Our company got ISO 27001 certified in 2019 and our ISMS was managed through Google docs, spreadsheets, and some of it in Atlassian products. This worked fine but was not much scalable nor did we have a single source of truth to refer to. In addition, we started to prepare for a SOC 2 certification in 2021 and now wanted to map our controls against multiple compliance frameworks. We reviewed several tools mentioned in the 2020 Gartner report for GRC products and narrowed down to ZenGRC for several reasons: It's nimble and faster to adopt than products, and yet strikes a good balance between simplicity and feature coverage. As a SaaS platform, we see ZenGRC growing with us as we progress our compliance programs.
Onboarding experience:
This process was a very pleasant experience with a set of scheduled video calls and hands-on training on the product. There was plenty of time for open questions and in some sessions, a Reciprocity GRC expert joined to answer specific questions on frameworks and how to apply them in the tool. This added a lot of value.
In addition to the onboarding sessions, we got access to the Zen University, an e-learning platform with video courses covering all areas of the product. The course modules are easy to follow tutorials that encourage to use the product while watching to get the most out of it. These courses were a great way to prepare each onboarding video call and note questions.
We also have access to ZenGRC's online documentation which covered all our needs so far. There are tutorials on features and also tips and tricks on how to utilise the product most effectively.
Access to GRC experts:
As mentioned above in the onboarding experience, having access to GRC experts when we are stuck with a certain question adds a lot of value to the services provided. We not only have access to a platform to manage our compliance programs but can also resolve roadblocks through expert advice as.
Data import:
As with all GRC products, data import is an important aspect and the CSV import functionality ZenGRC offers works really well. I was able to pick it up within a very short time and important most of our data already during our onboarding phase. The importer supports copy & paste from a spreadsheet, import of a spreadsheet directly and has useful validation to avoid importing incorrect data.
Ideas portal:
After onboarding, we have been pointed to an ideas portal where Reciprocity customers can vote on existing product ideas submitted by other customers or submit their own. It's really useful to see what features other customers requested and upvote what's of most value for our organization. Análise coletada por e hospedada no G2.com.
If you come from a very mature Google world, then ZenGRC's interfaces look a little basic in some areas. However, this doesn't really affect functionality or effectivity of the product.
The dashboard functionality served us well for now but could add a little more customizability. That being said, there have been improvements since we have adopted ZenGRC and there are more improvements on the roadmap. Also, we use Tableau and the native integration would solve all our needs for reporting should we ever need more.
The list view navigation and search sometimes require more clicks than necessary depending on what you are looking for. This has been raised in the ideas portal already and improvements are in the works. Análise coletada por e hospedada no G2.com.
Sendo mais novo no uso de uma ferramenta GRC, o que mais me atraiu no ZenGRC foi a funcionalidade e a capacidade de gerenciamento em comparação com os outros participantes nesse espaço. "Botão fácil" Análise coletada por e hospedada no G2.com.
Não há desvantagens no ZenGRC do meu ponto de vista, no entanto, tivemos dificuldades em saber por onde começar no uso da ferramenta. Simplesmente utilizamos um especialista de terceiros para ajudar. Análise coletada por e hospedada no G2.com.
Eu gosto do seguinte:
1. Upload em massa de Auditorias
2. Mudança de propriedade para as tarefas em massa
3. Capacidade de filtrar de várias maneiras para rastrear a Auditoria exata
4. Rastreamento de auditoria de ponta a ponta Análise coletada por e hospedada no G2.com.
Eu não diria que gosto do seguinte:
1. Não há opção que mostre a data de vencimento para as tarefas
2. Além disso, sempre que mudo o proprietário/responsável pela tarefa principal, isso não se reflete nas subtarefas, e preciso atualizar manualmente toda vez
3. Todas as tarefas futuras estão aparecendo na lista de ações a fazer
4. Tarefas principais não deveriam aparecer na lista de ações a fazer, já que são a tarefa principal para a criação automática de subtarefas
5. A visualização do painel não é boa
6. Os sistemas do sistema estão sendo limpos sempre que faço login novamente
7. Mesmo se eu compartilhar o acesso de leitura, o usuário pode editar as tarefas
8. O responsável pode mudar ao longo do tempo, e mesmo que a solicitação principal seja atualizada, isso não se reflete nas solicitações recorrentes que dela derivam
9. Às vezes, a recorrência é pulada. Em outras palavras, às vezes um mês é pulado
10. Não conseguimos duplicar uma solicitação automaticamente sem recorrência e um processo manual Análise coletada por e hospedada no G2.com.
