Release Date |
Description |
December 2019 |
- We've added a new reporting feature called Custom Reporting. You can quickly create reports that provide details on the status of your tasks and the rate of completion for the controls you've implemented across your compliance and risk management initiatives. For more information, please see our Custom Reporting Guide.
- We've made the following changes to the Vendor Risk Management module:
- You can now create a template from the questionnaire you've created in your questionnaire builder. Your custom questionnaire templates can be re-used in a new questionnaire.
- In the questionnaire builder, after you've added questions to your questionnaire, you can now adjust the order in which the questions are displayed.
- A new column was added to the table in your Questionnaire List. You can now see the status of your questionnaires from this area. For more information, please see this article.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Customs Trade Partnership Against Terrorism (CTPAT)
- Cybersecurity Maturity Model Certification DRAFT (Levels 1 through 5)
- FFIEC IT Examination Handbook
- Singapore Personal Data Protection Act
- VDA - Trusted Information Security Assessment Exchange (TISAX)
- Vermont Data Broker Regulation
|
November 2019 |
- From the Vendor Risk Management module, you can now export a CSV file containing the details of a questionnaire that your vendor has completed. For more information, see Exporting Finalized Questionnaires.
- From the Vendor Risk Management module, you can now export a CSV file containing the details of your blank questionnaires. See here for more information.
- The questionnaire builder under the Vendor Risk Management (VRM) module has been completely overhauled to provide a better user experience and additional functionality.
- You can now preview, clone, and export the questionnaires you've created in your questionnaire builder. See this article to learn more.
- We've made the following changes to the Vendor Risk Management module:
- Resolved an issue where Vendor Users were unable to update vendor Issues from their Vendor Portal.
- Resolved an issue where updating/editing a questionnaire name from the Questionnaire - [Questionnaire Name] page did not carry over to previously and currently-scheduled questionnaires.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Bank Secrecy Act Examination Manual
- Colorado Data Protection Act
- Internet of Things Assessment Questionnaire
- US Government Auditing Standards
|
October 2019 |
- We've made the following changes to the Vendor Risk Management module:
- Resolved an issue where the incorrect answer was considered the 'correct answer' for vendor responses when using the 2019 SIG Lite and/or 2019 SIG Full questionnaire templates. These changes affected 46 questions in total. This will also update the Vendor Score for all affected vendors. If you'd like details about the answer changes, please reach out to our Support team.
- Resolved an issue where deleted questionnaires were not being removed from the Questionnaire List.
- Made minor visual changes to the way you view questionnaire schedules. For more information, see the Schedules tab under the Working with Vendor Profiles (Vendor Details) section of this article.
- We've updated the Quarterly Product Update video in our Knowledge Base. This video covers new features that have been added to KCM GRC, and the remaining KnowBe4 product line–over the previous quarter.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- American Land Title Association Assessment Procedures
- Association of Corporate Counsel (ACC) Model Information Protection and Security Controls for Outside Counsel
- Canada's Anti-Spam Legislation
- Cayman Islands Data Protection Law
- Cloud Computing Compliance Controls Catalogue
- Illinois Personal Information Protection Act
- North Carolina Identity Theft Protection Act
- UK Data Security and Protection Toolkit
- The following are updated Managed Templates are now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Secure Controls Framework v2019.6
|
September 2019
|
- Regarding the Questionnaire Templates offered under the Vendor Risk Management (VRM) module, we've resolved an issue where the incorrect answer was considered the 'correct answer' for vendor responses. This change affects any questionnaire that includes the question(s) below. Therefore, this will also update the Vendor Score for all applicable vendors. For more information, please reach out to our Support team.
- Affected Questionnaire Templates: 2019 SIG Lite, 2019 SIG Full
- Affected Questions: D.7 Are Constituents able to view client's unencrypted Data?
- The 'correct answer' has been changed from "Yes" to "No"
- Regarding the Vendor Risk Management (VRM) module, we've fixed an issue in the questionnaire builder where the question text wasn't fully visible if it were longer than a single line.
- This issue also impacted "free-form" responses from vendors. The issue has now been resolved.
