Running the ISMS

Workflows and statuses

Purpose

Every issue type runs through a fixed workflow β€” a sequence of statuses. Statuses are marked with symbols: βšͺ️/πŸ”΅ in progress Β· 🟒/βœ… done Β· πŸ”΄/πŸ”₯ critical Β· πŸ”„ under review. The app installs 10 workflows with 32 statuses in total. This page shows the lifecycles per issue type; the matching day-to-day procedures are on the domain pages.

Risk Scenario

πŸ” Threat analysis β†’ πŸ‘ Applicable β†’ πŸ“Š Risk assessment β†’ πŸ“„ Risk treatment β†’ βœ… Accepted

First it is checked whether the scenario is applicable at all (otherwise it ends as πŸ‘Ž Not applicable). Then the current risk is assessed, treated and finally accepted. From πŸ”„ Under review it goes back into re-assessment β€” that keeps the loop alive.

Action & Corrective action

βšͺ️ Draft β†’ βšͺ️ Ready for implementation β†’ πŸ”΅ In implementation β†’ πŸ”΅ In effectiveness review β†’ 🟒 Implemented

Special states: πŸ”΅ In escalation (overdue), πŸ”„ Under review (periodic check) and 🟒 Not relevant / applicable.

Nonconformity (major/minor, opportunity for improvement)

✏️ In recording β†’ πŸ”΅ In progress β†’ πŸ”„ Under review β†’ βœ… Resolved

If a deviation leads to a risk of its own, it moves via πŸ”₯ In risk assessment to ❌ Risk recorded.

Audit

πŸ“ Draft β†’ ✏️ In preparation β†’ πŸ” Under audit β†’ πŸ“„ Report in progress β†’ βœ… Completed

The audit’s findings (major/minor nonconformities, opportunities for improvement) are connected to the audit file via the β€œfound in” link (Handling audits and nonconformities).

Asset (Process, Supplier, ICT Asset, Infrastructure)

✏️ In recording β†’ 🟒 Active β†’ πŸ”„ Under review β†’ πŸ”˜ Inactive

Additionally, πŸ”˜ Not applicable / not relevant is available β€” for example for imported BSI modules that do not apply to your scope. Only active assets and information feed the inheritance logic.

Information

✏️ In recording β†’ 🟒 Active β†’ πŸ”„ Under review β†’ πŸ”˜ Inactive

Information objects are recorded, are active in operation, are reviewed periodically and are set inactive at the end of their lifecycle. Only active information feeds the protection-need inheritance.

Requirement & Partial Requirement

βšͺ️ In planning β†’ πŸ”΅ In progress β†’ 🟒 Done

Controls that do not apply are set to πŸ”˜ Not applicable / not relevant β€” this is the basis of the Statement of Applicability (SoA).

Epic (chapter container)

βšͺ️ In planning β†’ πŸ”΅ In progress β†’ 🟒 Done

Epics represent the chapters of the requirement structure and run on the simple standard workflow.

Document (document control)

πŸ“ Draft β†’ ⏳ In approval β†’ βœ… Approved β†’ πŸ”„ Under review

The collector issue per controlled document mirrors the control state of the Confluence page. The document-control values are always the authoritative ones (Using document control); the issues are maintained automatically by the app.

Control Round (document control)

βšͺ️ In planning β†’ πŸ”΅ In progress β†’ βœ… Completed

Special states: β›” Rejected (approval refused) and πŸ”˜ Not applicable / not relevant. Control rounds are created as subtasks under the Document issue and are not edited by hand in day-to-day work.

Documentation baseline: app version 1.1.15 Β· 2026-08-20