementMerge protection goals and InfoSec objectives from linked requirements; record the previous fulfilment value for before/after comparison
Review Status & EscalationTraffic light 🟢/🟡/🔴 for all issues with a review interval; thresholds and escalation stages configurable

Background runs take place daily and weekly; the risk trend is captured as a weekly snapshot.

Notifications (RACI). The app sends role-based e-mails to Responsible, Accountable, Consulted and Informed on status transitions and field alerts, without you maintaining Jira Automation rules. Each rule is configurable individually, and a master switch turns everything off at once.

Three reports on demand. Each report is stored as a Confluence page, as a dated snapshot and without duplicates on the same day.

ReportContent
Risk ReportCategories, 4×4 matrix current/target, top risks, treatment including acceptances, actions, trend
Management ReviewMeeting template under ISO 27001 9.3 with automatically populated sections: audits, nonconformities, risks, actions, objectives, suppliers
Statement of Applicability (SoA)ISO 27001 6.1.3 d: all 93 Annex A controls with applicability, justification and implementation status
Automations: each rule can be switched on or off and started manually.
Reports: three snapshots as Confluence pages.

Screenshots from the development environment with sample data.

05

How does document control work in Confluence?

Document control manages approval and read acknowledgement per Confluence page in the space "ISMS Home", with deadlines, reminders and a tamper-proof log. Every record is additionally stored as a Jira issue (Document and Control Round). The Hub shows controlled pages, open approvals, open acknowledgements and the acknowledgement rate.

  • Approval rules: one approval is enough, everyone must approve, or majority.
  • Read acknowledgement per page with deadlines and reminders; for a new page version you choose whether it must be acknowledged again: Ask, Always or Never.
  • Log: name, timestamp and page version are recorded and cannot be changed afterwards.
  • My tasks: the signed-in person's open approvals and acknowledgements in one place.
  • Delivery: e-mails go through native Atlassian delivery, no external service.

The Confluence space "ISMS Home" (key ISMSTK) comes with 92 prepared pages. The top level covers InfoSec Management (objectives, KPIs, management reviews, stakeholder communication, SoA, legal register, internal and external issues, interested parties, RACI), Data Protection Management, Asset & Risk Management, Measures Management, Audit Management, Nonconformities, Requirements Management, Awareness Management and controlled documents such as the information security policy, ISMS scope and control of documents. Live Jira views on the pages show the current state of the project.

Document control: metrics and list of controlled pages in the space "ISMS Home".
"My tasks": the signed-in person's open approvals and read acknowledgements (interface shown in German).

Screenshots from the development environment with sample data.

06

What can the ISMS Agent (Atlassian Rovo) do?

The ISMS Agent is an AI assistant built on Atlassian Rovo and part of the shipped app. It works exclusively on your own ISMS data; the language model is operated by Atlassian, and your data does not leave the Atlassian Cloud. It requires Rovo to be enabled on your Atlassian site.

Read and explain: overview of the ISMS, search, issue details, explanation of the risk model, SoA gap analysis against ISO 27001:2022 Annex A, search for missing evidence.

Write, only after your confirmation: create an issue, change fields, comment, transition status, save a document draft in Confluence.

There are three entry points: "Open ISMS Agent" in the Hub, "Explain this control, risk or measure" on the detail page and "Analyse this area" in every work area.

RuleBehaviour
ConsentNo change without confirmation by the user
PermissionsThe agent acts with the permissions of the signed-in person
LabellingAI contributions carry the label ai-assisted
EvidenceAnswers point to issues and pages instead of making claims
LimitsDeletes nothing, changes no permissions, reads no file attachments

07

Which standards and regulations is the app suited for?

The app is designed for ISO 27001, including Annex A and the Statement of Applicability. The content packs include an ISO 27001 requirements catalog, 22 GDPR core obligations and a demo selection of BSI IT-Grundschutz modules. Requirements from NIS2, DORA, TISAX or customer requirements are mapped via CSV import or manually as Requirement issues.

FrameworkMapping in the app
ISO 27001Requirements catalog for clauses 4–10 (paraphrased) and 93 Annex A controls, SoA-ready; audit programme under §9.2; Management Review under 9.3
GDPRCatalog with 22 core obligations (Art. 5–49, paraphrased; not legal advice)
BSI IT-GrundschutzDemo selection of modules as assets in the inventory
NIS2, DORA, TISAX, customer requirementsNo dedicated catalog; requirements via CSV import (max. 200 rows per run, label custom-control) or manually as Requirement issues

For the DORA Register of Information, maplee offers a separate product: DORA Register of Information.

