Running the ISMS

Generating reports

Purpose

In the Reports area you generate three reports as Confluence pages at the click of a button. Each report is a snapshot: it captures the state of the day it was generated and does not change afterwards — exactly what an audit needs.

Who can do this

Everyone can view the area; generating reports is for Jira administrators only (“Only Jira administrators can generate reports.”). In addition, the ISMS project and the Confluence space must be installed — otherwise the button is disabled and the card explains what is missing.

The three reports

ReportWhat forWhat it containsFiled in Confluence
Risk ReportRegular briefing for management; evidence of risk assessment and treatmentDistribution of risks by category incl. change since the last report, risk matrix (current and target), top risks with affected assets, treatments incl. a list of all risk acceptances, status of measures from risk management, weekly trend, data quality📊 Risk Reports
Management ReviewPreparation and evidence of the management review per ISO 27001 clause 9.3Meeting template with the measurable items pre-filled (actions from the previous review, nonconformities, audit results, risk situation …); non-measurable items as placeholders; at the end a decision table, overall assessment and approval line📄 - Management Reviews
Statement of Applicability (SoA)Mandatory document per ISO 27001 6.1.3 d)All 93 Annex A controls: applicable?, justification, implementation state, owners, related issues. Controls without an issue appear as open; excluded controls without a justification are flagged in red📄 - Statement of Applicability (SoA) ISO 27001 Annex A

Steps

  1. Open Reports in the sidebar.
  2. Click Generate report on the report you want. While running, the card shows “Generating…” with the phases Preparing → Collecting data → Writing page. Leave the window open until the progress has finished.
  3. Use Open page to jump straight to the generated Confluence page.
Reports: cards “Risk Report”, “Management Review” and “Statement of Applicability (SoA)” with “Generate report”, “Last generated” and “Open page”.

Expected result

The success line reports “✓ Page created” or “Page updated”; the card shows the timestamp under Last generated. The page title carries the date, e.g. 2026-08-25 Risk Report.

Tip for the management review

Generate the Risk Report first, then the Management Review — the review then links automatically to the current risk report. The review period starts automatically at the previous review (the first time: the last twelve months).

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20