49 Reviews and Ratings
8 Reviews and Ratings
No answers on this topic
RSA Archer is fantastic at cataloguing, personalizing assessments, raw reporting, and capacity to add custom fields. It is a little clunky around adding contextual information to notifications, peeking into data before attempting to load pages, quick navigation or determining linked (or sub-linked) relationships. These are all concerns that can either be worked around with an appropriate data scheme or with careful administration of the sub-routines.Incentivized
If you are considering BitSight Security Ratings as a portion or bulk of a larger vendor management project you will be well served in letting the risk scores be an indication of how closely you need to examine a vendor. However, you should not base your assessment solely on the risk score provided. The risk score is based on publicly available data and can be inaccurate.Incentivized
Integration capabilities to multiple enterprise systemsControl standards and Procedures to address multiple regulatory/authoritative sources, standards and frameworks enabling test once satisfy many requiremntsRapid application development and User friendly tool with configuration capability to customize easily without user requiring programming or coding skills
Security hygiene tracking over timeUnderstandable risk score based on observationsPredictability model of potential cyber security issues based on security habits.Incentivized
They release time to time updates, which causes issues in the GUI. However, one has to be careful while installing the update.There is no open and free academy to learn more about the tool.One cannot stay to a particular product version, they have to move to the next version to keep up with the changes.Incentivized
Since data is based on public registration IP and domain data can be stale depending on ISP/Domain registration update delays.Correcting a false detection is a month-long endeavor and requires the company with the impacted score to clean up BitSight's data.Customer service for incorrect data is convoluted and requires a deep understanding of domain registration to correct the data. The responsibility for correcting data is placed solely on the customer's shoulders.Incentivized
Good tool to get the information communicated, approval workflow, and easy to add new findings/questionnaires. Seems to be compatible with different browsers and little downtime. Only request for improvement is to add an export feature with fewer clicks. Maybe batch export.Incentivized
Our RSA Archer team is dedicated to finding solutions for our organization. They haven't mentioned any issues with receiving support with deployment or bug fixes, and generally the platform is very dependable. They are always very excited about delivering a version upgrade and presenting any new features that provide more dashboards or chart types.Incentivized
It has been roughly 5 years since I have seen Securevue, so a lot can change, but to me it felt like several products were purchased and an attempt was made to piece them all together into a single solution (and I believe that may have been true). It also required agents on endpoints which did not fit the model I believed customers were looking for. MetricStream appeared to be difficult to install as it took their own engineers some time to get it installed in my lab environment. I did not think their web interface was as intuitive as RSA Archer. Customization to the platform was possible to some degree, but required a lot more work and technical skills than required by Archer. I did like the landing page for MetricStream which called out the important action items for the current user, but Archer v6.X now has this feature.Incentivized
BitSight Security Ratings ranks evenly with SecurityScorecard and both below OneTrust for our use case. We needed a platform that would let us define risk for our organization and weight scores differently based on data sensitivity. BitSight and SecurityScorecard are aggregate data that can provide insight into the security habits of a potential vendor and should be considered as an addition to most vendor management projects. However, they both provide metrics based on hygiene and not on data-defined risk. In concert with a platform to evaluate risk based on data and to inform the overall evaluation of a vendor, BitSight Security Ratings can be made to shine. Just understand that you may have to validate some data.Incentivized
We were able to achieve approx 63% gain in operational efficiency.Reduce the number of findings and exceptions during an Internal audit to almost zero.Get compliance to all client contracts tracked through the tool thus increasing the confidence of clients in our systems and processes.Incentivized
Wasted resource hours cleaning up data to correct erroneous risk score.Extra time spent addressing calls from clients about erroneous risk score data.Extra time validating risk score provided by BitSight Security Ratings for potential vendors to ensure valid data.Incentivized