Start here

How your ISMS works

The ISMS loop

An ISMS is not a tool but a control loop: you record what is worth protecting, assess the risks, take measures, check their effect and improve continuously (the “Plan–Do–Check–Act” principle of ISO 27001). The app mirrors exactly that loop — each domain covers one station:

StationWhat happensWhere in the app
Record assetsCreate processes, information, ICT assets, infrastructure, suppliers and BSI modules as an inventory.Assets & risks (Managing assets and risks)
Determine protection needRate confidentiality, integrity and availability (C/I/A) per asset — the highest value yields the protection need.Assets & risks
Assess risksCreate risk scenarios and derive the risk category from likelihood × impact.Assets & risks
Derive requirementsRecord legal, regulatory and normative controls and track their completion (SoA).Requirements (Maintaining requirements and the SoA)
Implement measuresPlan, implement and effectiveness-check concrete measures from risks, requirements and audit findings.Measures (Implementing and reviewing measures)
Audit & improveRun internal/external audits, document deviations and turn them into measures or risks.Audits & nonconformities (Handling audits and nonconformities)
DocumentMaintain policies, controlled documents and reports centrally — including approvals and read confirmations.Confluence space “ISMS Home” (Using document control)

Three core concepts that connect everything

Protection need (C/I/A)

Every asset is rated against three protection objectives: Confidentiality, Integrity and Availability. The protection need of an asset is the highest of the three values (“maximum principle”). Through asset hierarchies and links the protection need is inherited: the values of linked information objects act on the asset, and the highest value always wins.

Risk = likelihood × impact

A risk scenario is rated with two values from 1–4. Their product (max. 16) yields the risk category:

Risk value (likelihood × impact)Risk category
≥ 12🔴 4 - very high
≥ 6🟠 3 - high
≥ 3🟡 2 - medium
< 3🟢 1 - low

The app keeps two assessments: the current risk (today) and the target risk (after treatment). The same thresholds apply everywhere — on the issue, in the dashboard risk matrix and in the ISMS Agent’s answers.

Risk Management: “Needs attention” bar, tabs and the list of Risk Scenarios with “Current Risk Category”, “Target Risk Category”, “Risk Treatment” and “Next review”.

RACI responsibilities

Every issue records who is Responsible, Accountable, Consulted or Informed. These roles drive the automatic notifications (Setting up notifications (RACI)) and the visibility of confidential issues (Roles and permissions). In addition, the hub keeps a role register for the organisation-wide roles — top management, information security officer (CISO), ISMS team, data protection officer, internal audit and continuity/BCM officer, each with deputies.

Control detail view: “Responsibilities” (RACI), “Review & fulfilment” with fulfilment level and SoA applicability, plus “Linked items”.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20