ZenGRC

ZenGRC

von RECIPROCITY

Wer verwendet ZenGRC?

Wir unterstützen Informationssicherheits- und Compliance-Teams, die ihre Compliance-Anforderungen besser verwalten möchten. Zielindustrien umfassen Tech, Einzelhandel, Versorgungsunternehmen, Konsumgüter, Gesundheitswesen und Finanzen.

Was ist ZenGRC?

ZenGRC, wird von Unternehmen wie Walmart, Airbnb und Alaska Airlines geschätzt. Kunden, die ZenGRC nutzen, profitieren von Effizienzgewinnen und reduzieren die Zeit und die Kosten für die IT-Prüfung. Mit ZenGRC können Sie sicher sein, dass Ihr Unternehmen Zeit und Geld bei der Prüfung und Verwaltung von Risiken spart, um SOC, PCI, ISO, HIPAA, DSGVO, NIST, COSO und andere Vorschriften zu erfüllen. Holen Sie sich heute eine kostenlose Demo!

ZenGRC – Details

RECIPROCITY

https://reciprocitylabs.com/

Gegründet 2009

ZenGRC – Kostenübersicht

ZenGRC bietet keine Gratisversion und keine kostenlose Testversion.

Kostenlose Version

Nein

Gratis Testen

Nein

Einsatz

Cloud, SaaS, Web

Training

Persönlich

Live Online

Webinare

Dokumentation

Kundenbetreuung

Support während der Geschäftszeiten

Online

ZenGRC Funktionen

Audit Software
Alarmfunktion / Benachrichtigungen
Auditplanung
Aufgabenmanagement
Compliance Management
Dashboard
Formularverwaltung
Mobiler Zugriff
Problemmanagement
Risikobewertung
Verfolgen von Vermögensanlagen
Workflow-Management
Archivierung & Aufbewahrung
Compliance-Verfolgung
Einhaltung von Umweltvorschriften
FDA-Compliance
HIPAA konform
ISO-Compliance
OSHA-Compliance
Prozess-/Workflow-Automatisierung
Risikomanagement
Sardanes-Oxley-Compliance
Störfallmanagement
Testen von Steuerelementen
Umfragen & Feedback
Versionskontrolle
Wirtschaftsprüfung-Management
Data Mapping
Erkennung sensibler Daten
PIA / DPIA
Richtlinien Managemen-
Risikomanagement
Störfallmanagement
Zugriffskontrolle
Zustimmungs-Management
Betriebsrisiko-Management
Disaster Recovery
Einhaltung von Umweltvorschriften
IT-Risikomanagement
Internes Kontrollmanagement
Richtlinien Managemen-
Störfallmanagement
Wirtschaftsprüfung

Der Softwareanbieter hat diese Information nicht vervollständigt.

Compliance Berichterstattung
Dateiintegritätsüberwachung
Erkennungssystem für unberechtigte Eingriffe
Korrektur-Management
Log-Management
Management by Exception
PCI-Bewertung
Richtlinien Managemen-
Zugriffskontrolle
Alarmfunktion / Benachrichtigungen
Betriebsrisiko-Management
Compliance Management
Corrective and Preventive Action (CAPA)
Geschäftsprozess-Steuerung
IT-Risikomanagement
Internes Kontrollmanagement
Management by Exception
Mobiler Zugriff
Prädiktive Analytik
Reaktions-Management
Rechtliches Risikomanagement
Reputationsrisikomanagement
Risikobewertung
Wirtschaftsprüfung
Betriebsrisiko-Management
Compliance Management
Dashboard
Disaster Recovery
IT-Risikomanagement
Lieferanten-Management
Risikobewertung
Sicherheitsmanagement
Störfallmanagement
Wirtschaftsprüfung-Management

Der Softwareanbieter hat diese Information nicht vervollständigt.

