Solutions

GRC platform

Governance, risk, and compliance stay useful when the policy, the risk score, and the vendor file point at the same control. SecBoard keeps those records together.

Governance and compliance

The compliance module holds framework instances, local regulatory requirements, and internal policies. Mandatory processes have reminders and a confirmation that the step was executed. Documents keep policies and procedures with versioning and approval.

Risk, vendors, and personal data

Risk assessment calculates a level from threats, vulnerabilities, and assets, then records the response. TPRM keeps the vendor registry, assessments, documents, and questionnaires, including a link the vendor can fill in. GDPR support keeps data subjects, consents, the record of processing, requests, retention, DPIA, and breach records.

Questions

No. Compliance, risk, TPRM, documents, and GDPR support are modules of SecBoard.

The compliance module includes PCI DSS, ISO 27001, SOC 2, HIPAA, GDPR, and internal policies. The standards catalog adds the PCI DSS and ISO/IEC 27002 control text.

Yes. TPRM has questionnaire templates, conditional questions, and an external link for the vendor.

On the open-source ISMS page and on the pricing page: Community Edition, AGPL v3, self-hosted.

Related