Onspring Interview

I recently had the opportunity to speak with Jason Rohlf, VP Solutions, Mark Scheinkoenig, VP Commercial Sales, and Emily Figg, VP Marketing about their GRC solution at Onspring to discuss the product audience and upcoming features.

Onspring was founded in 2010 with headquarters in Kansas, USA. Its GRC solution is available in a cloud-only offering with a user-based licensing model. The platform supports a rich number of control frameworks and can use the Universal Compliance Framework (UCF) to minimize the response requirements for common controls.

The product is on a regular refresh cycle, which generally happens quarterly with several upcoming features and enhancements scheduled for release in the next quarter. These include a refresh of the user interface, which aims to provide a cleaner, more modern look that takes advantage of the visual real estate, and an update to the workflow feature set, including the introduction of dynamic workflows with multi-path capability.Upcoming releases will include new options for filtering and reporting on data.

This robust platform has been widely adopted across market sectors.

Source: Interview June 2020

Our Take

Partnering with an organization that understands the needs of its client base and invests in adapting to change and demand is key. When choosing a vendor, consider the roadmap or the product, whether the features they are planning to introduce are in line with your needs, and review the frequency with which changes are being made. A vendor who is vested in keeping the product current based on feedback from their user community is key to ensuring maximum return on investment over time.

Source: GRC at SoftwareReviews, Accessed July 1, 2020

Other Recent Research in Governance, Risk and Compliance

Governance, Risk and Compliance

Twilio Breach and Cloud Security

By exploiting a five-year-old configuration error, a hacker was able to access Amazon’s S3 cloud storage buckets on which Twilio’s code was loaded. As a result, customers were able to unknowingly download the modified code for twenty-four hours.

Governance, Risk and Compliance

Qualys and Ivanti Partnership Boasts an Incredibly Robust Vulnerability Management Platform

Qualys VMDR and Ivanti have announced a new partnership dedicated to improving the detection and patching of vulnerabilities. Announced July 30, the Qualys and Ivanti Partnership have already gone live as an integrated component of the VMDR solution.

Governance, Risk and Compliance

IBM Raises Price on Software Support; Shoves Customers Toward the Cloud

IBM is changing the terms of its ubiquitous Passport Advantage agreement to remove entitled discounts on over 5,000 on-premises software products, resulting in an immediate price increase for IBM Software & Support (S&S) across its vast customer landscape.

Governance, Risk and Compliance

RiskSense Releases a Unified Infrastructure Security Risk Management Program

RiskSense announced on July 13 its new version of the cloud-delivered RiskSense risk management platform. The main draw of the program is its holistic risk calculation across CVEs and CWEs.