> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How to Start with Brainframe

# 🚀 **How to Start with Brainframe**

> **"Build your GRC program once — as a connected web of assets, risks, controls and requirements — and let audits, reports and the Statement of Applicability generate themselves."**
>
> *This guide takes you from an empty workspace to a fully connected GRC environment. It is written for GRC professionals, so it focuses on **how Brainframe models your world** and the fastest path to value — not on explaining GRC fundamentals you already know.*

---

## 🧠 The One Concept That Makes Everything Click

Brainframe is built on a single idea:

> **Everything is a document, documents live in a familiar folder tree, and documents link to each other bi-directionally.**

Internalise this and the whole platform becomes intuitive:

* 📄 **Everything is a document** — assets, risks, policies, procedures, suppliers, KPIs, meeting notes, audit reports. They all share the same features (properties, versioning, approvals, reminders, tasks). See a [document view](https://docs.brainframe.com/en/article/document-view-1xqae9v/).
* 🔗 **Links are bi-directional** — link a risk to an asset once and it appears on both. Update the source and it updates everywhere. There is no "copy" — only one source of truth.
* ♻️ **Reuse over duplication** — one control document can mitigate many risks *and* satisfy requirements across ISO 27001, GDPR, NIS2 and DORA simultaneously. You build it once.

> 📌 The connected web you build in Phase 1 **is** your audit evidence in Phase 2. Nothing is ever done twice.

### 🗺 How Brainframe maps to your GRC vocabulary

| You already think in terms of… | In Brainframe it is a… | Lives under… |
| ---- |
| Asset inventory / CMDB | Primary & supporting **asset documents** | [Resources](https://docs.brainframe.com/en/article/resources-abzzvs/) |
| Risk register | **Risk documents** on a matrix + inventory | [Risks](https://docs.brainframe.com/en/article/risks-li00v8/) |
| Control library / policies & procedures | **Control documents** | [Controls Overview](https://docs.brainframe.com/en/article/controls-overview-1guam0z/) |
| Statement of Applicability | **Auto-generated** from framework config | [Compliance](https://docs.brainframe.com/en/article/compliance-1wcl5p/) |
| CAPA / findings | **Non-conformities** with corrective/preventive actions | [Compliance](https://docs.brainframe.com/en/article/compliance-1wcl5p/) |
| KPIs / OKRs / metrics | **KPI readings** on any document | [Objective Tracker](https://docs.brainframe.com/en/article/objective-tracker-vk68w9/) |
| Kanban / task tracking | **Workbench** checklists & boards | [Workbench](https://docs.brainframe.com/en/article/workbench-of9sr0/) |
| Evidence pack for auditor | **Distribution** (tracked, password-protected) | [Distributions](https://docs.brainframe.com/en/article/document-distribution-1k2gqwz/) |

---

## 🧭 Your Setup at a Glance

Work through four phases. Each builds on the previous one, and each has a clear outcome and a natural owner.

| Phase | Goal | Typical owner | Outcome |
| ---- |
| **0 · Foundations** | Configure the workspace once | Admin / ISO manager | Folder tree, users, document types, risk methodology ready |
| **1 · Connected core** | Assets → Risks → Controls, all linked | Risk & asset owners | A living, bi-directional GRC web |
| **2 · Compliance** | Point frameworks at existing controls | Compliance lead | Live SoA + maturity, audit-ready |
| **3 · Operate & improve** | Tasks, KPIs, reviews, reporting | Everyone | Continuous, evidenced improvement |

> 💡 **Fastest path to a first win:** Do a lightweight Phase 0, document **one** primary asset with its risks and controls (Phase 1), then load your **ISO 27001 template** (Phase 2) to see the SoA and maturity radar populate from work you already did.

### 👥 Where should *I* start?

* 🛡 **ISO / ISMS manager** → Phase 0 (methodology & structure) → Phase 2 (load the framework).
* ⚠️ **Risk owner** → Phase 1 (assets & risks) → governance tab.
* 📋 **Compliance / audit lead** → Phase 2 (frameworks, SoA, distributions).
* 📊 **Management / executive** → [Performance](https://docs.brainframe.com/en/article/performance-ewfk9q/) & [My Compliance](https://docs.brainframe.com/en/article/my-compliance-w4ie2c/) dashboards (Phase 3).

