SimpleRisk
simplerisk.comBuild Difficulty: 4/5
A few focused days to build a solid replacement
From Zero to GRC in Minutes
How to Replace SimpleRiskOverview
Features
37 features across 13 categories
AI(1)
Enhanced risk analysis including FAIR assessments and customized documentation generation
Administration(5)
Log and keep audit trails of all system changes for review by system administrators
Configure risk management process tailored to organization, change dropdown values, edit risk formulas, manage risk catalog, and define unlimited users with role mapping
Add and remove different types of fields and dynamically create custom page templates
Define multiple Business Units with teams, assign users across teams and Business Units, restrict user viewing to assigned teams and assets
One-click database backup and application/database upgrade capability
Asset Management(3)
Logically group assets together and associate them with risks
Basic automated discovery of assets with manual addition capability, valuation assignment, and association with teams and locations
Integrate with Tenable.io, Rapid7 Nexpose/InsightVM and Qualys to import asset and vulnerability data, triage vulnerabilities into risks
Compliance(5)
Maintain a record of past audit activities and evidence with access restrictions based on need to know
Initiate, track and manage audits at the framework, control, or test level with documentation and evidence tracking
Create a consistent, repeatable, scalable process for recurring audits, assessments and certifications
Define unlimited tests across frameworks and controls with test result tracking and application to multiple frameworks
Take pre-configured risk assessments for CIS Critical Security Controls, HIPAA, NIST 800-171, or PCI DSS 3.2 with yes/no questions
Data Management(1)
Import data into SimpleRisk by mapping CSV file fields, and export CSV files containing risks, mitigations, reviews, or combination reports
Governance(3)
Track and manage risk exceptions to policies and controls with approval workflows
Store policies, guidelines, standards and procedures in a single repository with documentation upload capabilities
Integration with 250+ regulatory frameworks mapped to more than 1,250 common controls
Incident Management(1)
Identify, respond to and recover from events that negatively impact the organization based on NIST 800-61 Computer Security Incident Handling Guide
Integration(4)
Bi-directional integration with Jira instances to connect risks to issues and sync data, status and comments
RESTful API to create scripted interactions with other applications for advanced automation and existing infrastructure leverage
Direct integration between Secure Controls Framework allowing selection from 190 frameworks mapped to 1,057 security and privacy controls including ISO 27001, NIST CSF, PCI DSS, GDPR, COBIT, COSO
API-level integration with Unified Compliance Framework to import frameworks and control mappings directly
Notification(1)
Send email notifications when risks are submitted, modified, or actioned upon, with scheduled reminders for management reviews
Reporting(2)
Create custom reports with graphical dashboards, risk appetite analysis, remediation prioritization, risk-to-control associations, and risk-to-asset associations
Filter data and tailor reports for C-Level, Technical, and Business stakeholders
Risk Management(7)
Auto-generate risk assessments and maturity questionnaires for 250+ frameworks and track results
Involve management in the risk management process by outlining next steps for risks with review process tracking
Plan mitigations for risks by setting mitigation dates, defining level of effort, assigning ownership, and tracking residual risk changes
Group risks together into higher level projects for batch management and reporting purposes
Ability to define contacts, create questions with logic, assemble questionnaires, and compare results over time
Identify and prioritize high level risks most likely to impact your organization
Submit, track and maintain a comprehensive registry of all organizational risks
Search(1)
Expand search functionality to find risks by textual search in risk data
Security(3)
Support for Active Directory and SAML authentication
AES-256 bit encryption key generation and encryption of sensitive text data in the database
Restrict risk viewing to only users who are members of the team that the risk is assigned to
Pricing
SimpleRisk Core
- ✓Unlimited Users
- ✓Basic Governance
- ✓Risk Registry
- ✓Basic Compliance
- ✓Asset Management
- ✓Self-Assessments
- ✓Reporting
- ✓Configuration
Starter Package
Popular- ✓Any three Standard Extras
- ✓Support
- ✓Hosting (optional)
Standard Extras
- ✓Advanced Search
- ✓API
- ✓Artificial Intelligence
- ✓Custom Authentication
- ✓Customization
- ✓Email Notification
- ✓Encrypted Database
- ✓Import-Export
- ✓Jira Integration
- ✓Risk Assessment
- ✓Team-Based Separation
- ✓Unified Compliance Framework
- ✓Vulnerability Management
Premium Extras
- ✓Incident Management
- ✓Organizational Hierarchy
Cost Calculator
Pricing data not available for SimpleRisk. Check their website for current pricing.
Build vs Buy
Should you build a SimpleRisk alternative or buy the subscription? Estimate based on 37 features.
Buy SimpleRisk
Better ValueBuild Your Own
Buying SimpleRisk saves ~$55,440 over 3 years vs building.
Estimates based on 37 features and a BuildScore of 4/5. Actual costs vary.
Integrations
8 known integrations