Lab · Product

    BISO Guide

    A working BISO operating system, running privately. Early access on request.

    Web app · Single operator · No public instance

    01The product

    What it is.

    BISO Guide is a single-operator web application that runs the business information security officer role end to end. Its spine is the four CISM domains: governance, risk management, program development and incident management. Each one is a working surface rather than a chapter heading.

    Everything the role produces has a place. The charter and the service catalogue, the risk register and the control library, the strategy map, the Statement of Applicability and the evidence behind it, incidents and the reviews that follow them.

    An AI agent workspace sits alongside all of it, and it is governed rather than trusted. The agent proposes, a person reviews, and only then is anything applied. Every intent, effect and reversal is recorded.

    It runs privately today. There is no public instance, no demo mode and no shared tenancy. Access is granted by hand, one operator at a time.

    02Contents

    What it carries.

    Seven layers, each one a surface the role actually has to work in.

    The BISO operating layer

    Profile and deployment model, a charter with a publish flow, a service catalogue with an inbox and triage, decision rights and scope-guard talk tracks. Alongside them, a health monitor that watches for seven known anti-patterns and a key-risk-indicator watch.

    Risk

    An ISO 27005 risk register, a control library with verification and validation, a risk profile heatmap, threat modelling with STRIDE, OCTAVE, LINDDUN and MITRE ATT&CK, and exceptions routed by a rules engine.

    Strategy

    Risk appetite and capacity, objectives, a versioned balanced-scorecard strategy map, and a NIST CSF capability tree carrying sliding-scale maturity.

    Assurance

    A Statement of Applicability, baselines, corrective and preventive actions, an evidence vault, a policy register, a third-party register, and gap analysis across them.

    Security operations

    Incidents, incident-response plans and playbooks, post-incident reviews, drills, and business impact analysis with continuity and recovery planning.

    Reference

    A library of 45+ standards on a seven-level clause taxonomy, with cross-standard mappings, plus a 20-chapter handbook inside the application.

    The governed AI agent

    A workspace where the agent proposes and a person disposes: write intents, effects and bundles, an autonomy matrix that says what may be attempted, evaluations, and standing jobs.

    03Access

    Early access on request.

    Access is granted by hand, one operator at a time. Write with a sentence or two about the function you run and what you would want the workspace to carry.

    04Method

    Built on these methods.

    The layers above cover the same ground as the methods published here. Where an entry on that ground exists, it is linked below; where nothing is published yet, the link goes to the index for that pillar.

    Risk register, control library and exceptions

    An independent, unofficial professional reference. Not affiliated with, authorized, sponsored, or otherwise endorsed by ISACA, NIST, ISO, or any other standards body. CISM® and AAISM™ are trademarks of ISACA.