Release Date |
Description |
December 2022 |
- We've added new fields to the risk import feature. Now, you can import your risks in bulk with a Category, Subcategory, Likelihood, Impact, and more. For more information, see our How to Import Risks to Your Risk Register article.
- We’ve added a bulk editing feature to your Risk Register. Now, you can update the Category, Likelihood, Impact, and Status of multiple risks at once. For more information, see the Updating Risks in Bulk section of our How to Use Your Risk Register article.
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- Standardized Information Gathering (SIG) Lite v2022 to v2023
- Standardized Information Gathering (SIG) Core v2022 to v2023
- Standardized Information Gathering (SIG) Detail v2022 to v2023
|
November 2022
|
- We've added an in-line editing feature to your risks. Now, you can edit your risks directly from the Risk Register instead of navigating to the View Risk page. For more information, see the Viewing and Updating Risks section of our How to Use Your Risk Register article.
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- ISO 27001 v2013 to v2022
- ISO 27001 Annex v2013 to v2022
- NERC CIP: Physical Security v014-2 to v014-3
- We've updated the following policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- Risk Assessment Policy
- Risk Management Policy
|
October 2022 |
- We've added an integration with KnowBe4’s KMSAT console to your platform. You can use this integration to create automated tasks that will collect your users' KMSAT training completions as evidence. For more information, see our How to Integrate KnowBe4's KMSAT Console with KCM GRC article.
- We've added a View All Risks button to your Risk Register. After using the search and filter features to find specific risks, you can click this button to view all of your risks at once. For more information, see our How to Use Your Risk Register article.
|
September 2022 |
- We’ve added a new framework to our free tool, the Compliance Audit Readiness Assessment (CARA). This new framework is the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, which you can use to make sure your organization is securing electronic protected health information (ePHI).
- We’ve improved the display and user experience of the Risk Register. To help you find your risks easily, we’ve also added a Filter widget. For more information, see our How to Use Your Risk Register article.
- We've added an integration with Atlassian Jira Software to your platform. You can use this integration to manage your KCM GRC tasks in Jira. For more information, see our How to Integrate Atlassian Jira Software with KCM GRC article.
- We’ve released revised control guidance for our PCI DSS managed template. KCM’s control guidance feature helps you create adequate controls so your organization can meet its requirements or other compliance efforts. To learn more about our control guidance, see these articles:
|
August 2022
|
- We've updated the following policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- Data Disposal Policy
- Record Retention Policy
- We've added the new Resource Center feature to your platform. From the Resource Center, you can view a full list of product guides and release notes, search our Knowledge Base, and create support tickets. For more information, see the Using the Resource Center section of our How to Use the Product Guide Feature article.
- We've released the new product guide feature. Product guides walk you through specific features to help you get the most out of your platform. For more information, see our How to Use the Product Guide Feature article.
- We've added the following new plan template for you to download and customize for your organization. For more information, see our How to Use Plan Templates in Your Platform article.
- Information Systems Continuity Plan
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- UK Data Security and Protection Toolkit Standard v22-23
|
July 2022
|
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- NERC CIP Cyber Security — Personnel & Training CIP-004-7
- NERC CIP Cyber Security — Electronic Security Perimeters CIP-005-7
- NERC CIP Cyber Security — Configuration Change Management and Vulnerability Assessments CIP-010-4
- NERC CIP Cyber Security — Information Protection CIP-011-3
- NERC CIP Cyber Security — Supply Chain Risk Management CIP-013-2
- We've added the following new managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- NERC CIP Cyber Security — Communications between Control Centers CIP-012-1
|
June 2022
|
- We've added a Notes column to the CSV file for the vendor list export. For more information, see the Exporting a Vendor List section of our How to Export Data in the Vendor Risk Management Module article.
- We’ve added a new framework to our free tool, the Compliance Audit Readiness Assessment (CARA). This new framework is the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF), which you can use to help your organization build its cybersecurity plan.
- We've updated the following policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- Acceptable Use Policy
- Email Security Policy
- We've updated the following managed template. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- UK Cyber Security Essentials v2.2 to v3.0
|
May 2022
|
- We’ve released revised control guidance for our HIPAA Security Rule managed template. KCM’s control guidance feature helps you create adequate controls so your organization can meet its requirements or other compliance efforts. To learn more about our control guidance, see these articles:
- We've improved our policy uploading process when you upload multiple policy files to your Policy Management module. Now, each file will process individually, so it may take more time for your files to upload. For more information, see the Uploaded Policies section of our Policy Management Module Guide.