---

# 🏗 Phase 0 — Foundations (configure once)

> **"A few minutes of setup here saves hours of rework later."** These are the admin-level decisions that shape everything downstream. Do them before mass-creating documents.

## 0.1 · Bring in your structure

* 🗂 Start from the **best-practice folder structure** provided during onboarding, **or** import your existing Word/Excel/PDF/PowerPoint files to recreate your hierarchy. See [bulk document import](https://docs.brainframe.com/en/article/bulk-document-import-12vfyj6/).
* Each user also has a **private inbox** (recent activity, personal & flagged documents); folder **colour indicators** give at-a-glance status.

## 0.2 · Set up people & access early

* 👤 Create your **users and groups** now so you can apply least-privilege from day one. See [workspace users](https://docs.brainframe.com/en/article/workspace-users-ftkgjk/).
* 🔐 Control visibility with [folder permissions](https://docs.brainframe.com/en/article/folder-permissions-htlsk6/) — checklists and documents are only visible to users with read access to their folder.
* 🧩 **Own via roles, not people.** Point ownership properties at a *Role / Responsibility* document rather than a named employee, so ownership survives staff turnover.

## 0.3 · Tune document types, properties & templates

* 📑 Brainframe ships **100+ document types** with unique identifiers, properties and templates. Adjust which properties are mandatory/optional and where each type is created by default. See [document types & templates](https://docs.brainframe.com/en/article/document-types-templates-lssmkc/).
* 🏷 [Document properties](https://docs.brainframe.com/en/article/document-properties-1jern28/) (owner, classification, review date, risk type…) are what make inventories filterable and reports consistent. Define your key ones now.

## 0.4 · Define your risk methodology

Configure this **before creating any risk**. Go to **Workspace Settings → Risk Types** ([custom risk types](https://docs.brainframe.com/en/article/custom-risk-types-x8x0pe/)):

* 📐 **Matrix scale** — 3×3, 4×4, 5×5, 10×10 (others on request).
* 🎯 **Risk appetite** — thresholds where appetite colours apply.
* ⏰ **Review frequency** — how often each risk type is revisited.
* 📋 **Mandatory/optional properties** per risk type.

> 🎨 You can override matrix colours purely for visualisation (to match your house conventions) without changing the underlying values.

## 0.5 · (Optional) Define KPI types

If you track metrics, set up **KPI types** now — default *Unit / Financial / Percentage*, or build [custom KPI types](https://docs.brainframe.com/en/article/custom-kpi-types-1vafrb3/) with your own measures and formulas.

**✅ Phase 0 done when:** structure imported · users & permissions set · key properties defined · risk methodology configured.

---

# 🕸 Phase 1 — Build the Connected Core

> **"Know what you have, know what threatens it, know how you protect it."** This is the operational heart of your program. Get this web right and compliance in Phase 2 flows almost for free.

## 1.1 · Map & create your assets

Sketch **what matters most** before you touch the platform (short workshops with department and technical leads: *Who owns this? What does it depend on? What breaks if it's gone for an hour? A day?*).

* 🥇 **Primary assets** — core services, processes or data whose disruption causes real financial/operational/reputational damage.
* 🧩 **Supporting assets** — the systems and resources those depend on (servers, networks, SaaS, repositories, identity, suppliers).

In **Resources → Core Business Assets** ([asset management](https://docs.brainframe.com/en/article/asset-management-16ofn81/)):

* ➕ **Create** a primary asset, **or** 🔗 **link an existing document** — Brainframe then auto-collects its supporting assets and related risks.
* Capture **business requirements**: ⏱ RTO · 💾 RPO · 🔥 criticality / max impact (all configurable properties).
* Assign **ownership** (to a role).

> 📌 The primary → supporting distinction is what builds your **risk hierarchy** and makes dependency chains visible and recursive.

