General tips
CISO Assistant is intended to be a multi-paradigm tool that suits everyone's background and approach to cyber-security programme organisation.
That said, here are some standard recommendations to get the most of it when you're just starting:
Map your organisation to the domains and perimeters (or create basic ones).
Add your users and assign them to groups (SSO and MFA are available even in the Community edition).
(recommended) Identify the assets to protect.
(recommended) Enumerate your existing capabilities and controls.
Define your baseline and focus on the basics — pick your controls and/or create new ones.
Get your actions implemented and reflect that on your audit progress.
Conduct a contextual risk assessment.
Share the insights with your organisation, review the priorities, and keep it alive.
Expand your coverage: periodic tasks, incidents, third-party risk, findings management.
Always keep focus on the actions and reflect their data on the other concepts.
Last updated
Was this helpful?