Running the ISMS

Running the ISMS

This chapter describes the recurring work in the ISMS — per domain, with ownership, trigger, cadence and result. The foundation is the hub’s six work areas with 21 pre-filtered lists in total; every group has a Needs attention view for what requires action.

Pages in this chapter

Recurring tasks at a glance

TaskWho (typically)Trigger / cadenceWhere
Record and assess new assets, information and risksISMS team, asset ownerson change; review per intervalManaging assets and risks
Classify requirements and maintain fulfilment (SoA)CISO, control ownersongoing; review interval per requirementMaintaining requirements and the SoA
Implement measures, review effectivenessassignees, accountabledue date; daily monitoringImplementing and reviewing measures
Run audits, resolve nonconformitiesinternal audit, CISOaudit programme; 30/14-day deadlinesHandling audits and nonconformities
Approve documents and collect read confirmationspage owners, all employeesper document version; daily remindersUsing document control
Generate reports for management and auditsJira administrators, CISObefore reviews/audits; as neededGenerating reports
Ask the ISMS questions, draft documentseveryone (with Rovo)as neededUsing the ISMS Agent (Rovo)

The daily entry point

The fastest overview is the Dashboard (The ISMS Hub at a glance): the Action center tile collects overdue measures, overdue requirement reviews, unassessed risks, pending document approvals, failed automations and due vendor reviews; My work shows your open items and links into document control. The Review cycle traffic light shows overdue, due-within-30-days and on-track reviews.

“ISMS team” dashboard: tiles per work area, Statement of Applicability, current/target risk matrix and “Action center”.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20