Atlassian app by maplee
ISMS with Jira & Confluence
The app sets up a complete information security management system in your Atlassian Cloud: a Jira project for risks, assets, actions, requirements, audits and nonconformities, plus a Confluence space with controlled documents. Designed for ISO 27001, with catalogs for GDPR and BSI IT-Grundschutz. Your data stays in Jira and Confluence.
Runs in your Atlassian Cloud on
1 Jira project — 17 issue types, 51 fields, 10 workflows
92 pages — Confluence space "ISMS Home"
13 automations — plus 3 reports on demand
01
What does the app set up in Jira and Confluence?
The app creates the project "ISMS Home" in your Jira Cloud with 17 issue types, 51 fields, 10 workflows and 30 filters. In Confluence it optionally creates the space "ISMS Home" with 92 prepared pages. Setup runs as a server-side job with a progress indicator and can be resumed after a failed step.
| Component | Scope |
|---|---|
| Jira project "ISMS Home" (key ISMS) | 1 project, as a Jira business project or as a Jira Service Management project |
| Issue types | 17: Epic, Requirement, Partial Requirement, Major Nonconformity, Minor Nonconformity, Opportunity for Improvement, Audit, Action, Corrective action, Risk Scenario, Information, Process, Supplier, ICT Asset, Infrastructure, Document, Control Round |
| Fields | 51 predefined fields with option values, protection-needs and risk logic |
| Workflows and statuses | 10 workflows with 32 statuses, distributed across the issue types |
| Screens and filters | 7 screens, 30 Jira filters |
| Confluence space "ISMS Home" (key ISMSTK) | 92 prepared pages: policy templates, controlled documents, registers, live Jira views |
| Automations | 13 in 4 groups, plus "Review Status & Escalation" |
| Reports | 3: Risk Report, Management Review, Statement of Applicability (SoA) |
| Content packs | ISO 27001 requirements catalog, GDPR core requirements, BSI IT-Grundschutz modules (demo selection), demo content, CSV import |
All objects are ordinary Jira issues and Confluence pages. They work with the permissions, search, filters and notifications your team already knows. The ISMS Hub, the app's user interface, is available in Jira, in Confluence and as a full-screen page; navigation runs from Dashboard and Explorer through the work areas to Automations, Notifications, Reports and Setup & Configuration.
Screenshots from the development environment with sample data.
02
Which work areas does the app cover?
Six work areas cover the core ISMS process: Risk Management, Asset Management, Measures Management, Requirements Management with the Statement of Applicability (SoA), Audit Management and Nonconformity Management. Each work area shows a "Needs attention" bar, tabs for open items, inline status transitions and multi-select with "Link items".
Risk Management. Risk Scenarios are rated by likelihood × impact (each 1 to 4), as a current and a target value. The risk category follows from the product: 12 and above very high, 6 and above high, 3 and above medium, below that low. Risk treatment (avoidance, reduction, acceptance) and next review are fields on the issue.
Asset Management. The inventory covers processes, information, ICT assets, infrastructure, suppliers and BSI modules. Each asset carries protection needs (C/I/A) and a flag for whether personal data is involved.
Measures Management. Actions and corrective actions are planned, implemented and tracked through to the effectiveness review. An automation with escalation stages monitors due dates.
Requirements Management. Requirements are structured by ISO clause and Annex A (A5 — Organisational controls, A6 — People controls, A7 — Physical controls, A8 — Technological controls). The Statement of Applicability (SoA) with review cycles is part of the work area; catalogs are imported with one click.
Audit Management. The audit programme under ISO 27001 §9.2 shows a calendar (quarter, year, 3 years) and a coverage matrix of ISO clauses × Annex A with the state planned, in progress or completed. Internal, external, certification and surveillance audits are managed together with their requests.
Nonconformity Management. Major nonconformities, minor nonconformities and opportunities for improvement are tracked through to closure. Their status is synchronised with the linked corrective actions, and deadlines are flagged 30 and 14 days ahead.
Screenshots from the development environment with sample data.
03
How do you keep the overview?
The dashboard has three views: "Top management" for the risk exposure, "ISMS team" as the full cockpit and "My view" for your own open items and documents. Every issue has a control detail page with RACI owners, review status and fulfilment; the Relationship Explorer shows the dependencies as a graph.
| View | Content |
|---|---|
| Top management | Risk exposure, risk trend, top risks, non-conformities & audits |
| ISMS team | Tiles per work area, Statement of Applicability in %, 4×4 risk matrix current/target, review cycle, action center, recent activity |
| My view | My open items and documents |
The control detail page summarises each issue: purpose & description, RACI owners (R/A/C/I), review & fulfilment with a traffic-light status, next review, fulfilment in percent, SoA applicability with justification, standard clause and Annex A. Control health is derived from review, evidence and fulfilment. Linked issues and the "Next action" sit directly below.
