About this project
CISO Assistant is an open-source Governance, Risk and Compliance (GRC) platform aimed at cybersecurity teams. It positions itself as a central hub that links compliance, controls, risks and remediation work instead of duplicating data across separate tools.
Core ideas described in the README:
- Decoupling compliance from security controls, so the same control implementation can be reused across frameworks and scopes.
- Multi-paradigm design intended to fit different methodologies and organizational backgrounds.
- API-first architecture supporting both the web UI and external automation.
- An open library format for defining custom frameworks, threat catalogs, reference controls and risk matrices.
Feature areas listed include compliance and audit campaigns, automatic control mapping and a mapping explorer, custom frameworks, policy and evidence management; risk assessment and registers, EBIOS RM, threat modeling, business impact analysis, cyber risk quantification and vulnerability management; third-party risk management, contracts and a DORA register of information; action plans, findings, tasks, Kanban boards, periodic checks, incidents and validation workflows; dashboards, reports and custom metrics; collaboration features such as assignments, requests, comments and universal search; automation via REST API, CLI, import wizard, Kafka, webhooks, MCP and Jira/ServiceNow integrations; and access controls including RBAC, SSO via SAML or OIDC, MFA, SCIM and audit logging.
The project states it includes more than 200 frameworks, with examples such as ISO 27001, NIST CSF, NIS2, SOC 2, PCI DSS, CMMC, GDPR, HIPAA, DORA, CIS Controls and CIS Benchmarks, plus many national and sector-specific standards. Some frameworks marked with an asterisk require manually obtaining an Excel sheet due to licensing.
Deployment: the quickest self-hosted path uses Docker and Docker Compose scripts for Linux/macOS and Windows, with prebuilt images or a build variant for specific architectures. Kubernetes (Helm) deployment is also mentioned. A cloud free trial is offered. The README warns against using the main branch directly in production and recommends tags or prebuilt images.
Customization: libraries can be loaded directly from Excel files through the Governance → Library page, or converted to YAML with provided Python tools. A mapping preparation tool helps build mappings between two framework libraries. Development requirements include Python, Node.js, pnpm and yaml-cpp, with WSL2 recommended for Windows users.
The interface is stated to be available in more than 26 languages. The project is maintained by Intuitem and has an open Discord community.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.