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- PCI DSS Self Assessment Questionnaire A v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire A-EP v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire B v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire B-IP v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire C v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire C-VT v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire D Merchants v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire D Service Providers v3.2.1 to v4.0
- PCI DSS Self Assessment Questionnaire P2PE v3.2.1 to v4.0
- We've added the following new policy template for you to download and customize for your organization. For more information, see our Policy Templates article.
|
April 2022
|
- We've added the following new plan template for you to download and customize for your organization. For more information, see our How to Use Plan Templates in Your Platform article.
- We've added the following new policy template for you to download and customize for your organization. For more information, see our Policy Templates article.
- Security Awareness Training and Testing Policy
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- International Traffic in Arms Regulations (ITAR) v4.2021 to v4.2022
- OWASP Level 1 v4.0.2 to v4.0.3
- OWASP Level 2 v4.0.2 to v4.0.3
- OWASP Level 3 v4.0.2 to v4.0.3
- PCI DSS v3.2.1 to v4.0
- PCI DSS Appendix A v3.2.1 to v4.0
- UK Anti Bribery Statute Adequate Procedures Checklist v5.21012 to v2022
- UK Data Security and Protection Toolkit Standard v20-21 to v21-22
|
March 2022
|
- We’ve released revised control guidance for our NIST CSF managed template. KCM’s control guidance feature helps you create adequate controls so your organization can meet its requirements or other compliance efforts. To learn more about our control guidance, see these articles:
- We've improved our search feature in specific areas of your platform. On the pages listed below, KCM GRC will save the previous terms you entered into the search bars. This will allow you to refresh your page, close your browser, or move between different KCM GRC tabs without losing the last search term you searched for. If you clear your browser cache, you will lose your previous search term entry.
- Requirements subtab of the View Scope page
- Task subtab of the View Scope page
- Vendors page
- Controls page
- We’ve added the KnowBe4 Privacy Policy and Terms of Service to KCM GRC. Now, KCM GRC users will be prompted to acknowledge these policies. For more information, see our Terms of Service and Privacy Policy article.
- We’ve added a new framework to our free tool, the Compliance Audit Readiness Assessment (CARA). This new framework is the Statement on Standards for Attestation Engagements no. 18 Trust Services Criteria (SSAE 18 TSC), which you can use to assess the quality of financial reporting and system security that your organization provides.
- We've added the option to permanently delete controls in bulk. For more information, see the Deleting Controls in Bulk section of our How to Use Controls in Your KCM GRC Platform article.
- We've added the following new policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- System Integrity Policy
- Third-party Risk Management
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- Cybersecurity Maturity Model Certification (CMMC) Level 1 v1.02 to v2.0
- Cybersecurity Maturity Model Certification (CMMC) Level 2 v1.02 to v2.0
- ISO 27002 v2013 to v2022
- NY DFS Cybersecurity Requirements v2017 to v2021
- Gramm-Leach-Bliley Act Safeguard Rule v5.2002 to v12.2021
- Gramm-Leach-Bliley Act Privacy Rule v5.2002 to v12.2021
|
February 2022
|
- We've added a button that allows you to preview file evidence in your browser. For more information, see the Reviewing Evidence section of our How to Monitor and Approve Tasks article.
- We've added the following new policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- Change Management Policy
- Configuration Management Policy
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- Australian Government (ASD) Information Security Manual v4.2021 to v12.2021
- Higher Education Community Vendor Assessment Tool (HECVAT) v2.11 to v3.0
|
January 2022
|
- We've updated the following managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- Standardized Information Gathering (SIG) Lite v2021 to v2022
- Standardized Information Gathering (SIG) Core v2021 to v2022
- We've added the following new managed templates. For more information, see our Managed Templates article. To have additional templates added to your account, contact your Customer Success Manager.
- Standardized Information Gathering (SIG) Detail v2022
- We've added the following new Standardized Information Gathering (SIG) questionnaire templates for you to use when creating a questionnaire in your Vendor Risk Management module. For more information, see our How to Create and Configure Questionnaires article.
- 2022 SIG Core
- 2022 SIG Lite
- We've added our first plan template to the Policy Management module. The Incident Response Plan includes instructions for detecting, responding to, containing, and remediating security incidents that happen in your organization. For more information, see our Policy Templates article.
- We've added the following new policy templates for you to download and customize for your organization. For more information, see our Policy Templates article.
- Acceptable Use Policy
- Data Classification and Handling Policy
- System Maintenance Policy
|
Comments
0 comments
Article is closed for comments.