You can find here CISO Assistant global organization. All entities will be linked to or contained within these objects.
For Access Control purpose, CISO Assistant data is organized in a tree of folders. Starting from a root folder called Global, it divide into sub-folders called domains. The organization of the tree is not hard-coded, it is entirely determined by configuration. Any object in CISO Assistant is attached to a folder (including folders), either directly or indirectly through a parent object that is attached to a folder.
In CISO Assistant, organizational structure is managed through a hierarchical tree of Folders, Domains, and Perimeters. This design is central to the platform's Access Control and data management strategy, ensuring that information is segmented by business unit, department, or client.1
CISO Assistant data is organized in a flexible, non-hardcoded tree structure.1
Root Folder: Every instance starts with a root folder named Global.1
Tree Logic: All objects in the platform (assets, risks, audits, and even other folders) are attached to a folder either directly or through a parent object.1
Configuration: The organization of this tree is entirely determined by your specific configuration rather than being fixed by the software.1
Domains are specialized sub-folders that serve as the primary organizational unit for your work area.1
Purpose: A domain is used to delimit a specific area of work, such as an individual department within a company or a specific customer if you are a service provider.1
Scope of Permissions: Every role or permission a user has on a domain applies to all objects and actions within that domain.1
Setup: Creating a domain is typically the first action taken in CISO Assistant as it brings together all necessary objects for a specific perimeter.1
Perimeters are the fundamental context objects where active evaluations occur.12
Function: They define the boundaries for what you are evaluating, such as a specific company, subsidiary, or system environment (e.g., "Production" vs. "Corporate").23
Containment: A perimeter contains all related risk scenarios and compliance audits. By pinning assets and audits to a specific perimeter, the platform prevents "messy overlap" across different business units.12
Status Tracking: Perimeters include specific fields for internal reference and lifecycle status, such as:
Design
Development
Production
End of Life
Dropped1
Organizational structure is tied directly to the platform's Role-Based Access Control (RBAC) model.1
User Groups: These go hand-in-hand with domains. User groups associate permissions with users and define their scope by being attached to a specific domain.1
Automatic Creation: In the Community Edition, when you create a domain, user groups for that domain are automatically created for each built-in role. You simply need to assign users to the relevant groups to grant them access.1
Setting up your organizational structure correctly is the most critical first step in CISO Assistant. This hierarchy ensures that data is properly segmented, access is restricted to the right people, and your compliance reports remain clean and focused.
CISO Assistant uses a flexible, non-hardcoded tree structure. Every object—whether it is a risk, an asset, or an audit—must be attached to a folder or a parent object within this tree.1
The Root Folder: Every instance starts with a top-level folder named Global.1
Custom Folders: You can create sub-folders to organize your business units (e.g., "North America," "Europe," or "HR Department").12
A Domain is a specialized type of sub-folder that acts as the primary organizational unit. It delimits a specific area of work or a client.1
Why use them? Domains are the boundaries for Role-Based Access Control (RBAC). Permissions granted on a domain apply to every object within that domain.1
Automatic Setup: When you create a domain, the platform automatically generates user groups for each built-in role (e.g., Manager, Auditor, Contributor). You simply add users to these groups to grant them access.1
A Perimeter is a "context object" that defines the exact boundary of what you are evaluating—such as a specific company, subsidiary, or system environment.12
The "No Overlap" Rule: Any asset, audit, or risk scenario you create is pinned to a specific Perimeter. This prevents data from one department (e.g., Finance) from "bleeding" into another (e.g., R&D).2
Lifecycle Tracking: Each perimeter tracks the maturity of the system it represents:1
Design / Development: For systems not yet live.
Production: For active, live environments.
End of Life / Dropped: For decommissioning systems.
Follow this workflow to establish your first organizational branch:
Step 1: Create a Domain
Navigate to Domains in the sidebar.
Click Create New Domain.
Name it based on the business unit or client (e.g., "Corporate IT").
Assign the domain to the Global folder (or a sub-folder if you've created one).
Step 2: Create a Perimeter
Navigate to Perimeters in the sidebar.
Click Add Perimeter.
Name: Give it a specific scope name (e.g., "AWS Production Environment").
Folder/Domain: Select the Domain you created in Step 1.
Status: Set to "Production" (or the relevant lifecycle stage).
Step 3: Assign Users
Go to System > Users or User Groups.
Find the groups that were automatically created for your new Domain.
Add the relevant team members to these groups (e.g., add your DevOps lead to the "Manager" group for the "AWS Production" domain).
Object
Level
Purpose
Key Benefit
Folder
Top/Middle
General grouping and categorization.
Clean navigation.
Domain
Middle
Scoping permissions and access control.
Secure data segmentation.
Perimeter
Bottom
Defining the technical/business boundary.
Focused, isolated audits.
Once your Domain and Perimeter are established, use this checklist to populate CISO Assistant with the technical and business data required for accurate risk and compliance assessments.
1. Identify Primary Assets (PR)
Primary assets represent the core business value you are protecting. Focus on data and high-level processes.
Customer Data: PII, account information, and purchase history.1
Financial Records: Transaction logs, billing data, and audit trails.1
Intellectual Property: Source code repositories, proprietary algorithms, and trade secrets.1
Corporate Communications: Email archives and sensitive internal documents.1
2. Identify Supporting Assets (SP)
Supporting assets are the infrastructure and tools that host or process your primary assets.1
Cloud Infrastructure: AWS, Azure, or GCP environments (e.g., EC2 instances, S3 buckets).1
Databases: Production instances hosting customer or financial data.1
Web Applications: Patient portals, customer dashboards, or API gateways.1
Employee Endpoints: Corporate laptops, workstations, and mobile devices.1
3. Data Entry & Import
Choose the onboarding method that best fits your current data volume:
Manual Entry: Best for small environments. Use the Assets sidebar to add items one by one.
Data Wizard (Excel/CSV): Best for bulk onboarding. Download the asset template from the Import section and upload your inventory.2
CLI (CLICA): Best for automated workflows. Use the uv run clica.py import-assets command to sync from existing spreadsheets.2
4. Mapping & Configuration
Assign to Perimeter: Ensure every asset is linked to the correct Perimeter (e.g., "AWS Production").1
Dependency Mapping: Link Primary Assets to their Supporting Assets. For example, link "Customer Data" (PR) to your "Production Database" (SP).1
Asset Classification: Tag assets with labels (e.g., "GDPR-Relevant" or "Critical") to assist with automated risk filtering.1
5. Verification (X-Rays)
Run Integrity Scan: Navigate to the X-Rays dashboard.
Check for Orphaned Assets: Address any assets that are not linked to a risk scenario or a perimeter.1
Validate Business Value: Ensure every primary asset has a documented business value or criticality level assigned.1