ZenGRC – Nutzerbewertungen

Zeigt 5 von 19 Nutzerbewertungen

Gesamt
4,5/5
Benutzerfreundlichkeit
4,7/5
Kundenservice
4,8/5
Funktionen
4,4/5
Preis-Leistungs-Verhältnis
4,6/5
Andrew W.
Manager, IT Controls
Computer-Software, 1.001-5.000 Mitarbeiter
Verwendete die Software für: 1-5 Monate
  • Gesamtbewertung
    5/5
  • Benutzerfreundlichkeit
    5/5
  • Eigenschaften & Funktionalitäten
    4/5
  • Kundenbetreuung
    5/5
  • Preis-Leistungs-Verhältnis
    5/5
  • Wahrscheinlichkeit der Weiterempfehlung
    10/10
  • Quelle des Nutzers 
  • Bewertet am 21.5.2018

"Logical and minimal approach to GRC saves time!"

Kommentare: One of the biggest benefits that has made a huge impact is the time savings we've achieved in our IT Security group by using ZenGRC. Our old email/spreadsheet process would be a multi-week process, cause confusion every audit and often get us lost in the weeds of details when we needed to be focusing on the auditors. The first audit we ran through ZenGRC saved us literally a full week of time that would have been dedicated to reviewing evidence submission via email and spreadsheets. Having ZenGRC in place allowed us to put multiple review points in place BEFORE the evidence came to our group for review practically eliminating the requirement of follow-up request corrections.

Vorteile: ZenGRC brings all the tools you need to run a successful GRC program to the table in a clear, concise and minimalist package that's nimble and efficient. Our company had been utilizing the old method of email/spreadsheets and was getting lost in the weeds even on the smallest of audits and struggling to keep up each year to stay ahead. Our evaluations with other tools fell flat, didn't meet our requirements or introduced complexity. Our evaluation of ZenGRC started with skepticism, but quickly turned positive once we realized how logically organized the system was on the back-end. During our testing period, we were able to quickly create a Sarbanes-Oxley program, using both their template import and the GUI, in a matter of days. Since that time only a few short weeks ago we have now almost completed a full internal audit of our SOX program, complete with evidence collection and control evaluations. Our rough estimate has us gaining back a full week of time from previous audits last year and year prior using the old email/spreadsheet method. We are now rolling out an ISO27001, SOC2 and internal security control framework on the heels of the SOX success.

Nachteile: As with any SaaS from a small company that is new to market (less than 5 years), there are aspects of the tool that require some creative thinking and clever workarounds. This is not necessarily a dislike in my opinion, however less technical individuals may find this aspect difficult or troublesome. ZenGRC staff do redeem themselves on this front as they're quick to respond to feature requests and have already implemented several suggestions our team has submitted. Since starting to use the product, they have continually updated the product with new features, fixes and updates to existing functionality.

  • Quelle des Nutzers 
  • Bewertet am 21.5.2018
Steven B.
IT Security Analyst
Versicherung, 5.001-10.000 Mitarbeiter
Verwendete die Software für: Mehr als 1 Jahr
  • Gesamtbewertung
    5/5
  • Benutzerfreundlichkeit
    5/5
  • Eigenschaften & Funktionalitäten
    5/5
  • Kundenbetreuung
    5/5
  • Preis-Leistungs-Verhältnis
    5/5
  • Wahrscheinlichkeit der Weiterempfehlung
    10/10
  • Quelle des Nutzers 
  • Bewertet am 8.11.2019

"Powerful, extensible, and easy to use software. Excellent support and product roadmap."

Kommentare: We're facilitating internal audits with ZenGRC, and the software does a great job of it.

Vorteile: The ZenGRC solution streamlines conducting internal audits. Auditors can easily set up control frameworks (tons of templates are provided, which is very helpful), evidence requests, assign them to auditees, and review the evidence submitted. Auditees can easily provide feedback, ask questions, and submit evidence for review. The workflows ZenGRC supports are both incredibly accessible and very powerful. ZenGRC actively listens to customers and has actually incorporated a number of suggestions I (and other customers) have made. I'm excited to see what they'll develop in the future.

Nachteile: The ZenGRC solution is fantastic, and all the complaints I had 1.5 years ago have been resolved, and my expectations exceeded. I wish the vendor/third party management module was receiving more attention, sooner, but the roadmap for its development has been conveyed to me, and I understand the timing. I wish there was a licensing model which was not tied to user counts, which would enable us to do even more with the product.

