Share this article

Introducing new Vanta capabilities to automatically improve your security posture
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
From day one, Vanta has helped security teams build and maintain a strong security posture to protect sensitive data and reduce business risk. Our industry-leading trust management platform provides automated, continuous compliance, ensuring that the necessary people, processes, and technology for strong security are in place and working effectively.
With Vanta, customers like Unleash and Pigment are able to reduce costs and free up resources for strategic security initiatives. By automating manual tasks, Vanta gives security teams more time to focus on high-impact work. And as an integrated platform, Vanta enables tool consolidation and breaks down data silos while providing a unified view of compliance and risk.
To make it even easier to automatically improve your security posture, today we’re excited to announce new capabilities, including a framework for the CIS Critical Security Controls® 8.1, automated tests aligned to the CIS Foundation Benchmarks, and enhancements to the Vanta API. Check out the video below for a walk-through of these enhancements and read on to learn more.
<div style="padding:56.25% 0 0 0;position:relative;"><iframe src="https://player.vimeo.com/video/992294630?h=40076e4a56" style="position:absolute;top:0;left:0;width:100%;height:100%;" frameborder="0" allow="autoplay; fullscreen; picture-in-picture" allowfullscreen></iframe></div><script src="https://player.vimeo.com/api/player.js"></script>
Align to security best practices with the CIS Critical Security Controls®
Vanta now offers a pre-built framework aligned to the CIS Critical Security Controls v8.1, (or the CIS Controls®) to help you implement and maintain cybersecurity best practices automatically.
Developed by the CIS community of leading cybersecurity practitioners, the CIS Controls are the industry standard for improving your cybersecurity posture and provide a prioritized and focused approach to implementing security measures. The Controls include three Implementation Groups (IGs): IG 1 is for smaller or low-security organizations, IG 2 is for medium-sized and more mature organizations, and IG 3 is for large organizations with high security maturity.
Before, implementing and measuring the effectiveness of the CIS Controls was a manual and time-consuming process, resulting in duplicate work with other frameworks. With Vanta’s automated tests of technical controls, this process becomes very efficient. Additionally, you only need to do the work once and Vanta will apply it to multiple frameworks to minimize duplicate work. In fact, implementing the CIS Controls brings you over 60% of the way to SOC 2 or ISO 27001.
Now generally available in Vanta, our CIS Controls framework comes with over 150 controls covering 18 different cybersecurity categories, 170 tests, and 90 documents. When implementing the CIS Controls with Vanta, you can start with one of the three Implementation Groups and can optionally upgrade to another IG at no additional cost as your needs evolve.
Secure and monitor your public cloud with new automated tests aligned to the CIS Foundation Benchmarks™
Coming soon, Vanta will release new, pre-built automated tests aligned to the CIS Foundation Benchmarks to ensure a secure and compliant public cloud environment. The CIS Benchmarks are key for any organization with sensitive data stored in a public cloud.
As with all Vanta automated tests, these new tests run continuously. If a configuration falls out of compliance, Vanta sends notifications and provides remediation steps so you can resolve the issue quickly and maintain continuous security and compliance.
The new tests aligned to the CIS Foundation Benchmarks will be generally available for AWS with over 35 new or enhanced tests in the coming months and for Google Cloud Platform and Microsoft Azure later this year. They will be offered in the Collaborate and Scale packages.
Implement advanced security workflows with enhanced Vanta API capabilities
Earlier this year, we announced a new REST API to extend the power of Vanta and better integrate our data with other systems. Since then, we’ve added new functionality to the Vanta API with over 35 new endpoints. These can drive custom, automated workflows using third-party tools to quickly close security gaps, reduce risk, and eliminate human error. While the possibilities for API-driven automated workflows are essentially unlimited, here are two examples:
Automatically remediate failed Vanta tests
Let’s say your public cloud has a firewall port that is inappropriately exposed to the public, and a Vanta test checking for secure firewall configurations fails. A third-party product or script querying the Vanta API endpoint on a recurring basis for failed tests sees this and then automatically takes the specific steps to close the offending firewall port. This sort of automated remediation quickly closes gaps that a threat could otherwise exploit and streamlines the process for your security team.
Automatically verify employee compliance before they can perform sensitive actions
Let’s say a technical team member wants to obtain access to your development environment through your access management system. With the Vanta API, the access management solution can first check Vanta to verify the employee has met compliance requirements— including passing a background check, reading and accepting security policies, completing security training, and ensuring device monitoring software is on their endpoint—before access is granted in real time. If an employee falls out of compliance, access is immediately revoked, and any existing connections are terminated. This helps ensure only vetted and security-educated employees are working with sensitive data.
You can implement this workflow today with Border0, a next-generation access management provider, which has built an integration with Vanta. Learn more about the integration on the Border0 blog or watch this video.
The Vanta API is available to all current customers. Learn more about the Vanta API here or check out our developer docs.
Improve your security posture with Vanta
These new capabilities help you automatically improve your security posture, reduce risk, and streamline your security operations. If you’re interested in learning more about them, reach out to your account executive or customer success manager, or contact us here. And if you're attending the Black Hat USA conference in Las Vegas next week, drop by booth #2618 to meet the Vanta team.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.