-
Notifications
You must be signed in to change notification settings - Fork 2
Specs Management Review Decision
Claude edited this page Aug 28, 2026
·
1 revision
reports.models.management_review.ManagementReviewDecision
Structured decision output required by ISO 27001:2022 clause 9.3.3, feeding the review minutes and seeding downstream action plans.
Structured capture of the decisions required by clause 9.3.3. Used to produce the "Decisions" block of the minutes and to automatically seed action plans.
| Field | Type | Constraints | Description |
|---|---|---|---|
id |
UUID | PK | |
reference |
string | auto (prefix DECS), unique |
e.g. DECS-1
|
review |
FK → ManagementReview | required, CASCADE | Originating review |
category |
enum | required |
improvement, isms_change, resource_allocation, risk_acceptance, objective_adjustment, policy_update, other
|
input_clause |
enum | optional | The 9.3.2 input the decision relates to (a–g) |
title |
string | required, max 255 | Short title |
description |
text | required | Full text of the decision |
rationale |
text | optional | Justification, contextual elements |
owner |
FK → User | required | Person responsible for implementation |
due_date |
date | required | Due date |
priority |
enum | required |
low, medium, high, critical
|
status |
enum | required |
pending, in_progress, implemented, cancelled
|
implemented_at |
date | optional | Actual implementation date |
implementation_evidence |
text | optional | Evidence (link to a document, URL) |
linked_action_plan |
FK → ComplianceActionPlan | optional, SET_NULL | Action plan generated from this decision |
linked_treatment_plan |
FK → RiskTreatmentPlan | optional, SET_NULL | Treatment plan generated |
linked_objective |
FK → Objective | optional, SET_NULL | ISMS objective created/adjusted |
linked_isms_change |
FK → IsmsChange | optional, SET_NULL | Associated ISMS change |
created_at, updated_at
|
datetime | auto |
History : HistoricalRecords.
Business rules :
- A review can only move to
closedif all of its decisions haveownerANDdue_datefilled in. - When a decision moves to
implemented, iflinked_action_planis set, its status must beCLOSEDorVALIDATED(business safeguard, non-blocking UI warning). - A "Create an action plan from this decision" action generates a pre-filled
ComplianceActionPlanand setslinked_action_plan+originating_review(cf. README.md).
Built from docs/ at v0.36.0. Edits made here are overwritten by the next release : open a pull request against the source instead.
- Administration
- Ask Cairn
- Assets and suppliers
- Compliance
- The dashboard
- Finding your way
- Getting started
- Incidents
- How records move
- Organisational context
- Reports and management review
- Risks
- Trust Center
- Architecture
- Configuration
- Contributing
- The documentation system
- Installation
- Internationalisation
- Operations
- Release process
- Security
- Testing
- Adding an assistant provider
- Adding a dashboard widget
- Adding a domain entity
- Declaring a lifecycle
- Adding an MCP tool
- Adding a REST endpoint
- Adding a report
- Interface conventions
- Dashboard widgets
- Lifecycles
- MCP tools
- MCP tool parameters : Assets
- MCP tool parameters : Compliance
- MCP tool parameters : Governance and context
- MCP tool parameters : General
- MCP tool parameters : Incidents
- MCP tool parameters : Reports and management review
- MCP tool parameters : Risks
- MCP tool parameters : System and administration
- MCP tool parameters : Trust Center
- Management commands
- Models
- Permissions
- REST endpoints
- Environment variables
- MCP server
- REST API
- Assistant module (Ask Cairn)
- Module 0: User Management and Access Control
- Module 1: Context and Organization
- Module 2: Asset Management
- Module 3: Compliance
- Module 4: Risk Management
- Module 4 bis - EBIOS Risk Manager
- Module 5 : Trust Center
- Module 6 : Security Incident Management
- Management review : ISO 27001:2022 compliance (clause 9.3)