Archer offers a platform for holistic integrated risk management solutions that empower enterprise organizations to more effectively manage risk, ensure compliance, and address emerging challenges.
N/A
Secureframe
Score 9.0 out of 10
N/A
Secureframe, headquartered in San Francisco, helps companies get enterprise ready by streamlining SOC 2, ISO 27001, and HIPAA compliance. Secureframe aims to enable companies to get compliant within weeks, rather than months and monitors 40+ services, including AWS, GCP, and Azur.
N/A
Pricing
Archer Integrated Risk Management Platform
Secureframe
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Archer
Secureframe
Free Trial
No
No
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Archer Integrated Risk Management Platform
Secureframe
Features
Archer Integrated Risk Management Platform
Secureframe
Governance, Risk & Compliance
Comparison of Governance, Risk & Compliance features of Product A and Product B
Archer Integrated Risk Management Platform
9.5
13 Ratings
25% above category average
Secureframe
-
Ratings
Common repository of GRC items
8.712 Ratings
00 Ratings
Risk management
10.011 Ratings
00 Ratings
Integration with Corporate Performance Management (CPM) systems
RSA Archer is fantastic at cataloguing, personalizing assessments, raw reporting, and capacity to add custom fields. It is a little clunky around adding contextual information to notifications, peeking into data before attempting to load pages, quick navigation or determining linked (or sub-linked) relationships. These are all concerns that can either be worked around with an appropriate data scheme or with careful administration of the sub-routines.
Secureframe is well suited for repeatable compliance tasks like sharing SOC 2 documents through the Trust Center, managing vendor reviews, tracking employee training, and collecting audit evidence. It is less suited for situations that need business judgment or context outside the tool, such as deciding whether a requester is a legitimate customer, answering complex security questionnaires, or helping non-security owners interpret vendor risk questions.
Integration capabilities to multiple enterprise systems
Control standards and Procedures to address multiple regulatory/authoritative sources, standards and frameworks enabling test once satisfy many requiremnts
Rapid application development and User friendly tool with configuration capability to customize easily without user requiring programming or coding skills
Good tool to get the information communicated, approval workflow, and easy to add new findings/questionnaires. Seems to be compatible with different browsers and little downtime. Only request for improvement is to add an export feature with fewer clicks. Maybe batch export.
The Questionnaires feature (which assists in RFP's, security questionnaires, etc) could be designed a lot better. I see what they were going for, and based on their track record for improving features I'm sure it will get a refresh, but in it's current state it is the only features that I do not use.
Our RSA Archer team is dedicated to finding solutions for our organization. They haven't mentioned any issues with receiving support with deployment or bug fixes, and generally the platform is very dependable. They are always very excited about delivering a version upgrade and presenting any new features that provide more dashboards or chart types.
It has been roughly 5 years since I have seen Securevue, so a lot can change, but to me it felt like several products were purchased and an attempt was made to piece them all together into a single solution (and I believe that may have been true). It also required agents on endpoints which did not fit the model I believed customers were looking for. MetricStream appeared to be difficult to install as it took their own engineers some time to get it installed in my lab environment. I did not think their web interface was as intuitive as RSA Archer. Customization to the platform was possible to some degree, but required a lot more work and technical skills than required by Archer. I did like the landing page for MetricStream which called out the important action items for the current user, but Archer v6.X now has this feature.
From purely comparing marketing sites (unable to trial others), Secureframe had better first time SOC 2 audit documentation and explanations for free to ease you into understanding the processes.