Start Here - ISMS Quick Start
First-time setup
1. Confirm settings
Check your 5 x 5 risk bands, residual-risk review threshold, and control/evidence/document reminder windows.
2. Load your controlled documents
Add approved policies, procedures, standards, forms and records. Keep owner, version, approval and review dates current.
3. Build Controls & SoA
Create control records from material you are licensed to use. Record applicability, justification, implementation status, ownership, evidence and review dates.
Day-to-day workflow
| When you need to... | Use | What to keep current |
|---|---|---|
| Record and assess an information-security risk | Risks | Owner, 1-5 inherent assessment, treatment decision, linked controls, residual assessment, status and target date. |
| Track an action that reduces a risk | Risk Treatments | Related risk, action, owner, target date, status and completion date. |
| Store proof that a control/process is operating | Evidence | Description, owner, dates, linked controls/risks and attachments. |
| Plan or record assurance activity | Audits | Scope, lead auditor, dates, status, controls covered and conclusion. |
| Record an issue from an audit | Findings | Source audit, severity, description, root cause, owner, due date and status. |
| Track remediation and verify effectiveness | Corrective Actions | Related finding, remediation, owner, due date, completion and effectiveness review. |
Routine governance
Weekly / operational review
Use the Management Dashboard attention queue to deal with overdue treatments, reviews, expiring evidence and corrective actions.
Before an audit or management review
Run the Data Quality Check, then review the Risk Report, SoA Report and Management Review Pack.
Administration
Configure XWiki reader/editor/administrator groups before wider rollout. Keep PostgreSQL and XWiki backups scheduled and retain an off-server copy.