Running the ISMS

Implementing and reviewing measures

Purpose

Central control of all measures — whether they come from risks, requirements or audit deviations. Measures are planned, implemented and afterwards reviewed for effectiveness. Where you work in the hub: the Measures Management work area.

Who does this

The assignee (Responsible) implements; 👤 Accountable carries overall responsibility; the review is done by the person named in 👤 Effectiveness reviewed by.

Creating an action

  1. + New ISMS item → type Action (or Corrective action as the response to a deviation).
  2. Describe in the Summary and description what is to be implemented and how success can be recognised.
  3. Set Start date and Due date, assign the action and maintain 👤 Accountable.
  4. If the action stems from a risk: link it via mitigates to the risk scenario. If it stems from a deviation: link it to the nonconformity (Handling audits and nonconformities).
Measures Management: actions and corrective actions through to the effectiveness review, here the “Open” tab with status, completion and origin.

Implementing and reviewing

  1. Move the action through the workflow: ⚪️ Draft → ⚪️ Ready for implementation → 🔵 In implementation → 🔵 In effectiveness review → 🟢 Implemented.
  2. During the effectiveness review: fill in 📅 Effectiveness review (date), 👤 Effectiveness reviewed by and the result in 📊 Result of the effectiveness review; evidence belongs in 📑 Evidence.
  3. Only with a documented effectiveness review does the measure count as truly complete — a plain status change is not enough.

What happens automatically

  • Overdue Monitoring with Escalation (daily): notifies assignee and accountable about overdue measures — 1/3/7/30 days after the due date, then monthly.
  • Reminder for Effectiveness Review (daily): comments on measures in 🔵 In effectiveness review whose review date is more than 10 days past without a result.
  • Status Sync From Measure (event-based): once the action reaches 🟢 Implemented, linked nonconformities and the risk scenarios connected via mitigates automatically move to 🔄 Under review.
  • If 📊 Result of the effectiveness review is set to 🔴 not effective, the field alert warns Responsible and Accountable (Setting up notifications (RACI)).
  • With a 🔄 Review interval set, the review traffic light (🟢/🟡/🔴) and its configurable escalation stages apply (Running the ISMS).

Verify

  • Overdue measures appear under Needs attention and in the dashboard’s Action center; the special status 🔵 In escalation marks endangered measures.
  • The status of measures from risk management appears in the Risk Report (Generating reports).

Troubleshooting

  • No reminder received: daily helpers only run at the next cycle; start them manually in Automations for an immediate result. Also check the notifications master switch.
  • A linked nonconformity does not move: the status synchronisation can also be started manually (Status Synchronization: Measure ↔ Nonconformity, Managing automations).

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20