ciso-assistant-community  by intuitem

GRC tool for cybersecurity management, risk, and compliance

Created 2 years ago
3,183 stars

Top 15.1% on SourcePulse

GitHubView on GitHub
Project Summary

CISO Assistant is a comprehensive Governance, Risk, and Compliance (GRC) platform designed for cybersecurity and IT professionals. It aims to simplify GRC practices by providing a centralized hub for managing risks, application security, compliance, and privacy, supporting over 90 global frameworks with automated mapping.

How It Works

The platform's core innovation is its "decoupling" concept, separating compliance requirements from cybersecurity controls. This allows for reusability of assessments across different scopes or frameworks, enabling users to evaluate a single scope against multiple standards simultaneously. This approach reduces redundant work and allows teams to focus on remediation rather than repetitive reporting and consistency checks.

Quick Start & Requirements

  • Cloud Trial: Available at intuitem.com.
  • Local Installation: Requires Docker and Docker Compose. Clone the repository and run ./docker-compose.sh.
  • Prerequisites: Docker (>= 27.0), Docker Compose. For Windows, WSL is required.
  • Production: DJANGO_DEBUG=False is recommended.
  • Documentation: https://intuitem.gitbook.io/ciso-assistant/

Highlighted Details

  • Supports over 90 GRC frameworks (e.g., NIST CSF, ISO 27001, SOC2, GDPR, PCI DSS, NIS2, CMMC).
  • API-first design for UI interaction and external automation.
  • Customizable frameworks via a simple syntax and tooling.
  • Built-in risk assessment and remediation tracking workflows.

Maintenance & Community

  • Developed and maintained by Intuitem.
  • Active Discord community for interaction and support.
  • Roadmap available.

Licensing & Compatibility

  • Community Edition: AGPL v3.
  • Commercial Editions (Pro/Enterprise): Custom intuitem Commercial Software License.
  • Files outside the "enterprise" directory are AGPL v3; files within "enterprise" are under the commercial license. AGPL v3 may have implications for closed-source linking.

Limitations & Caveats

  • The main branch is for development and may contain breaking changes; stable versions should be used via tags or prebuilt images.
  • Safari may not work correctly with the local development setup due to HTTPS requirements for secure cookies.
  • Frameworks marked with * require manual retrieval of the latest Excel sheets due to licensing restrictions.
Health Check
Last Commit

14 hours ago

Responsiveness

1 day

Pull Requests (30d)
143
Issues (30d)
25
Star History
86 stars in the last 30 days

Explore Similar Projects

Starred by Dan Guido Dan Guido(Cofounder of Trail of Bits), Chip Huyen Chip Huyen(Author of "AI Engineering", "Designing Machine Learning Systems"), and
1 more.

cai by aliasrobotics

3.6%
4k
Cybersecurity AI (CAI) is an open framework for building AI-driven cybersecurity tools
Created 5 months ago
Updated 1 day ago
Feedback? Help us improve.