Running the ISMS
Workflows and statuses
Purpose
Every issue type runs through a fixed workflow β a sequence of statuses. Statuses are marked with symbols: βͺοΈ/π΅ in progress Β· π’/β done Β· π΄/π₯ critical Β· π under review. The app installs 10 workflows with 32 statuses in total. This page shows the lifecycles per issue type; the matching day-to-day procedures are on the domain pages.
Risk Scenario
π Threat analysis β π Applicable β π Risk assessment β π Risk treatment β β Accepted
First it is checked whether the scenario is applicable at all (otherwise it ends as π Not applicable). Then the current risk is assessed, treated and finally accepted. From π Under review it goes back into re-assessment β that keeps the loop alive.
Action & Corrective action
βͺοΈ Draft β βͺοΈ Ready for implementation β π΅ In implementation β π΅ In effectiveness review β π’ Implemented
Special states: π΅ In escalation (overdue), π Under review (periodic check) and π’ Not relevant / applicable.
Nonconformity (major/minor, opportunity for improvement)
βοΈ In recording β π΅ In progress β π Under review β β Resolved
If a deviation leads to a risk of its own, it moves via π₯ In risk assessment to β Risk recorded.
Audit
π Draft β βοΈ In preparation β π Under audit β π Report in progress β β Completed
The auditβs findings (major/minor nonconformities, opportunities for improvement) are connected to the audit file via the βfound inβ link (Handling audits and nonconformities).
Asset (Process, Supplier, ICT Asset, Infrastructure)
βοΈ In recording β π’ Active β π Under review β π Inactive
Additionally, π Not applicable / not relevant is available β for example for imported BSI modules that do not apply to your scope. Only active assets and information feed the inheritance logic.
Information
βοΈ In recording β π’ Active β π Under review β π Inactive
Information objects are recorded, are active in operation, are reviewed periodically and are set inactive at the end of their lifecycle. Only active information feeds the protection-need inheritance.
Requirement & Partial Requirement
βͺοΈ In planning β π΅ In progress β π’ Done
Controls that do not apply are set to π Not applicable / not relevant β this is the basis of the Statement of Applicability (SoA).
Epic (chapter container)
βͺοΈ In planning β π΅ In progress β π’ Done
Epics represent the chapters of the requirement structure and run on the simple standard workflow.
Document (document control)
π Draft β β³ In approval β β Approved β π Under review
The collector issue per controlled document mirrors the control state of the Confluence page. The document-control values are always the authoritative ones (Using document control); the issues are maintained automatically by the app.
Control Round (document control)
βͺοΈ In planning β π΅ In progress β β Completed
Special states: β Rejected (approval refused) and π Not applicable / not relevant. Control rounds are created as subtasks under the Document issue and are not edited by hand in day-to-day work.
Related pages
Documentation baseline: app version 1.1.15 Β· 2026-08-20