The Relationship Explorer shows the graph around an issue with selectable depth and the relationship types endangers, mitigates, protects, addresses, implements, uses, contains and parent of. A list view, zoom and search complement the graph.
The global search covers all ISMS issues. With "+ New ISMS item" you create any issue type from a single dialog, with search across all types and the most recently used types first.
Screenshots from the development environment with sample data.
04
What runs automatically?
13 automations in four groups calculate risk categories, inherit protection needs and personal-data flags, synchronise statuses and monitor deadlines. On top of that come the "Review Status & Escalation" automation, role-based RACI notifications and three reports generated as Confluence pages with one click. Jira admins enable or disable each rule individually and can start it manually.
| Group | Examples |
|---|---|
| Risk & Asset Management | Calculate risk category (likelihood × impact, current/target); inherit protection needs (C/I/A) by the maximum principle; inherit personal data; aggregate current/target |
| Measures Management | Due-date monitoring with escalation after 1, 3, 7 and 30 days, then monthly; reminder for the effectiveness review |
| Audit Nonconformities | Status sync action ↔ nonconformity; deadline monitoring 30 and 14 days before due |
| Requirements Management | Merge protection goals and InfoSec objectives from linked requirements; record the previous fulfilment value for before/after comparison |
| Review Status & Escalation | Traffic light 🟢/🟡/🔴 for all issues with a review interval; thresholds and escalation stages configurable |
Background runs take place daily and weekly; the risk trend is captured as a weekly snapshot.
Notifications (RACI). The app sends role-based e-mails to Responsible, Accountable, Consulted and Informed on status transitions and field alerts, without you maintaining Jira Automation rules. Each rule is configurable individually, and a master switch turns everything off at once.
Three reports on demand. Each report is stored as a Confluence page, as a dated snapshot and without duplicates on the same day.
| Report | Content |
|---|---|
| Risk Report | Categories, 4×4 matrix current/target, top risks, treatment including acceptances, actions, trend |
| Management Review | Meeting template under ISO 27001 9.3 with automatically populated sections: audits, nonconformities, risks, actions, objectives, suppliers |
| Statement of Applicability (SoA) | ISO 27001 6.1.3 d: all 93 Annex A controls with applicability, justification and implementation status |
Screenshots from the development environment with sample data.
05
How does document control work in Confluence?
Document control manages approval and read acknowledgement per Confluence page in the space "ISMS Home", with deadlines, reminders and a tamper-proof log. Every record is additionally stored as a Jira issue (Document and Control Round). The Hub shows controlled pages, open approvals, open acknowledgements and the acknowledgement rate.
- Approval rules: one approval is enough, everyone must approve, or majority.
- Read acknowledgement per page with deadlines and reminders; for a new page version you choose whether it must be acknowledged again: Ask, Always or Never.
- Log: name, timestamp and page version are recorded and cannot be changed afterwards.
- My tasks: the signed-in person's open approvals and acknowledgements in one place.
- Delivery: e-mails go through native Atlassian delivery, no external service.
The Confluence space "ISMS Home" (key ISMSTK) comes with 92 prepared pages. The top level covers InfoSec Management (objectives, KPIs, management reviews, stakeholder communication, SoA, legal register, internal and external issues, interested parties, RACI), Data Protection Management, Asset & Risk Management, Measures Management, Audit Management, Nonconformities, Requirements Management, Awareness Management and controlled documents such as the information security policy, ISMS scope and control of documents. Live Jira views on the pages show the current state of the project.
Screenshots from the development environment with sample data.
06
What can the ISMS Agent (Atlassian Rovo) do?
The ISMS Agent is an AI assistant built on Atlassian Rovo and part of the shipped app. It works exclusively on your own ISMS data; the language model is operated by Atlassian, and your data does not leave the Atlassian Cloud. It requires Rovo to be enabled on your Atlassian site.
Read and explain: overview of the ISMS, search, issue details, explanation of the risk model, SoA gap analysis against ISO 27001:2022 Annex A, search for missing evidence.
Write, only after your confirmation: create an issue, change fields, comment, transition status, save a document draft in Confluence.