- Regarding the Vendor Risk Management (VRM) module, we've fixed an issue where questionnaire questions were displayed in an incorrect order for vendor users and for KCM administrators when they were completing or reviewing questionnaires, respectfully.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Connecticut Insurance Data Security Law
- Lexcel England and Wales for In-house Legal Departments
- Lexcel England and Wales for Legal Practices
- Lexcel International
- Portugal Data Protection Law
- Sarbanes Oxley Act
- UK Data Protection Act
|
August 2019
|
- If you're using OneLogin or Okta as your SSO/SAML provider, you can configure your single sign-on by adding the "KCM GRC Platform" application to your provider's portal. See this article for more information.
- The following enhancements have been made to the Vendor Risk Management (VRM) Module:
- Regarding evidence due dates when using EDR, you can now override the default Effective Date Range Settings (found under Account Settings) on a per-control basis. See this article for more information.
- You can now manually offset the Vendor Score found under each vendor profile. From the Vendor Details page, click the Update button to change the existing Vendor Score.
- You can now include informational questions in your vendor assessments. These questions are not counted against the questionnaire score.
- Vendor Users can now edit their questionnaire answers after they have been saved, before the questionnaire has been finalized.
- You can now permanently delete vendor profiles from the Vendor List area of your VRM module.
- You can now permanently delete questionnaires from the Questionnaire List area of your VRM module.
- Fixed an issue in the questionnaire builder where you could save questions without adding answer options and were unable to configure the questionnaire as a result.
- Fixed an issue where auditor users were able to view tasks that had not been approved by an approving manager. Auditor users can only see tasks and task evidence that has been approved. See this article for more information about KCM user role permissions.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Australian Privacy Act
- Australian Prudential Standard CPS 234
- BDSG - German Federal Data Protection Act
- MDSAP - Australia: Therapeutic Goods (Medical Devices) Regulations
- MDSAP - Brazil: RDC (16, 23, 67)
- MDSAP - Canada: Medical Devices Regulations
- MDSAP - Japan: MHLW MO 169
- MDSAP - USA: Title 21 Food and Drug Regulation
- New Hampshire Senate Bill 193 v8.2019
- Privacy Shield Framework - EU-US
- Privacy Shield Framework - Swiss-US
- Texas House Bill 4390 - Privacy Protection Act
|
July 2019
|
- The KCM GRC platform now supports single sign-on and SAML 2.0 to allow your users to quickly and easily log in to KCM using your organization's single sign-on, without having to set up or use a password. See this article for more information.
- Under the Policy Management module, we've fixed an issue where "Invalid Date" was incorrectly showing under Policy Management > Campaigns > Campaign Name > Users tab (in Safari browsers).
- We've updated the Quarterly Product Update video in our Knowledge Base. This video covers new features that have been added to the KnowBe4 product line over the previous quarter.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Brazilian Data Protection Law (LGPD)
- Commonwealth of Virginia Hosted Environment Information Security Standard SEC 525
- FERPA
- Financial Conduct Authority Handbook (UK)
- Interagency Guidelines - Information Security Standards
- ISO 27002
- Texas Administrative Code §202 - State Agencies
- Texas Administrative Code §202 - Institutions of Higher Education
- UK Public Sector Network Code of Connection
- The following are updated Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- CJIS Security Policy v5.8
- HIPAA Privacy and Breach Rule
- HIPAA Security Rule
- The following enhancements have been made to the Vendor Risk Management (VRM) Module:
- When reviewing vendor questionnaires, you can now filter questions by the following: incorrect answers, answers with attachments, answers with issues, and informational questions.
- When reviewing vendor questionnaires, incorrect answers are now visually notated by a red line on the left-hand side of the question.
- In response to the significant growth of KCM GRC, the architecture of your platform was upgraded on July 17, 2019. This upgrade improves performance and allows us to better serve you by streamlining platform administration and maintenance.
|
June 2019
|
- The following enhancements have been made to the Vendor Risk Management (VRM) Module:
- When creating questionnaires, you can now upload a CSV file of custom questions. See here for details.
- When reviewing questionnaires, you can now change the score of vendor responses from the Questionnaire Review and Issue Details pages.
- When sending (scheduling) a questionnaire, you can set a suggested due date. The questionnaire assessee will see the due date in their email notification, and in their vendor portal.
