Product update
BlogProduct updates
September 6, 2024

New in Vanta | September 2024

Written by
Catherine Pagano
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

This month, the Vanta team launched new features to help you:

  • Scale your GRC program with a new report center, vendor risk management enhancements, 30 frameworks, and a new integrations milestone. 
  • Effortlessly create tailored SOC 2 policies with Policy Builder. 
  • Further streamline security reviews with question assignment. 
  • Speed up test remediation with a refined test details page.
  • Harness the full potential of Vanta’s API with enhanced documentation.
  • Further automate your security and compliance program with new and enhanced integrations.

Move your GRC program from point-in-time to continuous

Vanta announced several new features to move from a point-in-time GRC program to continuous in our first installment of Vanta Delivers, our quarterly release. In the event, Vanta’s Chief Product Officer, Jeremy Epling, announced product updates including:

  • Centralized, customizable, and actionable reporting that delivers comprehensive visibility into your security program. Security teams can now demonstrate the ROI of their programs with ease with reports on Compliance, Risk, Trust, Vendors, and Personnel.
  • Enhancements to our vendor risk management product that allow you to customize the inherent risk for each vendor and proactively follow-up on findings from security reviews.
  • Over 30 leading security and compliance frameworks, with customization to meet your specific needs and cross-mapping to accelerate the path to complete multiple frameworks.
  • More than 350 integrations to drive continuous monitoring across your entire security program, including expanded integrations for vulnerability management with Orca Security, SentinelOne, and CrowdStrike.

Watch an on-demand recording of Vanta Delivers. 

Simplify SOC 2 policy creation with Policy Builder 

Policy creation is a crucial step toward SOC 2 attestation, but it can be daunting for teams just starting their security journey. That’s why we’re excited to announce the general availability of Policy Builder, a dynamic policy creation and editing tool with step-by-step guidance, fill-in-the-blank prompts, and section editing guidance to help you understand required versus optional details. 

With Policy Builder, you can move through policy creation faster than ever, tailoring policy documents to your unique needs and feeling confident you're audit ready while doing so. Policy Builder is currently available for all SOC 2 policies, and additional framework policy sets will become available throughout the rest of the year.

If you’re interested in learning more about Policy Builder, schedule a demo. 

Save time on security reviews with question assignment 

Security reviews often demand collaboration across teams, and we’re now making it easier than ever to streamline the process. Question assignment now allows the primary owner of a security questionnaire to assign specific questions for other members of the team to complete and verify. Assigned members receive automatic notifications, enabling them to promptly address their tasks and keep the review on track. This efficient workflow reduces the need for multiple communication channels and significantly shortens the time required to complete a security review.

Learn more about collaboration in Questionnaire Automation.

Remediate tests faster with an updated redesigned 

We’re excited to unveil our redesigned test details page, crafted to streamline the remediation of failing tests. With a new header and organized tabs, you can quickly identify failing tests, understand the necessary steps for remediation, and close security gaps more efficiently.

Get the most out of Vanta’s API through our revamped Developer Hub

We’ve made unlocking the full capabilities of Vanta’s API simpler and more intuitive with our newly restructured Developer Hub. With additional and simplified guides to help you achieve a particular use case, we’ve streamlined the experience, allowing you to easily understand our API and find exactly what you need. Whether you're seeking to build custom integrations, automate processes or bulk actions, or query data for custom reports, our updated API documentation empowers you to fully harness the depth of Vanta's capabilities

Check out the documentation enhancements here.

Deepen security and compliance program automation with new and expanded integrations

In August, we introduced five new integrations—TalentLMS, Lacework, Torq, C/side, and Kitecyber. We also released key updates to two existing integrations, adding JQL support to the Jira integration to provide more optionality when searching for existing tickets, and expanding resource and test support in DigitalOcean. With over 350 deep and highly configurable integrations with critical vendors, Vanta leads the market in empowering teams to continuously monitor their security programs.

Explore all our integrations or tell us about any others you'd like to see.

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.