Do you use an ERM-system that also includes cyber security risk management? What tools or systems do you use?

2.7k viewscircle icon3 Upvotescircle icon5 Comments
Sort by:
Director of Finance8 days ago

We are using Riskonnect across the group for ERM, Internal Controls, Digital Security Risks & Compliance, TPRM, IA, Global Policy Mgt, Insurance

CISO in Insurance (except health)9 days ago

We are using group wise https://www.gartner.com/reviews/market/it-vendor-risk-management-solutions/vendor/archer/product/archer?gxtm_source=peer-community&gxtm_page=detailview for ERM, IT and Security Risk

1 Reply
no title9 days ago

We are using Archer across the group. <br><br>PS. Someone please to edit my comment above.

Chief Technology Officer in Finance (non-banking)9 days ago

We use a GRC platform called Standard Fusion which has been a good mid-market solution for Enterprise Risk, IT Risk, etc. We are also evaluating Archer as a step-up.

CISO in Governmenta month ago

We use ZenGRC which has built in frameworks for compliance checks (NIST etc.). The firm also updates proactively when framework or compliance (HIPAA/CJIS etc.) requires change. We use it to track audits (very versatile to assign audit criteria) maintain compliance evidence; vendor compliance processes and reviews; internal policy compliance (and standards compliance, remote access compliance, and a few other functions. It also has a risk scoring hierarchy which helps take the guesswork out of our vendor cyber evals. Our other organizational divisions also use it to track their compliance (internal audit etc.), but the platform was identified, implemented and primarily used by our security team.

Content you might like

Alation11%

Amundsen27%

Collibra33%

Datahub29%

None21%

Others9%

View Results

Yes45%

No51%

Unsure4%

View Results