## 1.2 · Attach supporting assets & visualise dependencies

* ⚙️ Link technologies, suppliers, tools and data as supporting assets (each has its own document type).
* 🌐 The result is a **recursive dependency chain** you can explore in an **expandable table view** and in the **graph view** per document.

## 1.3 · Document your controls & continuity artefacts

* 🛡 **Controls** — policies, procedures and technical safeguards. Each is one document, linkable from *many* risks, assets and (later) requirements.
* 📉 **BIA** — do this **first**; it informs the RTO/RPO you set on assets.
* 🔄 **BCP / DRP** — continuity and recovery plans.
* ⚔️ **Threats & Vulnerabilities** — the raw ingredients your risks are built from.

> 💡 **Recommended sequence:** BIA → RTO/RPO on assets → which controls & continuity strategies you actually need.

## 1.4 · Create & link your risks

Create a risk from its document type (e.g. **"Confidentiality, Integrity or Availability Risk (CIA)"**). Each risk captures:

* 🆔 Auto-incrementing identifier (default `R-00x`, customisable).
* 📝 Scenario, likelihood, impact, resulting level.
* 🔧 Existing controls & mitigations.
* 🎲 **Risk action** — Treat / Terminate / Tolerate / Transfer (or a mix).
* 👤 **Risk owner** — a role document wherever possible.

Then **link** — this is where the value compounds:

* 🔗 In **Linked Documents**, connect the risk to every affected asset, system or supplier (bi-directional — it appears on the asset too).
* 🛡 Link **existing controls** to show what already mitigates it.
* ✅ Add remediation **tasks** via the [Workbench](https://docs.brainframe.com/en/article/workbench-of9sr0/).

> 📌 **Gap detector:** any risk with no linked control and no explicit "tolerated" decision is a blind spot.

## 1.5 · Go deeper with the Governance tab

On an asset's **Governance tab** you can rate, per asset, **how maturely each control is implemented** and **how critical each risk is** — moving beyond simple links to quantified posture. See [asset risks & controls governance](https://docs.brainframe.com/en/article/asset-risks-and-controls-governance-1y7i7hu/).

## 1.6 · Validate the web

* 🕸 Use **dependency graphs** to sanity-check the whole picture.
* 📊 Each document's **Risks tab** shows risk evolution over time.

**✅ Phase 1 done when:** primary vs. supporting assets identified · owners (roles) assigned · RTO/RPO/criticality captured · every primary asset has ≥1 linked risk · every meaningful risk has a linked control *or* a documented "tolerated" decision.

---

# 📋 Phase 2 — Compliance Frameworks & the SoA

> **"Map any standard to controls you already built — and let Brainframe generate the paperwork."** Because your controls exist from Phase 1, compliance is mostly *pointing requirements at them*.

## 2.1 · Add your framework

**Compliance → Frameworks → Add Compliance Framework** ([compliance frameworks](https://docs.brainframe.com/en/article/compliance-frameworks-1mq2uoa/)). Provide 📛 name (e.g. `ISO/IEC 27001:2022`), and optionally 📄 description, 🔗 public URL, 📎 supporting documents.

> 📌 The framework/SoA module is **admin-only** and is **not** folder-hierarchy aware.

## 2.2 · Choose a setup method

* 🧱 **Template** — pre-loaded requirement set. **Fastest for ISO 27001** (80+ frameworks supported out of the box).
* ✍️ **Self-configured** — build categories & requirements manually (custom/niche frameworks).
* 📊 **Excel import** — bulk-load categories & requirements.

> ⚠️ Excel import brings in **requirements only** — linked controls, evidence, risks and notes are added afterward.

## 2.3 · Understand & link requirements

Each requirement carries an 🆔 identifier (e.g. `A.5.1`), 🏷 title and 📖 guidance. On each requirement:

* 🛡 **Link control** — **reuse the controls from Phase 1**.
* 📁 **Link evidence** — records, logs, screenshots.
* ⚠️ **Add risk** — justify applicability and scope.
* ✅ **Add tasks** — for anything not yet in place (they appear in your task list).
* 📝 **Notes** — auditor comments / improvements.

