How to Start with Brainframe
π How to Start with Brainframe
"Build your GRC program once β as a connected web of assets, risks, controls and requirements β and let audits, reports and the Statement of Applicability generate themselves."
This guide takes you from an empty workspace to a fully connected GRC environment. It is written for GRC professionals, so it focuses on how Brainframe models your world and the fastest path to value β not on explaining GRC fundamentals you already know.
π§ The One Concept That Makes Everything Click
Brainframe is built on a single idea:
Everything is a document, documents live in a familiar folder tree, and documents link to each other bi-directionally.
Internalise this and the whole platform becomes intuitive:
- π Everything is a document β assets, risks, policies, procedures, suppliers, KPIs, meeting notes, audit reports. They all share the same features (properties, versioning, approvals, reminders, tasks). See a document view.
- π Links are bi-directional β link a risk to an asset once and it appears on both. Update the source and it updates everywhere. There is no "copy" β only one source of truth.
- β»οΈ Reuse over duplication β one control document can mitigate many risks and satisfy requirements across ISO 27001, GDPR, NIS2 and DORA simultaneously. You build it once.
π The connected web you build in Phase 1 is your audit evidence in Phase 2. Nothing is ever done twice.
πΊ How Brainframe maps to your GRC vocabulary
You already think in terms of⦠| In Brainframe it is a⦠| Lives under⦠|
|---|---|---|
Asset inventory / CMDB | Primary & supporting asset documents | |
Risk register | Risk documents on a matrix + inventory | |
Control library / policies & procedures | Control documents | |
Statement of Applicability | Auto-generated from framework config | |
CAPA / findings | Non-conformities with corrective/preventive actions | |
KPIs / OKRs / metrics | KPI readings on any document | |
Kanban / task tracking | Workbench checklists & boards | |
Evidence pack for auditor | Distribution (tracked, password-protected) |
π§ Your Setup at a Glance
Work through four phases. Each builds on the previous one, and each has a clear outcome and a natural owner.
Phase | Goal | Typical owner | Outcome |
|---|---|---|---|
0 Β· Foundations | Configure the workspace once | Admin / ISO manager | Folder tree, users, document types, risk methodology ready |
1 Β· Connected core | Assets β Risks β Controls, all linked | Risk & asset owners | A living, bi-directional GRC web |
2 Β· Compliance | Point frameworks at existing controls | Compliance lead | Live SoA + maturity, audit-ready |
3 Β· Operate & improve | Tasks, KPIs, reviews, reporting | Everyone | Continuous, evidenced improvement |
π‘ Fastest path to a first win: Do a lightweight Phase 0, document one primary asset with its risks and controls (Phase 1), then load your ISO 27001 template (Phase 2) to see the SoA and maturity radar populate from work you already did.
π₯ Where should I start?
- π‘ ISO / ISMS manager β Phase 0 (methodology & structure) β Phase 2 (load the framework).
- β οΈ Risk owner β Phase 1 (assets & risks) β governance tab.
- π Compliance / audit lead β Phase 2 (frameworks, SoA, distributions).
- π Management / executive β Performance & My Compliance dashboards (Phase 3).
π Phase 0 β Foundations (configure once)
"A few minutes of setup here saves hours of rework later." These are the admin-level decisions that shape everything downstream. Do them before mass-creating documents.
0.1 Β· Bring in your structure
- π Start from the best-practice folder structure provided during onboarding, or import your existing Word/Excel/PDF/PowerPoint files to recreate your hierarchy. See bulk document import.
- Each user also has a private inbox (recent activity, personal & flagged documents); folder colour indicators give at-a-glance status.
0.2 Β· Set up people & access early
- π€ Create your users and groups now so you can apply least-privilege from day one. See workspace users.
- π Control visibility with folder permissions β checklists and documents are only visible to users with read access to their folder.
- π§© Own via roles, not people. Point ownership properties at a Role / Responsibility document rather than a named employee, so ownership survives staff turnover.
