CISO Assistant is an open-source GRC (Governance, Risk and Compliance) platform — a different take on cybersecurity posture management, built on a few load-bearing ideas:
Explicitly decoupling compliance from security-operations implementation.
Providing simplified tools for decision-making.
Assessing a program, product, or whole organisation against standard frameworks.
Letting you bring your own framework via a simplified DSL.
Acting as a one-stop shop for the Governance, Risk, and Compliance layers.
Introduction — design philosophy and vocabulary.
Concepts — the central objects you work with: domains, perimeters, applied controls, assets, assessments, risks.
Installation — getting CISO Assistant running.
— recorded demos and walkthroughs.
— subscription tiers and what's included.
— feature-by-feature comparison.
Configuration — organisation setup, IAM, SSO, and customisation.
Features — a catalogue of shipped capabilities.
Guides — task-oriented walkthroughs, both onboarding and ongoing operations.
AI and Integrations — the REST API, the MCP server, and third-party integrations.
Contributing — how to extend CISO Assistant and improve this documentation.
— partner programme for integrators and resellers.