intuitem/ciso-assistant-community

CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting. It supports 200+ global...

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 53 minutes ago
Added to GitGenius on September 15th, 2026
Created on September 20th, 2023
Open Issues & Pull Requests: 111 (+0)
GitHub issues: Enabled
Number of forks: 837
Total Stargazers: 4,433 (+0)
Total Subscribers: 43 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 24.7 hours
Mean response time: 31.7 days
90th percentile: 80.9 days
Tracked items: 602

Most active contributors

Sign in to see contributor activity.

How this project is maintained

About 17% of issues opened in the past year have never received a reply. 91% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Work labelled "deployment" is answered fastest, typically in about 6 hours, while "enhancement" waits about 11 days. 49% of tracked open issues have had no activity in three months. 84% of issues opened in the past year have been closed, leaving a working backlog.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 77
New in 7 days: 9
Closed in 7 days: 4
Avg open age: 216 days
Stale 30+ days: 60
Stale 90+ days: 46

Recent activity

Opened in 7 days: 8
Closed in 7 days: 3
Comments in 7 days: 10
Events in 7 days: 25

Top labels

  • question (198)
  • enhancement (63)
  • bug (58)
  • new feature (39)
  • Framework (22)
  • deployment (14)
  • ui (11)
  • High Value (7)

Detailed Description

CISO Assistant is a governance, risk, and compliance platform that consolidates risk management, application security, compliance auditing, third-party risk management, business impact analysis, privacy, and reporting into a single system.

The platform addresses the fragmentation of GRC tooling by providing a unified interface for managing security and compliance across multiple frameworks and standards. It works by maintaining a library of over two hundred global frameworks with built-in control mappings that automatically align organizational controls to relevant standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2, CIS, PCI DSS, NIS2, DORA, GDPR, HIPAA, and CMMC. This approach eliminates manual mapping work and reduces the overhead of demonstrating compliance to multiple regulatory bodies simultaneously.

Organizations managing compliance across multiple jurisdictions or standards should evaluate this tool if they currently operate separate systems for risk assessment, audit tracking, and compliance reporting. It suits enterprises and mid-market organizations that need to demonstrate adherence to multiple frameworks without maintaining disconnected spreadsheets and databases. The platform's support for quantification and LLM integration suggests it can assist with risk scoring and automated evidence collection, though the README does not compare these capabilities to competing GRC solutions.

The project maintains active development with regular updates to its framework library and feature set. The codebase is written in Python and the team actively incorporates new compliance standards and regulatory requirements into the platform. Development activity shows ongoing refinement of the core GRC functionality alongside expansion of supported frameworks and audit capabilities.