0.3 Β· Tune document types, properties & templates
- π Brainframe ships 100+ document types with unique identifiers, properties and templates. Adjust which properties are mandatory/optional and where each type is created by default. See document types & templates.
- π· Document properties (owner, classification, review date, risk typeβ¦) are what make inventories filterable and reports consistent. Define your key ones now.
0.4 Β· Define your risk methodology
Configure this before creating any risk. Go to Workspace Settings β Risk Types (custom risk types):
- π Matrix scale β 3Γ3, 4Γ4, 5Γ5, 10Γ10 (others on request).
- π― Risk appetite β thresholds where appetite colours apply.
- β° Review frequency β how often each risk type is revisited.
- π Mandatory/optional properties per risk type.
π¨ You can override matrix colours purely for visualisation (to match your house conventions) without changing the underlying values.
0.5 Β· (Optional) Define KPI types
If you track metrics, set up KPI types now β default Unit / Financial / Percentage, or build custom KPI types with your own measures and formulas.
β Phase 0 done when: structure imported Β· users & permissions set Β· key properties defined Β· risk methodology configured.
πΈ Phase 1 β Build the Connected Core
"Know what you have, know what threatens it, know how you protect it." This is the operational heart of your program. Get this web right and compliance in Phase 2 flows almost for free.
1.1 Β· Map & create your assets
Sketch what matters most before you touch the platform (short workshops with department and technical leads: Who owns this? What does it depend on? What breaks if it's gone for an hour? A day?).
- π₯ Primary assets β core services, processes or data whose disruption causes real financial/operational/reputational damage.
- π§© Supporting assets β the systems and resources those depend on (servers, networks, SaaS, repositories, identity, suppliers).
In Resources β Core Business Assets (asset management):
- β Create a primary asset, or π link an existing document β Brainframe then auto-collects its supporting assets and related risks.
- Capture business requirements: β± RTO Β· πΎ RPO Β· π₯ criticality / max impact (all configurable properties).
- Assign ownership (to a role).
π The primary β supporting distinction is what builds your risk hierarchy and makes dependency chains visible and recursive.
1.2 Β· Attach supporting assets & visualise dependencies
- βοΈ Link technologies, suppliers, tools and data as supporting assets (each has its own document type).
- π The result is a recursive dependency chain you can explore in an expandable table view and in the graph view per document.
1.3 Β· Document your controls & continuity artefacts
- π‘ Controls β policies, procedures and technical safeguards. Each is one document, linkable from many risks, assets and (later) requirements.
- π BIA β do this first; it informs the RTO/RPO you set on assets.
- π BCP / DRP β continuity and recovery plans.
- βοΈ Threats & Vulnerabilities β the raw ingredients your risks are built from.
π‘ Recommended sequence: BIA β RTO/RPO on assets β which controls & continuity strategies you actually need.
1.4 Β· Create & link your risks
Create a risk from its document type (e.g. "Confidentiality, Integrity or Availability Risk (CIA)"). Each risk captures:
- π Auto-incrementing identifier (default
R-00x, customisable). - π Scenario, likelihood, impact, resulting level.
- π§ Existing controls & mitigations.
- π² Risk action β Treat / Terminate / Tolerate / Transfer (or a mix).
- π€ Risk owner β a role document wherever possible.
Then link β this is where the value compounds:
- π In Linked Documents, connect the risk to every affected asset, system or supplier (bi-directional β it appears on the asset too).
- π‘ Link existing controls to show what already mitigates it.
- β Add remediation tasks via the Workbench.
π Gap detector: any risk with no linked control and no explicit "tolerated" decision is a blind spot.
1.5 Β· Go deeper with the Governance tab
On an asset's Governance tab you can rate, per asset, how maturely each control is implemented and how critical each risk is β moving beyond simple links to quantified posture. See asset risks & controls governance.
1.6 Β· Validate the web
- πΈ Use dependency graphs to sanity-check the whole picture.
- π Each document's Risks tab shows risk evolution over time.
