Running the ISMS
Implementing and reviewing measures
Purpose
Central control of all measures — whether they come from risks, requirements or audit deviations. Measures are planned, implemented and afterwards reviewed for effectiveness. Where you work in the hub: the Measures Management work area.
Who does this
The assignee (Responsible) implements; 👤 Accountable carries overall responsibility; the review is done by the person named in 👤 Effectiveness reviewed by.
Creating an action
- + New ISMS item → type Action (or Corrective action as the response to a deviation).
- Describe in the Summary and description what is to be implemented and how success can be recognised.
- Set Start date and Due date, assign the action and maintain 👤 Accountable.
- If the action stems from a risk: link it via mitigates to the risk scenario. If it stems from a deviation: link it to the nonconformity (Handling audits and nonconformities).
Implementing and reviewing
- Move the action through the workflow: ⚪️ Draft → ⚪️ Ready for implementation → 🔵 In implementation → 🔵 In effectiveness review → 🟢 Implemented.
- During the effectiveness review: fill in 📅 Effectiveness review (date), 👤 Effectiveness reviewed by and the result in 📊 Result of the effectiveness review; evidence belongs in 📑 Evidence.
- Only with a documented effectiveness review does the measure count as truly complete — a plain status change is not enough.
What happens automatically
- Overdue Monitoring with Escalation (daily): notifies assignee and accountable about overdue measures — 1/3/7/30 days after the due date, then monthly.
- Reminder for Effectiveness Review (daily): comments on measures in 🔵 In effectiveness review whose review date is more than 10 days past without a result.
- Status Sync From Measure (event-based): once the action reaches 🟢 Implemented, linked nonconformities and the risk scenarios connected via mitigates automatically move to 🔄 Under review.
- If 📊 Result of the effectiveness review is set to 🔴 not effective, the field alert warns Responsible and Accountable (Setting up notifications (RACI)).
- With a 🔄 Review interval set, the review traffic light (🟢/🟡/🔴) and its configurable escalation stages apply (Running the ISMS).
Verify
- Overdue measures appear under Needs attention and in the dashboard’s Action center; the special status 🔵 In escalation marks endangered measures.
- The status of measures from risk management appears in the Risk Report (Generating reports).
Troubleshooting
- No reminder received: daily helpers only run at the next cycle; start them manually in Automations for an immediate result. Also check the notifications master switch.
- A linked nonconformity does not move: the status synchronisation can also be started manually (Status Synchronization: Measure ↔ Nonconformity, Managing automations).
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20