Welcome to version 17.0.0! This major release introduces powerful new Risk Scenario Simulations, enhanced training controls with Module Builder Steps, and a variety of performance upgrades and bug fixes to make your experience smoother and faster.
🌟 Highlights & Key Features
Risk Scenario Simulations: You can now run detailed simulations against your Risk Scenarios to better understand and prepare for potential threats.
Module Builder Steps for Training: Ensure your workforce completes their training at the right pace. The new "Steps" concept in Module Builder allows you to guide users through training modules step-by-step.
Enhanced Compliance Visibility: The Compliance Framework page now visually displays Tracked Requirements in easy-to-read charts.
🛠️ Service Updates
Risk & Compliance
SSP Reports: Cleaned up the System Security Plan (SSP) Report display so it now shows a single Control Origination.
Control Categories: Updated the Control Category classifications to align with industry standards (Govern, Detect, Respond, Recover, Protect, Identify).
Workforce Enhancements: "Responsible Party" is now a required field on Workforce profiles. We have also added a new Active/Inactive status toggle for better workforce management.
🐛 Bug Fixes & Stability
Performance: Significantly shortened the load times for Tasks!
Session Timeouts: Fixed a highly requested bug where the automatic timeout would incorrectly kick users out after exactly one hour, regardless of whether they were actively using the platform.
Plan of Actions (POAs): Resolved an issue that was preventing POAs from being created.
UI Inconsistencies: Fixed bugs related to inconsistent PDF uploads and corrected the display columns (Responsible Party and Framework) on the Requirement Page.
Understand the key differences between NIST SP 800-171 Revision 2 and Revision 3 with this comprehensive migration guide and crosswalk. Learn how security requirements, assessment objectives, and DoD Organization-Defined Parameters (ODPs) align to help your organization prepare for future CMMC and FAR CUI compliance.
Explore practical risk register examples, including enterprise, operational, qualitative, and FAIR-based cybersecurity registers, to learn how organizations identify, prioritize, and manage risk more effectively.