Skip to Main Content
Cyber GRC Ideas Portal
ADD A NEW IDEA

All ideas

Showing 35

Configuring Design and Operating Effectiveness Values

Use Case: We use a shared responsibility model where some controls are provided by other parts of the org. Those controls are assessed separately and added to the evidence library for use in assessments of systems consuming the controls. My intent...
Guest 10 months ago in IT and Cyber Compliance 0 Pending Product Manager's Review

Report to view Common and Sample Questions response

Report to view the Common and Sample question responses provided by the Assessors or control owners during the testing
Guest 10 months ago in IT and Cyber Compliance 0 Pending Product Manager's Review

Enable copy paste functionality in Sample table of test execution page

Martktplaats B.V would like to be able to paste evidence into the sample table (in test execution page). This would allow them to fully use MetricStream to handle evidences. Currently, customer does this using the spreadsheet uploads. Other GRC so...
Guest almost 2 years ago in IT and Cyber Compliance 1 Pending Product Manager's Review

Complying with NIST 800-30 Cybersecurity Framework using IT and cyber risk module.

NIST SP 800-30 NIST Cybersecurity Framework is popular among companies in the US. NIST has become the gold standard for assessing cybersecurity maturity, identifying security gaps, and meeting cybersecurity regulations. Using our IT- risk module w...
Guest almost 3 years ago in IT and Cyber Risk 2 Pending Product Manager's Review

Request a function where if you want to edit the relationship list (add or remove) the pop-up window for the option shows what has already been selected previously.

I would like to request a function where if you want to edit the relationship list (add or remove) the pop-up window for the option shows what has already been selected previously. Currently if you want to edit it, the list does not show which one...
Guest over 1 year ago in IT and Cyber Risk 0 Pending Product Manager's Review

Need filter options in QP selection popup from Surveys

Currently, when we attempt to add Question and Procedures from library in the Questionnaire form under surveys, the QP popup window does not have filter options to choose right set of QPs. This is creating lot of inconvenience to customer when the...
Guest about 3 years ago in IT and Cyber Compliance 1 Pending Product Manager's Review

Ability to perform bulk manual Create Issue in the Vulnerability Scan Result Report

In the Vulnerability Management use case we see that the clients setup Remediation Rules for the Critical - Combined Risk Rating or other criteria's where remediation to be initiated as soon as the vulnerability is pulled into MetricStream. This l...
Guest almost 2 years ago in Threat & Vulnerability Management 0 Pending Product Manager's Review

Interaction between IT Risk and IT Compliance Module

In product's roadmap will there be interactions between IT Risk and IT Compliance Modules. For eg: Failure of a control and the creation of an issue in the IT compliance module does not change the Risk score in the IT Risk module. As this is suppo...
Guest almost 2 years ago in IT and Cyber Risk 0 Pending Product Manager's Review

Make Vector for Threat optional

Very often customers have threat data they want to upload/use, but do not have a threat vector defined for them. Can we make this field optional, or perhaps add values of Other or TBD.
Guest almost 2 years ago in IT and Cyber Risk 0 Pending Product Manager's Review

Ability to identify Risks not covered by any controls in the IT compliance product

Raiffeisen as part of it's use-case testing would like to • Identify risks which aren’t covered by any control• Identify assets which are not affected by a dedicated risk I tried Orphans - but the Assets are related to the Orgs and the Risks relat...
Guest about 2 years ago in IT and Cyber Compliance 0 Pending Product Manager's Review