Getting started

First week checklist

The order of work that gets an organization from empty to audit-ready, mapped to the dashboard readiness plan.

RolesViewerEditorAdminRoute/Shown toAll organizations

What it is

The dashboard already contains a plan: one tab per framework, four phases, and a step list whose items complete themselves as you work. This checklist is that plan written out in the order that works best in practice, with the rule that marks each step done. Follow it and the Progress banner on the dashboard will climb without anyone ticking boxes.

Where to find it

Overviewframework tab
The dashboard readiness plan with phases and the accordion of implementation stepsThe dashboard readiness plan with phases and the accordion of implementation steps
The readiness plan. Each step shows its completion metric.

Key actions

Phase 01: setup and scoping

StepDone whenDo it
Company setupSeeded as done by the wizard; links to SettingsReview Settings → Context and fix anything you rushed in the wizard
FrameworksThe right frameworks are enabledChoose frameworks
TeamOwners and reviewers can sign inInvite your team

Phase 02: implementation

These are the accordion steps on the dashboard, in dashboard order. The completion rule is what the metric under each step measures.

StepComplete whenWhere the work happens
1. Critical Systems Scan FindingsFindings from connected systems are resolved; Rescan Systems runs a new passSecurity findings
2. Information Security Policies"Policies approved" reaches 100%Policies and the policy editor
3. Compliance Controls"Framework controls completed" reaches 100%Controls
4. Assets"Assets with owner" reaches 100%Assets
5. PersonnelMFA, signatures, and training coverage each reach 100%Personnel and Training and acknowledgement
6. Risk Assessment"Risks reviewed" reaches 100%, meaning every risk has a treatment planRisk register

Regulatory frameworks (GDPR, CCPA, EU AI Act) keep only steps 1, 2, 3, and 6.

A practical order for the week:

Connect the identity provider and one infrastructure source, then wait for the first sync. Steps 1, 3, 4, and 5 all move on their own after this.
Assign an owner to every asset. Use Select all and Edit on the assets page to do it in one pass.
Review generated policies, edit what does not match reality, and approve them. Each approved policy also fills the "Required policy" slot on the controls that need it.
Open the controls that still show partial coverage, link the missing evidence, and set an owner.
Give every risk a treatment plan, even if the treatment is to accept it.
Resolve or accept the scan findings that remain.

Phase 03: verification

StepComplete when
Run an internal auditAt least one internal audit exists under Audit

This phase is omitted for regulatory frameworks and CIS v8.

Phase 4: certification

StepComplete when
Publish a trust pageA trust page is published from the Trust center

When Phase 2 completes, the dashboard shows a Phase 2 complete card with Set up Trust Center and Contact Support buttons.

Statuses and fields

ElementMeaning
"Progress: N%"Readiness for the framework in the active tab
Mark as done / UndoManual override for a step; stored in your browser only
"View all …" linksOpen the listing page behind a step

Readiness for an auditable framework starts at 35% once the wizard finishes and adds up to 60 points from Phase 2; a regulatory framework's readiness is Phase 2 alone, out of 100.

Tips and gotchas

Manual marks are per browser

Mark as done is stored in your browser only, so a teammate on another machine does not see it. Use it for steps you have handled outside Noru, and let the metrics do the rest.

Do the sync-driven steps first. A day of waiting for syncs while you edit policies is cheaper than uploading evidence by hand that a connector would have collected anyway.

Personnel coverage counts the people in the directory. If shared or automation accounts are synced in, set their type to Service Account in the directory; service accounts are excluded from MFA requirements and compliance calculations.

What Noru does not do

The readiness percentage is a progress measure, not an audit opinion. Noru does not verify that an approved policy is followed, that an asset owner is the right person, or that a treatment plan is adequate. An auditor will.

Last updated on