> 🔗 A single requirement/control can belong to **multiple frameworks at once** — one control can satisfy ISO 27001, GDPR and DORA together. Removing it from one leaves the others intact.

## 2.4 · Manage coverage from the Controls Overview

The [Controls Overview](https://docs.brainframe.com/en/article/controls-overview-1guam0z/) dashboard (**Compliance → Frameworks → Control overview**) gives an organisation-wide view: total vs. actively-mitigating controls, **control maturity**, **document maturity**, and **overdue reviews**.

Its **Framework Mapping matrix** is the power view for multi-framework shops — rows are controls, columns are frameworks, cells show mapped requirements. Spot reuse, find gaps, and add mappings directly from the grid.

## 2.5 · Set applicability → auto-generate the SoA

* ☑️ Every requirement has an **Applicable** checkbox (on by default). Unchecking marks it **N/A** and excludes it from maturity tracking.
* 📌 **Nothing is deleted** — linked controls, risks, evidence and notes are hidden and fully restored when you re-enable.
* 🤖 Brainframe **auto-generates the Statement of Applicability** from this configuration — click **"Show Statement of Applicability"** for the audit-ready table. There is **no separate SoA to maintain by hand**.

## 2.6 · Track maturity

As you link controls, evidence and risks, **maturity builds automatically** and is shown as a **radar chart per category** — weak categories become obvious *before* an auditor finds them.

## 2.7 · Handle findings: Non-conformities & Audits

* ❌ Log **Non-conformities** and assign **corrective & preventive actions (CAPA)**; track them to closure.
* 🔍 Keep a centralised **Audit** workspace, generate audit reports, and store auditable proofs. See the [Compliance module](https://docs.brainframe.com/en/article/compliance-1wcl5p/).

## 2.8 · Prepare for the audit

* 🖨 **Print simple** — categories, requirements, applicability, IDs, linked control & evidence names.
* 📊 **Print detailed** — the above **plus** maturity radars and related risks per requirement.
* 📤 **Export to Excel** — requirement details, status, linked controls, evidence, risks (re-importable).
* 📦 **Distribution** for external auditors — group evidence into categories, add 🔐 password protection, and enable 👁 read/approval tracking. See [distributions](https://docs.brainframe.com/en/article/document-distribution-1k2gqwz/).

> 💡 Schedule a periodic (e.g. quarterly) export as an offline backup of your compliance evidence.

**✅ Phase 2 done when:** framework added · controls linked to each applicable requirement · evidence attached · related risks linked · N/A items unchecked with justification · maturity radar reviewed · SoA generated · audit export/distribution prepared.

---

# 🔄 Phase 3 — Operate & Continuously Improve

> **"GRC is not a one-off project — it's a living program."** These modules turn your web into daily practice and keep it audit-ready between certifications.

* 🛠 **Workbench & tasks** — run remediation, onboarding, incidents and supplier lifecycles on **Kanban boards** (custom stages, dependencies, reminders, progress %). Folder-aware, with table view and workspace-wide charts. See [process management](https://docs.brainframe.com/en/article/process-management-br4e74/).
* 🎯 **Objective Tracker (KPIs/OKRs)** — record readings on any document, watch trendlines against targets, and consolidate them in the KPI menu. See [objective tracker](https://docs.brainframe.com/en/article/objective-tracker-vk68w9/).
* 📊 **Performance dashboards** — business, security and quality performance in one place for management reviews. See [performance](https://docs.brainframe.com/en/article/performance-ewfk9q/).
* ✅ **Approvals & versioning** — formal [document approvals](https://docs.brainframe.com/en/article/document-approvals-dmgns6/) and full [version history](https://docs.brainframe.com/en/article/document-versioning-5ikgy4/) keep policies controlled and auditable.
* ⏰ **Reminders & reviews** — one-time or recurring [reminders](https://docs.brainframe.com/en/article/document-reminders-1dz7kr2/) (with optional auto-created tasks) for policy reviews, supplier re-assessments and control reviews.
* 🤝 **Suppliers & GDPR** — manage third-party risk with [supplier management](https://docs.brainframe.com/en/article/supplier-management-9yrcxi/) and run privacy programs (RoPA, DPAs, DPIAs) with [GDPR management](https://docs.brainframe.com/en/article/gdpr-management-8sjur4/).
* 📌 **My Compliance dashboard** — each user's personal command centre: risk reviews, personal & process tasks, overdue items. See [my compliance](https://docs.brainframe.com/en/article/my-compliance-w4ie2c/).

