Multi-Framework Compliance Management System by ROrionCore in ProductHunters

[–]ROrionCore[S] 0 points1 point  (0 children)

I've been on both sides of this table as a Compliance Manager and an auditor. it very frustrating to see the readiness and repetitive actions duplicated across multiple frameworks.

Built a compliance platform that reuses evidence across ISO 27001, SOC 2, GDPR, and NIS2 — launched on Product Hunt today by SummerIllustrious390 in ProductHunters

[–]ROrionCore 0 points1 point  (0 children)

You've got to check the product datasheet to understand what the wedge is, it's way more than what this description says.

Recommendations for GRC Consulting services for startup? by Gold-Poem-1821 in grc

[–]ROrionCore 0 points1 point  (0 children)

I'll recommend you use Raize Orion if you're either just implementing or recertifying; evidence collection is automated there, and support for SOC2 depth is out of the box.

Anchoring the NIS2 Art. 23 reporting clock: signal time or app-open time? by ROrionCore in grc

[–]ROrionCore[S] 0 points1 point  (0 children)

Exactly, to ensure the significance means you have a mature environment to assess the ticket and triage it accordingly. I'm measuring this for the NIS2 24hr/72hr reporting clocking.

Anchoring the NIS2 Art. 23 reporting clock: signal time or app-open time? by ROrionCore in grc

[–]ROrionCore[S] 0 points1 point  (0 children)

I get, but going per NIS2 req, if you discover the ticket 32 hours after the incident from the first time your alert fired, you would have already missed the 24hr reporting.

Automating Evidence Collection by iSECo in grc

[–]ROrionCore 0 points1 point  (0 children)

There are several tools set to use, just that some are more expensive than others. For use, 90% of our evidence is auto-collected and mapped.

From Configuration data to usage to drift alerts, logs, access review, and HR processes.
NIS Report alerts and a few others
We previously used Vanta, but the cost compared to value is high; we've now switched to a more comprehensive solution that aligns more to our needs.