First 30 Minutes

This guide walks you through the most important setup steps in your first session.

Before you start

You will need:

  • Admin access to your AutoCISO organization
  • Your company’s legal name and primary industry
  • At least one team member to invite (optional but recommended)

Step 1: Complete your organization profile

Go to Settings → Organization and fill in:

  • Company name and logo
  • Industry and employee count
  • Primary contact and DPO (if applicable)

This information appears in generated reports and the Statement of Applicability.

Step 2: Import your employees

AutoCISO needs your employee list to run access reviews and gap analysis.

Connect your identity provider under Settings → Integrations:

  • Google Workspace
  • Microsoft Azure AD
  • Okta
  • Manual CSV import (for organizations without SSO)

Step 3: Run your first gap analysis

Go to ISO → Gap Analysis and click Run analysis. AutoCISO will:

  1. Map your current data to ISO 27001 Annex A controls
  2. Identify gaps and incomplete controls
  3. Generate a prioritized remediation backlog

This takes 1–3 minutes depending on your data volume.

Step 4: Review your top risks

Go to Risk → Risk Register to see risks identified during gap analysis. Use the status, domain, and strategy filters to review active, awaiting review, mitigated, accepted, avoided, or closed risks, then assign owners and target dates to the top 5–10 active items.

Step 5: Invite your team

Go to Settings → Team to invite colleagues. Assign roles:

  • Admin — full access including settings
  • Compliance Manager — access to ISO, Risk, Evidence, Audits
  • IT / Security Lead — access to access reviews, vulnerabilities, SBOMs
  • HR / Operations — access to employees and onboarding

What to do next

  • Follow the Setup Checklist to track your progress
  • Pick 2–3 guides from Guides relevant to your current priorities
Last reviewed: 2026-05-03

Was this page helpful?

Esc