Reference and glossary
Reference and glossary
Terminology English ↔ German
The app interface and all created Jira/Confluence objects are bilingual. This table pairs the English and German designations so you can map both editions of the manual and mixed-language teams.
Areas and objects
| English | Deutsch |
|---|---|
| ISMS Hub · Dashboard · Explorer (Relationship Explorer) | ISMS-Hub · Dashboard · Explorer (Beziehungs-Explorer) |
| Work areas: Asset Management, Risk Management, Measures Management, Requirements Management, Audit Management, Nonconformity Management | Arbeitsbereiche: Asset-Management, Risikomanagement, Maßnahmenmanagement, Anforderungsmanagement, Auditmanagement, Abweichungsmanagement |
| Roles & responsibilities · Document control · Automations · Notifications · Reports · Setup & Configuration | Rollen & Zuständigkeiten · Dokumentenlenkung · Automatisierungen · Benachrichtigungen · Berichte · Einrichtung & Konfiguration |
| Project “ISMS Home” (key ISMS) · Confluence space “ISMS Home” (key ISMSTK) | Projekt „ISMS Home" (Schlüssel ISMS) · Confluence-Bereich „ISMS Home" (Schlüssel ISMSTK) |
| Project roles: Bearbeiter (editor), Beobachter (observer), Administrators (not translated) | Projektrollen: Bearbeiter, Beobachter, Administrators |
| Security level “Confidential” | Sicherheitsstufe „Vertraulich" |
Issue types
| English | Deutsch |
|---|---|
| Epic · Requirement · Partial Requirement | Epic · Anforderung · Teil-Anforderung |
| Audit · Major Nonconformity · Minor Nonconformity · Opportunity for Improvement | Audit · Hauptabweichung · Nebenabweichung · Verbesserungspotenzial |
| Action · Corrective action | Maßnahme · Korrekturmaßnahme |
| Risk Scenario · Information · Process · Supplier · ICT Asset · Infrastructure | Risiko-Szenario · Information · Prozess · Lieferant · IKT-Asset · Infrastruktur |
| Document · Control Round | Dokument · Lenkungsrunde |
Link types
| English | Deutsch |
|---|---|
| Mitigation: mitigates / is mitigated by | Mitigation: mitigiert / wird mitigiert von |
| Endangerment: endangers / is endangered by | Gefährdung: gefährdet / wird gefährdet von |
| Processing: processes / is processed by | Verarbeitung: verarbeitet / wird verarbeitet von |
| Audit finding: found in / has finding | Auditfeststellung: festgestellt in / hat Feststellung |
Key fields
| English | Deutsch | Values |
|---|---|---|
| 🔒 confidentiality · 🔗 Integrity · 🕒 Availability · 🛡️ Protection need | 🔒 Vertraulichkeit · 🔗 Integrität · 🕒 Verfügbarkeit · 🛡️ Schutzbedarf | 1 - normal · 2 - high/hoch · 3 - very high/sehr hoch |
| 🎲 Current/Target Likelihood | 🎲 IST-/SOLL-Eintrittswahrscheinlichkeit | 🟢 1 - rare/selten · 🟡 2 - medium/mittel · 🟠 3 - frequent/häufig · 🔴 4 - very frequent/sehr häufig |
| 💥 Current/Target Impact | 💥 IST-/SOLL-Schadenshöhe | 🟢 1 - negligible/vernachlässigbar · 🟡 2 - limited/begrenzt · 🟠 3 - significant/beträchtlich · 🔴 4 - critical/existenzbedrohend |
| 🚦 Current/Target Risk Category | 🚦 IST-/SOLL-Risikokategorie | 🟢 1 - low/gering · 🟡 2 - medium/mittel · 🟠 3 - high/hoch · 🔴 4 - very high/sehr hoch |
| ↘️ Risk treatment | ↘️ Risikobehandlung | Avoidance/Vermeidung · Reduction/Reduktion · Transfer · Acceptance/Akzeptanz |
| 🆔 Personal data | 🆔 personenbezogene Daten | 0 – No personal data · 1 – Personal data · 2 – Special personal data |
| 👤 Accountable · 👤 Consulted · 👤 Informed | (identical) | People (RACI) |
| 🔄 Review interval · 📅 Reviewed on · 📅 Next Review · 🔄 Review status | 🔄 Überprüfungsintervall · 📅 überprüft am · 📅 nächste Überprüfung · 🔄 Überprüfungsstatus | Interval: 30/60/90/180/360/720/1080 days · Status: 🟢 Up to date/Aktuell · 🟡 Due/Fällig · 🔴 Overdue/Überfällig |
| Completion | % Erfüllungsgrad | 0 % … 100 % in 20 % steps |
| 📄 Reason for applicability | 📄 Begründung der Anwendbarkeit | regulatory/contractual requirement, best practice, exclusion (2 variants) |