- A Scheduled Questionnaires Calendar has been added to the Vendor Management Dashboard. All questionnaires are listed on the day were sent or will be sent.
- You can now cancel active questionnaires from the Assigned Questionnaires tab, under the Vendor Details page.
- You can now cancel questionnaire schedules (questionnaires to be sent) from the Schedules tab, under the Vendor Details page.
- If your vendor did not receive the email notification for their assigned questionnaire, you can now generate and send their login link from the Assigned Questionnaires tab, under the Vendor Details page.
- You can now archive questionnaires that have not been sent or scheduled.
- Vendor Administrator users can now view vendor profiles and questionnaires that have been archived. See this article to learn more about KCM user role privileges.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Gramm-Leach-Bliley Act Privacy Rule
- Gramm-Leach-Bliley Act Safeguard Rule
- IRS Publication 1075
|
May 2019
|
- You can now follow this article to stay informed of the new and updated Managed Templates available for your account. Our team ensures we have the up-to-date versions of these frameworks available for your use. Contact your Customer Success Manager to have additional templates added to your account.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- ASD Information Security Manual v3.2019
- Commonwealth of Virginia ITRM Standard SEC501 v10.1
- UK Ministry of Defence - Defence Standard Low Profile
- UK Ministry of Defence - Defence Standard Moderate Profile
- UK Ministry of Defence - Defence Standard High Profile
- The following are updated Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- CIS Critical Security Controls Group 1 7.1
- CIS Critical Security Controls Group 2 7.1
- CIS Critical Security Controls Group 3 7.1
|
April 2019
|
- The Vendor Risk Management (VRM) module was released.
- The VRM module lets you centralize your third-party risk management processes by prequalifying risk, assessing your vendors, and conducting remediation efforts in your KCM GRC platform. See our Introduction Guide to learn more.
- Updates were made to the User Roles available in your account. This includes updates to the User Management and User Profile pages in your account. See more information in our Working with Users article.
- You can now manage evidence submission settings (DocuLinks and documents) at the scope level–in addition to the account-wide settings. See more information in our Managing Account Settings article, here.
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- NCUA ACET v1.0
- DFARS NIST 800-171 SA v11.2017
- HMG Security Policy v1.0
- Massachusetts Data Privacy Regulation v2009
- The following are updated Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- CIS Critical Security Controls 7.1
- CCIS Critical Security Controls 7 to 7.1_Changes
|
March 2019
|
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- PCI DSS SAQ A
- PCI DSS SAQ B
- PCI DSS SAQ B-IB
- PCI DSS SAQ C
- PCI DSS SAQ C-VT
- PCI DSS SAQ D Merchants
- PCI DSS SAQ P2PE
- PCI DSS - SAQ D Service Providers v3.2.1
- Secure Controls Framework
- OWASP Level 1 v4.0
- OWASP Level 2 v4.0
- OWASP Level 3 v4.0
|
February 2019
|
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- Financial Services Sector Coordinating Council (FSSCC) v1.0
- NIST SP 800-171 Appendix E v2016
- FedRAMP High Baseline Controls v8.2018
- FedRAMP Moderate Baseline Controls v8.2018
- FedRAMP Low Baseline Controls v8.2018
- FedRAMP LI-SaaS Baseline v8.2018
- NIST 800-53 High-Impact Baseline rev4
- NIST 800-53 Moderate-Impact Baseline rev4
- NIST 800-53 Low-Impact Baseline rev4
- International Traffic in Arms Regulations (ITAR) v12.2018
- The following are updated Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
|
January 2019
|
- The following are new Managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- PCI DSS - Self-Assessment Questionnaire A-EP v3.2.1
- AB-375 Consumer Privacy Act of California v1.0
- NAIC MDL - Insurance Data Security Law v4th Quarter 2017
- PIPEDA v12.2018
- HITECH v2.2009
- The following are updated managed Templates now available for your account (contact your Customer Success Manager to have additional Templates added to your account):
- HIPAA Privacy and Breach v1.0
- HIPAA Security Rule v1.0
- PCI DSS Appendix A v3.2.1
- CJIS Security Policy v5.7
- SWIFT CSP v2019
|
Comments
0 comments
Article is closed for comments.