Requirements Management after importing the ISO 27001 catalog.

Screenshots from the development environment with sample data.

08

Where does your data live and what do you need?

The app is an Atlassian Forge app and runs entirely in your Atlassian Cloud. There is no maplee server and no data outside Jira and Confluence. You need Jira Cloud; Confluence Cloud is optional and is required for the Confluence space and document control.

TopicFact
PlatformAtlassian Forge; execution and storage in your Atlassian Cloud
PrerequisitesJira Cloud required; Confluence Cloud optional (Confluence space, document control, reports as pages); Rovo optional for the ISMS Agent
LanguagesGerman and English; chosen before installation, a later switch renames project, fields, statuses, issue types, workflows, filters and Confluence, reversible and without data loss
Project typeJira business project (default, no JSM licence) or Jira Service Management project (opt-in, with queues and customer portal)
Roles & responsibilitiesRole register with Top management (mandatory), Information security officer (CISO) (mandatory), ISMS team, Data protection officer (DPO), Internal audit, Continuity/BCM officer; each with holders, deputies and groups; scope via user groups with read access to the document space
AdministrationSetup, automations, field options and licence for Jira admins only
Licence and pricingVia the Atlassian Marketplace, free trial; pricing on the Atlassian Marketplace
UninstallationClean uninstallation with a full teardown of the created objects
Roles & responsibilities: holders, deputies and groups per role.

Screenshots from the development environment with sample data.

09

How do you get started?

You install the app from the Atlassian Marketplace, choose language and project type and let it set up "ISMS Home". Guided onboarding produces a preliminary readiness score; after that you import the ISO 27001 catalog or your own requirements. If you want support with the rollout, maplee accompanies the implementation.

  1. Install and set up. Install the app from the Atlassian Marketplace, choose language and project type, start the installation of "ISMS Home". The job runs server-side with a progress indicator.
  2. Complete onboarding. Profile (company, industry, size, locations, systems, data types), ISMS scope and self-assessment on leadership, roles, risks, assets, access, suppliers, incidents and continuity. The result is your preliminary readiness score.
  3. Load content and fill roles. Import the ISO 27001 catalog, GDPR core requirements or your own controls via CSV, fill Roles & responsibilities, create the first Risk Scenarios and assets.

Product plus implementation from a single provider. maplee develops the app and advises on the rollout. Matching services:

All services are listed under Services.

Onboarding: profile, ISMS scope and self-assessment with a preliminary readiness score (interface shown in German).
"+ New ISMS item": one dialog for all 17 issue types (interface shown in German).

Screenshots from the development environment with sample data.

Frequently asked questions

Do I need Jira Service Management?
No. The default is a Jira business project without a JSM licence. If you want queues and a customer portal, you can opt in to create "ISMS Home" as a Jira Service Management project.
Do I need Confluence?
Jira Cloud is required, Confluence Cloud is optional. The Confluence space "ISMS Home" with 92 pages, document control and the reports as Confluence pages require Confluence.
Where does the data live?
In your Atlassian Cloud. The app is a Forge app without its own server; all objects are Jira issues and Confluence pages. E-mails go through native Atlassian delivery.
Do I need Rovo for the ISMS Agent?
Yes. The ISMS Agent is built on Atlassian Rovo and requires Rovo to be enabled on your Atlassian site. All other functions of the app work without Rovo.
Can I switch the language later?
Yes. The content language is chosen before installation. A later switch renames project, fields, statuses, issue types, workflows, filters and the Confluence space, reversible and without data loss.
Can I map NIS2, DORA or TISAX?
The app has no dedicated catalog for NIS2, DORA or TISAX. You map such requirements via CSV import (max. 200 rows per run) or manually as Requirement issues. For the DORA Register of Information there is a separate maplee product.
Can I keep using my existing Jira projects?
Yes. The app creates its own project "ISMS Home" and does not change existing projects. Issues from other projects can be connected to ISMS issues through Jira issue links.
What happens on uninstallation?
The app offers a clean uninstallation with a full teardown of the created objects. A Jira admin triggers it from "Setup & Configuration".

Try the app in your Atlassian Cloud

Install "ISMS with Jira & Confluence" from the Atlassian Marketplace and set up "ISMS Home" in your own environment. Pricing on the Atlassian Marketplace.

maplee is not an Atlassian partner. Jira & Confluence are products of Atlassian.