There are three entry points: "Open ISMS Agent" in the Hub, "Explain this control, risk or measure" on the detail page and "Analyse this area" in every work area.
| Rule | Behaviour |
|---|---|
| Consent | No change without confirmation by the user |
| Permissions | The agent acts with the permissions of the signed-in person |
| Labelling | AI contributions carry the label ai-assisted |
| Evidence | Answers point to issues and pages instead of making claims |
| Limits | Deletes nothing, changes no permissions, reads no file attachments |
07
Which standards and regulations is the app suited for?
The app is designed for ISO 27001, including Annex A and the Statement of Applicability. The content packs include an ISO 27001 requirements catalog, 22 GDPR core obligations and a demo selection of BSI IT-Grundschutz modules. Requirements from NIS2, DORA, TISAX or customer requirements are mapped via CSV import or manually as Requirement issues.
| Framework | Mapping in the app |
|---|---|
| ISO 27001 | Requirements catalog for clauses 4–10 (paraphrased) and 93 Annex A controls, SoA-ready; audit programme under §9.2; Management Review under 9.3 |
| GDPR | Catalog with 22 core obligations (Art. 5–49, paraphrased; not legal advice) |
| BSI IT-Grundschutz | Demo selection of modules as assets in the inventory |
| NIS2, DORA, TISAX, customer requirements | No dedicated catalog; requirements via CSV import (max. 200 rows per run, label custom-control) or manually as Requirement issues |
For the DORA Register of Information, maplee offers a separate product: DORA Register of Information.
Screenshots from the development environment with sample data.
08
Where does your data live and what do you need?
The app is an Atlassian Forge app and runs entirely in your Atlassian Cloud. There is no maplee server and no data outside Jira and Confluence. You need Jira Cloud; Confluence Cloud is optional and is required for the Confluence space and document control.
| Topic | Fact |
|---|---|
| Platform | Atlassian Forge; execution and storage in your Atlassian Cloud |
| Prerequisites | Jira Cloud required; Confluence Cloud optional (Confluence space, document control, reports as pages); Rovo optional for the ISMS Agent |
| Languages | German and English; chosen before installation, a later switch renames project, fields, statuses, issue types, workflows, filters and Confluence, reversible and without data loss |
| Project type | Jira business project (default, no JSM licence) or Jira Service Management project (opt-in, with queues and customer portal) |
| Roles & responsibilities | Role register with Top management (mandatory), Information security officer (CISO) (mandatory), ISMS team, Data protection officer (DPO), Internal audit, Continuity/BCM officer; each with holders, deputies and groups; scope via user groups with read access to the document space |
| Administration | Setup, automations, field options and licence for Jira admins only |
| Licence and pricing | Via the Atlassian Marketplace, free trial; pricing on the Atlassian Marketplace |
| Uninstallation | Clean uninstallation with a full teardown of the created objects |
Screenshots from the development environment with sample data.
09
How do you get started?
You install the app from the Atlassian Marketplace, choose language and project type and let it set up "ISMS Home". Guided onboarding produces a preliminary readiness score; after that you import the ISO 27001 catalog or your own requirements. If you want support with the rollout, maplee accompanies the implementation.
- Install and set up. Install the app from the Atlassian Marketplace, choose language and project type, start the installation of "ISMS Home". The job runs server-side with a progress indicator.
- Complete onboarding. Profile (company, industry, size, locations, systems, data types), ISMS scope and self-assessment on leadership, roles, risks, assets, access, suppliers, incidents and continuity. The result is your preliminary readiness score.
- Load content and fill roles. Import the ISO 27001 catalog, GDPR core requirements or your own controls via CSV, fill Roles & responsibilities, create the first Risk Scenarios and assets.
Product plus implementation from a single provider. maplee develops the app and advises on the rollout. Matching services:
- Atlassian ISMS Assessment: review of your Atlassian environment and rollout plan.
- ISO 27001 Gap Analysis: comparison of your current state with the requirements of the standard.
- NIS2 Readiness Workshop: assessment of whether you are affected and derivation of the requirements.
All services are listed under Services.
Screenshots from the development environment with sample data.
Frequently asked questions
Do I need Jira Service Management?
Do I need Confluence?
Where does the data live?
Do I need Rovo for the ISMS Agent?
Can I switch the language later?
Can I map NIS2, DORA or TISAX?
Can I keep using my existing Jira projects?
What happens on uninstallation?
Try the app in your Atlassian Cloud
Install "ISMS with Jira & Confluence" from the Atlassian Marketplace and set up "ISMS Home" in your own environment. Pricing on the Atlassian Marketplace.
maplee is not an Atlassian partner. Jira & Confluence are products of Atlassian.