Interaction between IT Risk and IT Compliance Module
In product's roadmap will there be interactions between IT Risk and IT Compliance Modules. For eg: Failure of a control and the creation of an issue in the IT compliance module does not change the Risk score in the IT Risk module. As this is suppo...
Guest
almost 2 years ago
in IT and Cyber Risk
0
Pending Product Manager's Review
Very often customers have threat data they want to upload/use, but do not have a threat vector defined for them. Can we make this field optional, or perhaps add values of Other or TBD.
Guest
almost 2 years ago
in IT and Cyber Risk
0
Pending Product Manager's Review
Ability to identify Risks not covered by any controls in the IT compliance product
Raiffeisen as part of it's use-case testing would like to • Identify risks which aren’t covered by any control• Identify assets which are not affected by a dedicated risk I tried Orphans - but the Assets are related to the Orgs and the Risks relat...
Adidas would like the Evidence Management (Project) to have a recurring Frequency - this can be useful for evidence that needs to be gathered once a quarter or once a year for example - they can then setup the project just once and the request rec...
Adding all vulenrability detail pulled from tenable or other connectors to Vulnerability scan results report
Adding all vulnerability detail pulled from tenable or other connectors to Vulnerability scan results report
Otherwise, provide different reports for different connectors
Asset Library data should get pulled from Connector
PIF use Tenable as Connector and we should pull Asset Library data from the connector only and to create GRC library - Asset for it like UCF instead of asking users to create asset in GRC library as well
Adding Vilnerability Ageing to the Rule Wizard and Calculate & Fetch the First Identified Date and Last Scanned date from tenable-to configure the automation for items that are not compliant as per the risk appetite
Customer use Tenable ...
UCF content - tracking the data import process should improve
There should be an import status progress report The object levels should be added to Framework Referece object Imported Questions and Procedures should be mapped to the respective controls
IT Risk Assessment form: Ability to show Question name as response filed header for free text columns
If there are more number of questions in assessment secion, when assessor click on response then customer need to know for which question, they need to provide response.
Guest
over 2 years ago
in IT and Cyber Risk
0
Pending Product Manager's Review