Running the ISMS
Domains and issue types
Purpose
After installation there is one Jira project, “ISMS Home” (key ISMS), and one Confluence space. All four domains live inside the same project and are distinguished by the issue type. This page explains the building blocks; the recurring workflows per domain follow on the next pages.
The 17 issue types
| Domain | Issue type | What for |
|---|---|---|
| Requirements | Epic | Container for the chapters of the requirement structure (clause / Annex A) — the only container level above the issues |
| Requirement | A security requirement or control | |
| Partial Requirement | Sub-item of a requirement (subtask) | |
| Audits & nonconformities | Audit | An audit file — findings are attached via the “found in” link |
| Major Nonconformity | Absence or complete breakdown of a required system or critical requirement | |
| Minor Nonconformity | Partial fulfilment of a requirement, a once-off failure | |
| Opportunity for Improvement | Suggestion beyond the minimum requirement (OFI) | |
| Measures | Action | A planned security measure to be implemented |
| Corrective action | Response to an identified deviation | |
| Assets & risks | Risk Scenario | An assessed risk with a current and a target value |
| Information | Information object with protection need and personal-data flag | |
| Process | Asset type: business or supporting process | |
| Supplier | Asset type: supplier / service provider | |
| ICT Asset | Asset type: hardware, software, application, platform | |
| Infrastructure | Asset type: buildings, networks, data centres, cloud environments | |
| Document control | Document | Collector issue per controlled Confluence document — carrier of the notifications (Using document control) |
| Control Round | Subtask under the Document issue — a single approval or confirmation round |
Links between the domains
Besides the Jira standard link “relates to”, the app creates four directed link types of its own:
| Link type | Reads as (outward / inward) | Typically between |
|---|---|---|
| Mitigation | “mitigates” / “is mitigated by” | Action → Risk Scenario |
| Endangerment | “endangers” / “is endangered by” | Risk Scenario → asset or information |
| Processing | “processes” / “is processed by” | Asset (e.g. process) → Information |
| Audit finding | “found in” / “has finding” | Nonconformity → Audit |
The direction is binding: “Action mitigates risk” is correct, never the other way round. The Explorer in the hub shows these links and the hierarchy as a graph.
Historical note
Up to and including the previous version, the app created four separate Jira projects — ISMSANF (requirements), ISMSAUN (audits & nonconformities), ISMSMM (measures) and ISMSRISK (assets & risks). These abbreviations live on internally as names of workflows and screens, but they are no longer project keys. Existing installations keep their previous layout; migration notes: Language, project type and required entries.
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20