β Phase 1 done when: primary vs. supporting assets identified Β· owners (roles) assigned Β· RTO/RPO/criticality captured Β· every primary asset has β₯1 linked risk Β· every meaningful risk has a linked control or a documented "tolerated" decision.
π Phase 2 β Compliance Frameworks & the SoA
"Map any standard to controls you already built β and let Brainframe generate the paperwork." Because your controls exist from Phase 1, compliance is mostly pointing requirements at them.
2.1 Β· Add your framework
Compliance β Frameworks β Add Compliance Framework (compliance frameworks). Provide π name (e.g. ISO/IEC 27001:2022), and optionally π description, π public URL, π supporting documents.
π The framework/SoA module is admin-only and is not folder-hierarchy aware.
2.2 Β· Choose a setup method
- π§± Template β pre-loaded requirement set. Fastest for ISO 27001 (80+ frameworks supported out of the box).
- βοΈ Self-configured β build categories & requirements manually (custom/niche frameworks).
- π Excel import β bulk-load categories & requirements.
β οΈ Excel import brings in requirements only β linked controls, evidence, risks and notes are added afterward.
2.3 Β· Understand & link requirements
Each requirement carries an π identifier (e.g. A.5.1), π· title and π guidance. On each requirement:
- π‘ Link control β reuse the controls from Phase 1.
- π Link evidence β records, logs, screenshots.
- β οΈ Add risk β justify applicability and scope.
- β Add tasks β for anything not yet in place (they appear in your task list).
- π Notes β auditor comments / improvements.
π A single requirement/control can belong to multiple frameworks at once β one control can satisfy ISO 27001, GDPR and DORA together. Removing it from one leaves the others intact.
2.4 Β· Manage coverage from the Controls Overview
The Controls Overview dashboard (Compliance β Frameworks β Control overview) gives an organisation-wide view: total vs. actively-mitigating controls, control maturity, document maturity, and overdue reviews.
Its Framework Mapping matrix is the power view for multi-framework shops β rows are controls, columns are frameworks, cells show mapped requirements. Spot reuse, find gaps, and add mappings directly from the grid.
2.5 Β· Set applicability β auto-generate the SoA
- βοΈ Every requirement has an Applicable checkbox (on by default). Unchecking marks it N/A and excludes it from maturity tracking.
- π Nothing is deleted β linked controls, risks, evidence and notes are hidden and fully restored when you re-enable.
- π€ Brainframe auto-generates the Statement of Applicability from this configuration β click "Show Statement of Applicability" for the audit-ready table. There is no separate SoA to maintain by hand.
2.6 Β· Track maturity
As you link controls, evidence and risks, maturity builds automatically and is shown as a radar chart per category β weak categories become obvious before an auditor finds them.
2.7 Β· Handle findings: Non-conformities & Audits
- β Log Non-conformities and assign corrective & preventive actions (CAPA); track them to closure.
- π Keep a centralised Audit workspace, generate audit reports, and store auditable proofs. See the Compliance module.
2.8 Β· Prepare for the audit
- π¨ Print simple β categories, requirements, applicability, IDs, linked control & evidence names.
- π Print detailed β the above plus maturity radars and related risks per requirement.
- π€ Export to Excel β requirement details, status, linked controls, evidence, risks (re-importable).
- π¦ Distribution for external auditors β group evidence into categories, add π password protection, and enable π read/approval tracking. See distributions.
π‘ Schedule a periodic (e.g. quarterly) export as an offline backup of your compliance evidence.
β Phase 2 done when: framework added Β· controls linked to each applicable requirement Β· evidence attached Β· related risks linked Β· N/A items unchecked with justification Β· maturity radar reviewed Β· SoA generated Β· audit export/distribution prepared.
π Phase 3 β Operate & Continuously Improve
"GRC is not a one-off project β it's a living program." These modules turn your web into daily practice and keep it audit-ready between certifications.
