This guide provides an end-to-end operational manual for CISO Assistant, synthesized from the platform's core architecture and documentation. It focuses on the "how-to" for daily users, bypassing deep technical setup.
The platform is organized into five primary domains in the sidebar. The "Golden Rule" of CISO Assistant is Decoupling: you define assets, risks, and controls once, and the engine maps them across various frameworks automatically.1
Domain
Primary Purpose
Perimeters
Define organizational boundaries (e.g., "Production," "Corporate").1
Assets
Inventory everything owned or operated, including dependency mapping.1
Frameworks
Access over 150+ pre-built standards (ISO 27001, NIST CSF, etc.).12
Audits
Active gap analyses and compliance assessment execution.1
Risk Assessments
Model threat scenarios and calculate financial or operational impact.1
To begin using CISO Assistant effectively, follow this structural workflow:
Perimeters prevent "messy overlap" between business units.
Action: Create a Perimeter for each evaluate scope (e.g., Subsidiary A, Department B).1
Grouping: Use Folders to organize these perimeters into a clear hierarchy.3
Cataloging: Add software, data sets, and physical hardware.1
Dependency Mapping: Link a business service (e.g., Patient Portal) to its underlying infrastructure (e.g., AWS). If a component fails, the system visualizes the high-level business impact.1
CISO Assistant enables "Continuous Compliance" rather than one-off spreadsheet exercises.
Select Framework: Choose from the library of 150+ templates or upload a custom Excel-based framework.12
Launch Campaign: Start an audit against a specific Perimeter.1
Cross-Mapping: The engine automatically applies controls used in other audits (e.g., an ISO 27001 access control will map to SOC 2).1
Managers can delegate audit tasks to specific team members:
Draft: Set up the requirements and assign actors.3
In Progress: Respondents are notified via email to begin work.3
Review: Once submitted, reviewers can Close the task or Request Changes with specific feedback.3
The platform shifts risk from subjective "Red/Yellow/Green" charts to actionable data.1
Qualitative (Matrix): Use standard 3x3, 4x4, or 5x5 matrices for quick assessments.3
Quantitative (CRQ): Attach financial loss or recovery metrics to threat scenarios to see actual residual risk after controls are applied.1
Threat Catalog: Leverage the built-in library (e.g., ICT-001 Ransomware, ICT-002 Phishing) to model scenarios quickly.3
This is the "master list" of your active security measures.
Continuous Lifecycle: Instead of static "Yes/No" answers, assign owners and set recurring review schedules (e.g., every 90 days).1
Evidence Collection: System owners upload text, links, or files directly into the control. These update in real-time across every audit using that control.1
The X-rays feature automatically scans your assessments for inconsistencies.2
Errors: Critical issues (e.g., a risk scenario with no assets linked).2
Warnings: Important items (e.g., an assessment with no assigned author).2
Info: General status updates (e.g., "Assessment still in progress").2