Running the ISMS
Generating reports
Purpose
In the Reports area you generate three reports as Confluence pages at the click of a button. Each report is a snapshot: it captures the state of the day it was generated and does not change afterwards — exactly what an audit needs.
Who can do this
Everyone can view the area; generating reports is for Jira administrators only (“Only Jira administrators can generate reports.”). In addition, the ISMS project and the Confluence space must be installed — otherwise the button is disabled and the card explains what is missing.
The three reports
| Report | What for | What it contains | Filed in Confluence |
|---|---|---|---|
| Risk Report | Regular briefing for management; evidence of risk assessment and treatment | Distribution of risks by category incl. change since the last report, risk matrix (current and target), top risks with affected assets, treatments incl. a list of all risk acceptances, status of measures from risk management, weekly trend, data quality | 📊 Risk Reports |
| Management Review | Preparation and evidence of the management review per ISO 27001 clause 9.3 | Meeting template with the measurable items pre-filled (actions from the previous review, nonconformities, audit results, risk situation …); non-measurable items as placeholders; at the end a decision table, overall assessment and approval line | 📄 - Management Reviews |
| Statement of Applicability (SoA) | Mandatory document per ISO 27001 6.1.3 d) | All 93 Annex A controls: applicable?, justification, implementation state, owners, related issues. Controls without an issue appear as open; excluded controls without a justification are flagged in red | 📄 - Statement of Applicability (SoA) ISO 27001 Annex A |
Steps
- Open Reports in the sidebar.
- Click Generate report on the report you want. While running, the card shows “Generating…” with the phases Preparing → Collecting data → Writing page. Leave the window open until the progress has finished.
- Use Open page to jump straight to the generated Confluence page.
Expected result
The success line reports “✓ Page created” or “Page updated”; the card shows the timestamp under Last generated. The page title carries the date, e.g. 2026-08-25 Risk Report.
Tip for the management review
Generate the Risk Report first, then the Management Review — the review then links automatically to the current risk report. The review period starts automatically at the previous review (the first time: the last twelve months).
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20