Our team has been crushing it on our https://securityprogram.io platform. We're building neat features, and our customers are getting a lot out of it. I'm hoping we can release some of the case studies we're working on soon! This post describes some of the recent advances in the tool.
An important thing to do for security is to track who has access to what and make sure it reflects the correct designation of duties. Often, companies may see a person leave and never revoke their access. A user audit ensures that these types of situations are detected and remediated.
It is possible to do user auditing by hand, but it can be a pain. You have to know how to get to the reports from each different system, and you have to remember to do it every month.
In SPIO, we now make this easy for GitHub and AWS, with Google Apps and Azure/O365 support on the way. Here's how it works:
The process is to review the access levels and confirm that everyone has the right level of privileges. By unifying the UI for this across the most common platforms, we make it much easier to do this important security program task!
Friendliness is a core value at Jemurai.
Although we understand what we're thinking (mostly) with securityprogram.io, we realize that there are a lot of new ideas and industry jargon for users that aren't well versed in security - which is our target audience!
So we added product tours for things like the Risk Register and the Vendor Tracker. What is it? How do you use it? What do the fields mean?
We also added articles for deeper context. Articles provide background like Why is this important?
We also added in app support via Intercom. This allows users to ask for help and get it in near real time while they are in the application!
SPIO captures important tasks you need to do to build a security program. Within the tool, we tag tasks and allow you to filter your views based on these tags. By doing this, you can identify and zero in on the tasks that you most want to see. For example, filter to simple program
and get the 20 things we think should be part of every simple program. Alternatively, you search for cis 20:
or even cis 20: control 13
to see only tasks covering specific standards, areas, or controls you care about.
We expect to add more detailed mapping to NIST CSF, FERPA and other standards to make reviewing tasks in context really easy.
In addition to the core Security Awareness Training and Policy related training that we already had, we released training for:
Did I mention that the training is built right into the platform and can be tracked right on the dashboard?
The things we're working on now include:
We'd love to hear from you about what you think we should do next!