Start Here - ISMS Quick Start

Last modified by Lee Pedley on 2026/09/21 21:59

Start here
For ISMS records, use the Add New... button inside each register. The XWiki Create button in the top-right creates general wiki pages and is not the normal route for structured ISMS records.

First-time setup

1. Confirm settings

Check your 5 x 5 risk bands, residual-risk review threshold, and control/evidence/document reminder windows.

Open Settings

2. Load your controlled documents

Add approved policies, procedures, standards, forms and records. Keep owner, version, approval and review dates current.

Open Controlled Documents

3. Build Controls & SoA

Create control records from material you are licensed to use. Record applicability, justification, implementation status, ownership, evidence and review dates.

Open Controls & SoA

Day-to-day workflow

When you need to...UseWhat to keep current
Record and assess an information-security riskRisksOwner, 1-5 inherent assessment, treatment decision, linked controls, residual assessment, status and target date.
Track an action that reduces a riskRisk TreatmentsRelated risk, action, owner, target date, status and completion date.
Store proof that a control/process is operatingEvidenceDescription, owner, dates, linked controls/risks and attachments.
Plan or record assurance activityAuditsScope, lead auditor, dates, status, controls covered and conclusion.
Record an issue from an auditFindingsSource audit, severity, description, root cause, owner, due date and status.
Track remediation and verify effectivenessCorrective ActionsRelated finding, remediation, owner, due date, completion and effectiveness review.

Routine governance

Weekly / operational review

Use the Management Dashboard attention queue to deal with overdue treatments, reviews, expiring evidence and corrective actions.

Before an audit or management review

Run the Data Quality Check, then review the Risk Report, SoA Report and Management Review Pack.

Administration

Configure XWiki reader/editor/administrator groups before wider rollout. Keep PostgreSQL and XWiki backups scheduled and retain an off-server copy.

This workspace supports your ISMS process and evidence. It does not by itself establish ISO/IEC 27001 conformity or certification, and it intentionally does not reproduce licensed ISO control wording.