The tool is easy to navigate in and has a lot of flexibility to add custom attributes to each of the data types, particularly when using it as a system of record for compliance-related activities. The company is also really receptive to feedback as far as its features - they've incorporated a lot of the feedback provided. Análise coletada por e hospedada no G2.com.
There are some features that aren't super robust - like role-based access controls, uploading multiple files to a record in bulk, and the general setup of the Jira integration. Análise coletada por e hospedada no G2.com.
ZenGRC is a great tool to manage our complete audit cycle end to end, from automating a request to collect evidence on a defined frequency and closing them with the validation. It can be integrated with many audit frameworks. It creates an easy job in tracking and aligning the collected data in a structured way. It reduces a lot of manual work on tracking things. The tool is very much user-friendly. The support team's response to add features or resolve issues is applauded. Análise coletada por e hospedada no G2.com.
It would have been wonderful if the licensing is related to the number of users, as we face these issues as our Organization is on tremendous growth now, and we have to onboard several users to the tool. We may also need some more features added to the iterations of the created tasks. Also it would be good if the tools allows some more ways of customization that can be allowed on the taks that are being created. It would be good to have a free trail initially to have a feel on the tool before having user subscriptions Análise coletada por e hospedada no G2.com.
Acho mais útil como reduziu os esforços manuais e cria um processo mais fácil para as pessoas que usam esta ferramenta para trabalhos relacionados a negócios. Análise coletada por e hospedada no G2.com.
Eu não gosto de como ele integra aplicativos de terceiros. Isso torna o software mais lento e nem sempre é preciso. Análise coletada por e hospedada no G2.com.
ZenGRC's training and educational content under the knowledge base make it easy to stand up the platform yourself with minimal support. ZenGRC allows for a common approach to risk management across the enterprise and can be used by all business units. ZenGRC also enables a holistic view of how compliance status, program maturity, audit results, and vendors affect the overall risk score of the organization. This solution is easy to use, easy to stand up, and scalable as your organization grows. ZenGRC also offers excellent support. Análise coletada por e hospedada no G2.com.
A more robust API integration with Jira would be beneficial. Vendor review requests submitted through Jira contain information that needs to be then re-entered into the GRC tool. I would prefer that this information already required for the ticket would be able to feed into the GRC tool without manual re-entry by the risk analyst. Análise coletada por e hospedada no G2.com.
Fairly easy to navigate with sidebar menu.
Many options of things to record (audits, issues, etc.)
User access easily integrated into our single sign on capability. Análise coletada por e hospedada no G2.com.
Could do better withthe side bar menu as not all options are listed and it's a roundabout process to get to some of the options.
Also navigation from one screen or page to another often entails going back to the beginning.
Search functionality could be improved - not always easy to find information within a recorded item.
Could do with having more fields when recording an issue/risk, to include more for action plans/due dates/owners and details for example.
Some of the above might simply be because I am farily new at using it. AS I get more familiar, they might become easier. Análise coletada por e hospedada no G2.com.
ZenGRC nos dá a capacidade de usar os vários aspectos de uma ferramenta GRC. Não restringe com base em módulos, o que nos ajuda a implementar todos os módulos da maneira que funciona melhor para a organização. Os módulos proporcionam facilidade de personalizar os campos que queremos capturar e como queremos importar ou exportar dados em massa. Além disso, o mapeamento de controles usando SCF é benéfico para vincular vários padrões com um conjunto comum de controles.
Também adorei a equipe dedicada que foi capaz de responder a todas as nossas perguntas durante as fases de demonstração e POC. Os especialistas do produto conhecem o produto e realmente adorei que estavam trabalhando continuamente para melhorar a funcionalidade da ferramenta. Análise coletada por e hospedada no G2.com.
A interface do usuário atual pode ser melhorada. Os extratos do relatório e a aparência de uma visão precisam ser melhorados. No momento, a plataforma tem muitas abas sob o mesmo controle / risco / questões... é altamente benéfico se tudo isso puder ser trazido para uma aparência de uma visão. A plataforma não permite que o acesso do usuário seja restrito por módulo. Por exemplo: o proprietário do controle com acesso de editor pode até editar políticas e riscos, o que não é uma ótima maneira de implementar a segregação de funções. Precisamos de acesso baseado em funções em toda a plataforma. Análise coletada por e hospedada no G2.com.