  • Quelle des Nutzers 
  • Bewertet am 8.11.2019
Pramod A.
IT-Security Analyst II
Finanzdienstleistungen, 1.001-5.000 Mitarbeiter
Verwendete die Software für: 6-12 Monate
  • Gesamtbewertung
    3/5
  • Benutzerfreundlichkeit
    5/5
  • Eigenschaften & Funktionalitäten
    3/5
  • Kundenbetreuung
    4/5
  • Preis-Leistungs-Verhältnis
    4/5
  • Wahrscheinlichkeit der Weiterempfehlung
    7/10
  • Quelle des Nutzers 
  • Bewertet am 12.9.2017

"ZenGRC is a great workflow tool from starting a request to collect evidences and close out request."

Kommentare: ZenGRC is a great tool for managing different audits. I love the workflow from starting multiple requests to collecting and accepting evidences. It is reducing the manual effort of tracking requests in excel file. The audit report matrix gives a solid picture for management to track and find the status of the active audit.

Nachteile: The tool needs some enhancements and bug fix to add value to the customers and be user friendly. We are actively using the tool to manage our PCI audit. There are some features that needs to be added to save time during evidence collection and verifying process. I do not think the ZenGRC has met their SLA for customer support. I hope they work on redefining their SLA for their customer.

  • Quelle des Nutzers 
  • Bewertet am 12.9.2017
Dave A.
Director of Security & IT
Computer-Software, 201-500 Mitarbeiter
Verwendete die Software für: Mehr als 2 Jahre
  • Gesamtbewertung
    5/5
  • Benutzerfreundlichkeit
    5/5
  • Eigenschaften & Funktionalitäten
    5/5
  • Kundenbetreuung
    5/5
  • Preis-Leistungs-Verhältnis
    5/5
  • Wahrscheinlichkeit der Weiterempfehlung
    10/10
  • Quelle des Nutzers 
  • Bewertet am 22.9.2017

"ZenGRC is a major part of our successful compliance programs"

Kommentare: Because it's so well organized we've managed to keep the required staff to manage compliance at a minimum.

Vorteile: I have been using ZenGRC for over two years now and it has been an essential tool helping us get and stay organized when we embarked on gaining a SOC 2 attestation. We have since been through two SOC 2 audits and are using ZenGRC to help us assess and remediate our gaps against ISO 27001.

Nachteile: There's still a some things you have to edit by exporting to CSV, editing in your favorite spreadsheet app, then re-importing, so it would be nice if some of that functionality was built into the UI. That being said, that workflow is actually ideal for some tasks. Our last audit firm wasn't able to use the app directly for requesting and managing audit evidence so there was a bit of duplication of effort. The ZenGRC team is making some changes to make that better though.

  • Quelle des Nutzers 
  • Bewertet am 22.9.2017
Travis R.
CISO
Computer-Software, 13-50 Mitarbeiter
Verwendete die Software für: Mehr als 1 Jahr
  • Gesamtbewertung
    5/5
  • Benutzerfreundlichkeit
    5/5
  • Eigenschaften & Funktionalitäten
    4/5
  • Kundenbetreuung
    5/5
  • Preis-Leistungs-Verhältnis
    5/5
  • Wahrscheinlichkeit der Weiterempfehlung
    10/10
  • Quelle des Nutzers 
  • Bewertet am 10.11.2017

"ZenGRC Delivers Compliance and Automation"

Kommentare: The immediate benefits are streamlining of processes and simplification of evidence collection. What used to be a multi-step JIRA project with a manual review, then publishing to a separate project where our auditors could view the evidence, is now a simple workflow. This is a huge timesaver and makes the audit process as painless as possible.

Vorteile: Simple, easy to use, despite managing complex workflows and multiple audits across ,multiple teams. Easy to import specific controls and modify existing control sets to meet our needs as necessary. Audit readiness dashboard is critical as you prepare for new compliance initiatives or are questioned on "how difficult" it would be to be to become compliant with a specific regulation or framework to close a deal.

Nachteile: The JIRA integration is improving in significant ways, however the complexity and manner with which we implemented JIRA makes an effective integration difficult and as a result the immediate integration is not as useful as we would like to see. That being said, the two-way sync has made a dramatic improvements, and for most customers, the existing integration is likely more than sufficient.

  • Quelle des Nutzers 
  • Bewertet am 10.11.2017