Getting started with Strike Graph
Written By Micah
The Strike Graph platform is organized into three main areas of content: risks, controls, and evidence. The following information will help your organization get started in building a strong compliance program.
Invite your team
First, it's important to consider who should be a part of your compliance dream team and invite them to join the Strike Graph platform. Once your teammates sign up, they can score risks, become control or evidence owners, upload evidence attachments, and more.
Guidance on adding users and inviting teammates is available here. When each new account is created, the new user will be added to your organization at the Contributor permission level (instead of a Manager), so always feel free to update user permissions to best support your organization's growing team.
Complete risk assessment
A great place to start getting a handle on your cybersecurity compliance journey is to begin with a Risk Assessment. This will help you better understand your IT landscape and appropriately scope your controls to cover only the areas that are applicable to your business.

You can find the Risk Assessment under the Risk Management section of Strike Graph. The Risk Assessment will prompt you to review your Risk Library and lead you through the scoring and mitigation process. Strike Graph's Risk Assessment is also fully customizable to fit the needs of your unique organization.
For more information on getting started with the Strike Graph Risk Assessment, click here.
A video demonstration of how to utilize Strike Graph's risk assessment tool can be found here.
Customize control set
After youβve completed the Risk Assessment, check out your Control Library. This will be your main point of reference as you work to establish and maintain your controls. Within the Control Library, you can monitor the status of your controls, see which cybersecurity framework criteria they address, what evidence items are suggested, and which risks each control helps mitigate.
A great place to start is to review and assign owners for each control. Control owners should be the functional business leader responsible for ensuring that the control is operational. It may be an executive, HR Manager, IT Director, or other leaders in your organization.
Strike Graph also empowers users to customize control descriptions, frequencies, and progress flags to reflect how your unique organization implements each control.
A video demonstration of how to utilize Strike Graph's Control Library can be found here.
Collect evidence
Once you have solidified your Control Library, the next step is to start collecting evidence to prove your control operation.
Evidence comes in many forms, and from all over your business. It may be a written document like a policy, a screenshot from one of your third-party systems confirming that settings are configured appropriately, or a sample of your onboarding process.
The Strike Graph Evidence Repository comes pre-loaded with over 300+ common pieces of evidence to cover the controls in your Control Library. Each evidence item is provided as a starting point and can be customized as necessary to suit your needs.
Strike Graph recommends reviewing your evidence items and assigning relevant evidence owners. Evidence owners are typically the person with direct access or responsibility for that evidence, so it may be an HR manager, a software engineer, or a project manager.
Strike Graph also offers integrations into popular third-party tools to help streamline evidence collection. Integrations also allow for automated collection to ease the burden of evidence expiration.
Questions?
Reach out through our chat feature for real-time Customer Success support 8 AM-5 PM PT Monday through Friday.