Start here
How your ISMS works
The ISMS loop
An ISMS is not a tool but a control loop: you record what is worth protecting, assess the risks, take measures, check their effect and improve continuously (the “Plan–Do–Check–Act” principle of ISO 27001). The app mirrors exactly that loop — each domain covers one station:
| Station | What happens | Where in the app |
|---|---|---|
| Record assets | Create processes, information, ICT assets, infrastructure, suppliers and BSI modules as an inventory. | Assets & risks (Managing assets and risks) |
| Determine protection need | Rate confidentiality, integrity and availability (C/I/A) per asset — the highest value yields the protection need. | Assets & risks |
| Assess risks | Create risk scenarios and derive the risk category from likelihood × impact. | Assets & risks |
| Derive requirements | Record legal, regulatory and normative controls and track their completion (SoA). | Requirements (Maintaining requirements and the SoA) |
| Implement measures | Plan, implement and effectiveness-check concrete measures from risks, requirements and audit findings. | Measures (Implementing and reviewing measures) |
| Audit & improve | Run internal/external audits, document deviations and turn them into measures or risks. | Audits & nonconformities (Handling audits and nonconformities) |
| Document | Maintain policies, controlled documents and reports centrally — including approvals and read confirmations. | Confluence space “ISMS Home” (Using document control) |
Three core concepts that connect everything
Protection need (C/I/A)
Every asset is rated against three protection objectives: Confidentiality, Integrity and Availability. The protection need of an asset is the highest of the three values (“maximum principle”). Through asset hierarchies and links the protection need is inherited: the values of linked information objects act on the asset, and the highest value always wins.
Risk = likelihood × impact
A risk scenario is rated with two values from 1–4. Their product (max. 16) yields the risk category:
| Risk value (likelihood × impact) | Risk category |
|---|---|
| ≥ 12 | 🔴 4 - very high |
| ≥ 6 | 🟠 3 - high |
| ≥ 3 | 🟡 2 - medium |
| < 3 | 🟢 1 - low |
The app keeps two assessments: the current risk (today) and the target risk (after treatment). The same thresholds apply everywhere — on the issue, in the dashboard risk matrix and in the ISMS Agent’s answers.
RACI responsibilities
Every issue records who is Responsible, Accountable, Consulted or Informed. These roles drive the automatic notifications (Setting up notifications (RACI)) and the visibility of confidential issues (Roles and permissions). In addition, the hub keeps a role register for the organisation-wide roles — top management, information security officer (CISO), ISMS team, data protection officer, internal audit and continuity/BCM officer, each with deputies.
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20