| 📊 Requirement level | 📊 Anforderungsstufe | 1 - Basic · 2 - Standard · 3 - High requirement |
| 🔒 ISO 27001 Standard chapter · 🔐 ISO 27001 Appendix A | 🔒 ISO 27001 Normkapitel · 🔐 ISO 27001 Anhang A | 23 clauses · 93 controls A5–A8 |
| 🎯 CIA Triad · 🎯 InfoSec objectives · 🌱 Origin | 🎯 Schutzziele · 🎯 InfoSec-Ziele · 🌱 Ursprung | — |
| 📅 Audit from/to · 👤 Lead auditor · 👤 Identified by · 📅 Identified on | 📅 Audit von/bis · 👤 leitender Auditor · 👤 festgestellt von · 📅 festgestellt am | — |
| 📅 Effectiveness review · 👤 Effectiveness reviewed by · 📊 Result of the effectiveness review · 📑 Evidence · 🚦 Risk status | 📅 Wirksamkeitsprüfung am · 👤 Wirksamkeitsprüfung durch · 📊 Ergebnis der Wirksamkeitsprüfung · 📑 Nachweise · 🚦 Risikostatus | Result: 🟢 effective · 🟡 partially effective · 🔴 not effective · Risk status: 🟢 On track · ⚠️ At risk · 🚨 Critical risk |
| ⚠️ Threat | ⚠️ Gefährdung | 47 BSI elementary threats (G 0.1 … G 0.47) |
| 💾 RPO · ⏳ RTO (each 30 min / 4 h / 1 d / 1 w) | 💾 RPO · ⏳ RTO | 🟢 1 - normal · 🟡 2 - high · 🔴 3 - very high |
Glossary
| Term | Meaning |
|---|---|
| Requirement / control | A security requirement from a standard, law, contract or custom framework; the basis of the SoA. |
| Domain | One of the four subject areas: assets & risks, requirements, measures, audits & nonconformities — all inside the “ISMS Home” project. |
| Content pack | Optional starting content: Demo, ISO 27001, BSI modules, GDPR. |
| Control round | One approval or confirmation round of document control, bound to exactly one page version. |
| Maximum principle | The protection need is the highest of confidentiality, integrity and availability. |
| Module | Installable unit of the app: ISMS project, Confluence space, content packs. |
| RACI | Responsible (assignee), Accountable, Consulted, Informed — roles on an issue driving notifications and confidentiality. |
| Review cycle | Periodic review driven by the review interval, “Reviewed on”, “Next Review” and the review-status traffic light. |
| Role register | The six organisation-wide ISMS roles in the hub (top management, CISO, ISMS team, DPO, internal audit, continuity/BCM) with deputies. |
| SoA | Statement of Applicability — the list of all Annex A controls with applicability, justification and implementation state. |
| Smart link | Live embedding of a Jira filter as a table on a Confluence page. |
| Effectiveness review | Check after implementing a measure whether it achieves its goal — with date, reviewer and result. |
FAQ
- Can I change the language later? Yes — the switch renames, but does not add missing pages (Switching the app language).
- Can I change the project type later? No — the Jira (Business) / JSM choice is made once (Language, project type and required entries).
- What happens on uninstall? The ISMS project incl. all issues and the entire app-owned Jira configuration are removed — cannot be undone (Ongoing configuration and maintenance).
- When does a measure count as complete? Only with a documented effectiveness review (Implementing and reviewing measures).
- Does my data leave the Atlassian Cloud? No — the app runs entirely inside your Atlassian Cloud, including the ISMS Agent.
Page index
- Start here
- Initial setup
- Running the ISMS
- Administration and maintenance
- Troubleshooting and support
- Reference and glossary
Documentation baseline
| Item | Value |
|---|---|
| App | ISMS with Jira & Confluence, version 1.1.15 (package.json) |
| Evidence baseline | Commit 701416edfd431a2dd66953e3822423dc5d7da455, branch main, 2026-08-20 |
| Manual created | 2026-08-25 |
| Change record | 2026-08-25 — first edition, verified against source code, UI texts and configuration of the baseline. |
Documentation baseline: app version 1.1.15 · 2026-08-20