---

# 🔗 How It All Connects

> **"Build once, comply many times."**

```
                         ┌──────────────────────────────┐
                          │   Governance tab: maturity   │
                          │   & criticality ratings      │
                          └──────────────┬───────────────┘
                                         │
   Assets ──depend on──► Assets          │
     │                                   ▼
     └──threatened by──► Risks ──mitigated by──► Controls
                           │                        │
                           │                        │ linked to
                           ▼                        ▼
                    Non-conformities        Framework Requirements
                       (CAPA/tasks)         (auto-generates the SoA
                                             + maturity radar)
```

* 🏷 You document **assets** and dependencies.
* ⚠️ You identify **risks** against them.
* 🛡 You link **controls** that mitigate the risks.
* 📋 You point **framework requirements** at those same controls.
* 🤖 Brainframe generates your **SoA, maturity view, and reports** automatically.

The controls you build for operational risk management **are** your compliance evidence. Nothing is done twice.

---

## 📌 Common Use Cases

* 🏅 Achieve **ISO 27001 certification** quickly from a template.
* 🏦 Run a financial entity's **ISMS under DORA**.
* 🔌 Govern **IoT / connected-device** risks mapped to controls.
* 🤝 Track **third-party / supplier** risk and evidence.
* 🗺 Run **multiple overlapping frameworks** (ISO 27001, GDPR, NIS2, SOC 2…) from one control set.

---

## 🌟 Best Practices

* 📁 **Link, don't duplicate** — one source of truth, updated everywhere.
* 👤 **Own via roles, not people** — ownership survives turnover.
* 📉 **BIA first** — it drives RTO/RPO and continuity strategy.
* 🎯 **Rate maturity honestly** — accuracy beats optimism in audits.
* 🔍 **Reassess risks quarterly** or after major change.
* ♻️ **Reuse controls across frameworks** — the biggest long-term saving.
* 🗂 **Keep evidence attached** to controls & requirements.
* 📊 **Watch the maturity radar** — fix weak categories before auditors flag them.
* ⏰ **Automate reviews with reminders** — never let a policy or supplier review lapse.

---

## 🎯 Master Checklist

**Phase 0 — Foundations**
* [ ] Folder structure imported / created
* [ ] Users, groups & folder permissions configured
* [ ] Key document properties & types tuned
* [ ] Risk methodology (matrix, appetite, review frequency) set
* [ ] KPI types defined *(optional)*

**Phase 1 — Connected core**
* [ ] Primary vs. supporting assets identified
* [ ] Owners (roles) assigned; RTO/RPO/criticality captured
* [ ] Supporting assets linked; dependencies visualised
* [ ] Core controls, BIA, BCP/DRP documented
* [ ] Every primary asset has ≥1 linked risk
* [ ] Every meaningful risk has a control **or** a "tolerated" decision
* [ ] Governance tab ratings reviewed

**Phase 2 — Compliance**
* [ ] Framework added (template / self-configured / Excel)
* [ ] Controls linked to each applicable requirement
* [ ] Evidence attached; related risks linked
* [ ] Applicability set (N/A justified)
* [ ] Maturity radar reviewed; SoA generated
* [ ] Non-conformities/CAPA & audits tracked
* [ ] Audit export / distribution prepared

**Phase 3 — Operate & improve**
* [ ] Workbench boards running for key processes
* [ ] KPIs & performance dashboards in management reviews
* [ ] Approvals & versioning enforced on controls
* [ ] Recurring reminders set for reviews
* [ ] My Compliance dashboard adopted by owners

---

> 💬 **Need help?** Every module referenced above has a dedicated article in the documentation. If something is still unclear, contact us at support@brainframe.com.
