Running the ISMS
Maintaining requirements and the SoA
Purpose
Management of all security requirements and controls (e.g. ISO 27001 Annex A, BSI, GDPR, custom frameworks) including the Statement of Applicability (SoA). Where you work in the hub: the Requirements Management work area.
Who does this
The CISO and control owners (project role Bearbeiter). Importing catalogs is for Jira administrators only.
Layout
- The Structure tab shows the requirements as a tree: framework → chapter (Epic) → requirement → partial requirement.
- The list tabs show the pre-filtered views, including Needs attention (e.g. due requirement reviews).
- Already imported catalogs are listed at the bottom under Imported catalogs; new ones come via Import catalogs (Content packs: Demo, ISO 27001, BSI, GDPR).
Classifying requirements (the basis of the SoA)
- Open the requirement (from a list or search) and check ownership (👤 Accountable) and standard references (🔒 ISO 27001 Standard chapter, 🔐 ISO 27001 Appendix A).
- Decide applicability:
— Applicable controls run through the workflow ⚪️ In planning → 🔵 In progress → 🟢 Done while you maintain the completion level.
— Non-applicable controls are set to 🔘 Not applicable / not relevant with the justification recorded in the field 📄 Reason for applicability.
Maintaining fulfilment and evidence
- Document evidence in the 📑 Evidence field — the ISMS Agent finds requirements without evidence or with stale evidence (Using the ISMS Agent (Rovo)).
- Set a 🔄 Review interval so the review cycle calls the requirement up regularly.
- The manual helper Inherit Security Goals aggregates CIA and InfoSec objectives from linked requirements (de-duplicated); Store Previous Fulfillment keeps the previous value from the changelog (Managing automations).
Expected result
The dashboard’s Statement of Applicability ring shows the classification state. At the click of a button, the Statement of Applicability (SoA) is generated as a Confluence report covering all 93 Annex A controls (Generating reports).
What happens next
- When a requirement reaches 🟢 Done, the enabled RACI rule notifies the parties involved.
- Gaps become measures (Implementing and reviewing measures) or risks (Managing assets and risks).
Troubleshooting
- A control shows as “open” in the SoA report: controls without an assigned issue deliberately appear as open — that is how you spot your gaps.
- Custom frameworks: via Import custom controls (CSV) in Setup, administrators create e.g. TISAX controls as requirement issues (Ongoing configuration and maintenance).
Related pages
Screenshots from the development environment with sample data.
Documentation baseline: app version 1.1.15 · 2026-08-20