- π Workbench & tasks β run remediation, onboarding, incidents and supplier lifecycles on Kanban boards (custom stages, dependencies, reminders, progress %). Folder-aware, with table view and workspace-wide charts. See process management.
- π― Objective Tracker (KPIs/OKRs) β record readings on any document, watch trendlines against targets, and consolidate them in the KPI menu. See objective tracker.
- π Performance dashboards β business, security and quality performance in one place for management reviews. See performance.
- β Approvals & versioning β formal document approvals and full version history keep policies controlled and auditable.
- β° Reminders & reviews β one-time or recurring reminders (with optional auto-created tasks) for policy reviews, supplier re-assessments and control reviews.
- π€ Suppliers & GDPR β manage third-party risk with supplier management and run privacy programs (RoPA, DPAs, DPIAs) with GDPR management.
- π My Compliance dashboard β each user's personal command centre: risk reviews, personal & process tasks, overdue items. See my compliance.
π How It All Connects
"Build once, comply many times."
ββββββββββββββββββββββββββββββββ
β Governance tab: maturity β
β & criticality ratings β
ββββββββββββββββ¬ββββββββββββββββ
β
Assets ββdepend onβββΊ Assets β
β βΌ
βββthreatened byβββΊ Risks ββmitigated byβββΊ Controls
β β
β β linked to
βΌ βΌ
Non-conformities Framework Requirements
(CAPA/tasks) (auto-generates the SoA
+ maturity radar)
- π· You document assets and dependencies.
- β οΈ You identify risks against them.
- π‘ You link controls that mitigate the risks.
- π You point framework requirements at those same controls.
- π€ Brainframe generates your SoA, maturity view, and reports automatically.
The controls you build for operational risk management are your compliance evidence. Nothing is done twice.
π Common Use Cases
- π Achieve ISO 27001 certification quickly from a template.
- π¦ Run a financial entity's ISMS under DORA.
- π Govern IoT / connected-device risks mapped to controls.
- π€ Track third-party / supplier risk and evidence.
- πΊ Run multiple overlapping frameworks (ISO 27001, GDPR, NIS2, SOC 2β¦) from one control set.
π Best Practices
- π Link, don't duplicate β one source of truth, updated everywhere.
- π€ Own via roles, not people β ownership survives turnover.
- π BIA first β it drives RTO/RPO and continuity strategy.
- π― Rate maturity honestly β accuracy beats optimism in audits.
- π Reassess risks quarterly or after major change.
- β»οΈ Reuse controls across frameworks β the biggest long-term saving.
- π Keep evidence attached to controls & requirements.
- π Watch the maturity radar β fix weak categories before auditors flag them.
- β° Automate reviews with reminders β never let a policy or supplier review lapse.
π― Master Checklist
Phase 0 β Foundations
- Folder structure imported / created
- Users, groups & folder permissions configured
- Key document properties & types tuned
- Risk methodology (matrix, appetite, review frequency) set
- KPI types defined (optional)
Phase 1 β Connected core
- Primary vs. supporting assets identified
- Owners (roles) assigned; RTO/RPO/criticality captured
- Supporting assets linked; dependencies visualised
- Core controls, BIA, BCP/DRP documented
- Every primary asset has β₯1 linked risk
- Every meaningful risk has a control or a "tolerated" decision
- Governance tab ratings reviewed
Phase 2 β Compliance
- Framework added (template / self-configured / Excel)
- Controls linked to each applicable requirement
- Evidence attached; related risks linked
- Applicability set (N/A justified)
- Maturity radar reviewed; SoA generated
- Non-conformities/CAPA & audits tracked
- Audit export / distribution prepared
Phase 3 β Operate & improve
- Workbench boards running for key processes
- KPIs & performance dashboards in management reviews
- Approvals & versioning enforced on controls
- Recurring reminders set for reviews
- My Compliance dashboard adopted by owners
π¬ Need help? Every module referenced above has a dedicated article in the documentation. If something is still unclear, contact us at support@brainframe.com.
Updated on: 06/07/2026
Thank you!