Running the ISMS

Domains and issue types

Purpose

After installation there is one Jira project, “ISMS Home” (key ISMS), and one Confluence space. All four domains live inside the same project and are distinguished by the issue type. This page explains the building blocks; the recurring workflows per domain follow on the next pages.

The 17 issue types

DomainIssue typeWhat for
RequirementsEpicContainer for the chapters of the requirement structure (clause / Annex A) — the only container level above the issues
RequirementA security requirement or control
Partial RequirementSub-item of a requirement (subtask)
Audits & nonconformitiesAuditAn audit file — findings are attached via the “found in” link
Major NonconformityAbsence or complete breakdown of a required system or critical requirement
Minor NonconformityPartial fulfilment of a requirement, a once-off failure
Opportunity for ImprovementSuggestion beyond the minimum requirement (OFI)
MeasuresActionA planned security measure to be implemented
Corrective actionResponse to an identified deviation
Assets & risksRisk ScenarioAn assessed risk with a current and a target value
InformationInformation object with protection need and personal-data flag
ProcessAsset type: business or supporting process
SupplierAsset type: supplier / service provider
ICT AssetAsset type: hardware, software, application, platform
InfrastructureAsset type: buildings, networks, data centres, cloud environments
Document controlDocumentCollector issue per controlled Confluence document — carrier of the notifications (Using document control)
Control RoundSubtask under the Document issue — a single approval or confirmation round
ISMS Hub: type picker “Create a new ISMS item” with the search field “Search issue types…” and issue types grouped by work area.

Besides the Jira standard link “relates to”, the app creates four directed link types of its own:

Link typeReads as (outward / inward)Typically between
Mitigation“mitigates” / “is mitigated by”Action → Risk Scenario
Endangerment“endangers” / “is endangered by”Risk Scenario → asset or information
Processing“processes” / “is processed by”Asset (e.g. process) → Information
Audit finding“found in” / “has finding”Nonconformity → Audit

The direction is binding: “Action mitigates risk” is correct, never the other way round. The Explorer in the hub shows these links and the hierarchy as a graph.

Relationship Explorer: dependencies between risks, assets, requirements and actions.

Historical note

Up to and including the previous version, the app created four separate Jira projects — ISMSANF (requirements), ISMSAUN (audits & nonconformities), ISMSMM (measures) and ISMSRISK (assets & risks). These abbreviations live on internally as names of workflows and screens, but they are no longer project keys. Existing installations keep their previous layout; migration notes: Language, project type and required entries.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20