Product update with Ilma the llama.
BlogProduct updates
August 12, 2024

New in Vanta | August 2024

Written by
Lauren Wade
Product Marketing
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

This month, the Vanta team launched new functionalities to help you:

  • Automatically improve your security posture.
  • Automate questionnaires across multi-product organizations with customization.
  • Save time by reusing evidence from past security reviews within Vendor Risk Management.
  • Track vulnerability compliance in Vanta with new integrations to Gitlab and SentinelOne.
  • Establish a shared understanding with your auditor.

Automatically improve your security posture

Vanta announced several new features to align your program to security best practices with a new CIS Critical Security Controls® v8.1 framework. Secure and monitor your public cloud with new automated tests aligned to the CIS Foundation Benchmarks™ for AWS, Azure, and GCP, and implement advanced security workflows with enhanced Vanta API capabilities.

Check out the video below for a walk-through of our security posture enhancements.

<iframe src="https://player.vimeo.com/video/992294630?h=40076e4a56" width="640" height="360" frameborder="0" allow="autoplay; fullscreen; picture-in-picture" allowfullscreen></iframe>

Read more about these new capabilities in our blog.

Automate questionnaires across multi-product organizations with customization 

When it comes to completing customers’ security questionnaires, organizations with multiple product lines need a way to tailor responses by product. For instance, a set of organizational policies may apply across the whole product line, while the SOC 2 framework is only relevant to a specific product. When done manually, this matrix of information can quickly become unmanageable for security and compliance teams, slowing down questionnaire responses and their sales process. 

Vanta’s Questionnaire Automation product helps organizations complete security reviews up to five times faster. And with the introduction of multi-product tagging of your answer library and resources in Vanta, organizations can now apply the same time saving automations for all of their products with helpful customization.

Resources and question-answer pairs in the knowledge base can be configured to one, multiple, or all products. So when a security questionnaire comes in for a specific product, compliance teams can automate responses, pulling in only the information relevant to that product—nothing more, nothing less. 

Tune in to our upcoming webinar on Questionnaire Automation to learn more.

Save time on security reviews by reusing evidence from past vendor questionnaires 

The most time-consuming aspect of a security review is gathering evidence from the vendor. It can take months to gather all of the necessary documents, and when it comes time to renew or follow up assessment, those previously collected documents are key to saving time.

Now, within Vanta Vendor Risk Management, you can easily import evidence from past security reviews into a new security review, right within Vanta.

If you’re interested in learning more about Vanta’s Vendor Risk Management, schedule a demo. 

Track vulnerability compliance in Vanta with new and improved integrations to Gitlab and SentinelOne

Monitoring for vulnerability management compliance against SLAs and assigning tasks to resolve exceptions is an important requirement for GRC teams. We’re excited to announce two new and enhanced integrations to help centralize this work right within Vanta. 

The existing Gitlab integration was expanded to support pulling vulnerabilities into Vanta. Our new integration with SentinelOne supports ingesting vulnerabilities as well. Both of these enhancements are currently available in beta, and will be generally available soon!

And, you can now find integrations with Pentest-Tools (Document Upload) and 13 Security (Access

Document upload, and Vulnerabilities).

See all of our integrations or let us know about additional ones you need.

Establish a shared understanding with your auditor

Audits are essential to your security program and maintaining clarity on the status of your audit helps you operate at peak efficiency. Vanta now features more granular evidence statuses to clearly show the state of evidence. These new statuses make it easier to collaborate and track status with your auditor.

These new statuses are available now for all customers.

Test it for yourself

Log in to your Vanta account to try out these new features if they are a part of your plan. If you’re not a Vanta customer and want to learn more, request a demo.

As always, we welcome your feedback. Let us know what you think by reaching out to your Customer Success Manager and stay in the loop on Vanta news on LinkedIn.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.