Wiki source code of Information Security Management System
Last modified by Lee Pedley on 2026/09/21 21:18
Show last authors
| author | version | line-number | content |
|---|---|---|---|
| 1 | = Information Security Management System = | ||
| 2 | |||
| 3 | {{info}}Use the [[ISMS Management Dashboard>>ISMS.Dashboard]] for management review, overdue items and register navigation.{{/info}} | ||
| 4 | |||
| 5 | == Core registers == | ||
| 6 | |||
| 7 | * [[Controlled Documents>>Controlled Documents.WebHome]] | ||
| 8 | * [[Controls & Statement of Applicability>>Controls and SoA.WebHome]] | ||
| 9 | * [[Risks>>Risks.WebHome]] | ||
| 10 | * [[Risk Treatments>>Risk Treatments.WebHome]] | ||
| 11 | * [[Evidence>>Evidence.WebHome]] | ||
| 12 | * [[Audits>>Audits.WebHome]] | ||
| 13 | * [[Findings>>Findings.WebHome]] | ||
| 14 | * [[Corrective Actions>>Corrective Actions.WebHome]] | ||
| 15 | |||
| 16 | == Automation in this build == | ||
| 17 | |||
| 18 | * IDs for Risks, Treatments, Evidence, Audits, Findings and Corrective Actions are derived from the page name when the ID is blank. | ||
| 19 | * Risk inherent/residual scores are calculated in the edit form from the 1-5 likelihood and impact values. | ||
| 20 | * Relationship pickers are restricted to the appropriate register classes. | ||
| 21 | * Review / expiry / overdue warnings are shown on records and on the management dashboard. | ||
| 22 | |||
| 23 | {{warning}}The 30-day review window and score >=15 dashboard indicator are management defaults, not requirements of ISO/IEC 27001. Configure your ISMS criteria and licensed control content to match your organisation.{{/warning}} |