Grigory Emelianov
TeamCommented on Suche sollte auch auf Deutsch funktionierenDanke @Domenico Genco , du hast vollkommen recht, die Suche ist aktuell nicht für deutsche Begriffe optimiert, das Rechtsregister-Beispiel bringt es auf den Punkt. Wir schauen es uns anCommented on Uploading proof of completionAbraham Aranguren thanks for this feedback! I just have a few questions: Which OS systems are relevant here? Is it company devices or their own? Do you think they would install more famous MDM solutions like Kandji or MS Intune instead if you'd implement something like that? I co…Commented on Add possibility to see which policies need to be accepted for each employeeHey Tanja, cool, this makes sense, thanks for the upvote. At the moment we focused on evidence-first approach. But I totally understand where you are coming from. We'll think about best way to show it without hindering possibility to focus on evidence. As usual, if this feature g…Commented on Suggest "unused" Vendors by no login activityCool idea, thanks Amir El Sayed! This would only work for google workspace unfortunately and only where SSO is used a lot. So, most of vendors will not have this level of information. Do you think it would fit better in access page than on vendors page?Commented on Uploading proof of completionHi, we were recently considering this feature but we found a few potential UX issues in the workflow: Without Secfix agent, if they want to upload evidence about device compliance (password manager, encryption, etc.), employees will need to enter at 1. least device name, 2. opera…Commented on Link assets to risks in the Risk RegisterCool idea, thanks Amir El Sayed we will keep it in mind. We already see a strong use case for Risk-Vendor mapping. But other elements seem to create more noise than help in our experiments. Do you have specific useful examples where mapping the inventory assets and people to spec…Commented on Centralized Storage for Non-Policy and ISMS-Specific DocumentsThanks for the feedback! The main benefit we are chasing at Secfix for users is to make things tidy, clean and structured. By introducing a folder logic to collect more docs I think you will actually loose structure that Secfix gives you long term by adding more and more loose do…Commented on Enable manual setting of reviewed/ needs review for diverse objectshi everyone, brilliant! I understand the pain point better. To reiterate - the major concern is: Risks and vendors can expire any time. It's difficult to anticipate when your risk register will change the statuses because there is no way to know the expiration date and there is n…Commented on Visualize Admin Accounts in the Monitored Computer listhey Cyrill Rüttimann can you please explain a bit more? I am not sure I understand what you are referring to as admin account and admin of what exactly? Are you talking about multiple user accounts on the same device or admin/employee permissions in the Secfix platform? Thanks a…Commented on Make policy version history accessible for all users.hey Miriam M., do you know why? Why is this a problem? thxCommented on Support excluding non-critical unencrypted partitions from HD encryption checkhey everyone, who struggles with this today? On which OS? thanks!Commented on Enable Filtering in Compliance Report Viewsthanks Florian G., we are currently ideating something like this :) Is there anything else we need to fix/build in the Compliance Report in your opinion?Commented on Revoke approval of a policyhey everyone, can someone please share light: what is the difference from your perspective between the 'Owner' and 'Approver'?Commented on Automatically un-assign computers from terminated usersHey everyone, imagine the computer becomes unassigned. Is it important to identify to whom this device was assigned later?Commented on ISO 42001 (AI Management Systems)Update: This is a hot topic right now. Most Dakks certification bodies (auditors) don't have any auditors accredited to certify customers. We are looking for auditors to build this out as we speak. We are also already playing around with first use cases that are connecting with I…Commented on Change manual evidence to an automated taskFlorian Caspari thanks! Did I understand correctly that you suggest to backfill the cloud provider agreement out of the cloud provider documents that you uploaded under the related vendor? Or what exactly do you mean under 'already in assets available'? (ps usually we refer to in…Commented on Add custom fields to risks in risk registerThanks for feedback! Historically when Secfix customers asked for custom fields (a common feature request), deeper investigation revealed that 40% of cases were about some more specific use cases that could be implemented in various ways but often slow you down long term. We will…Commented on Bulk deletion of AssetsCharlotte B. were we able to resolve your problem? Could you give us some feedback? Thank you :)Commented on Add custom fields to vendorsQuick update here: At Secfix we carefully analyse every potential custom field before implementing it. We try to avoid 'feature bloating' as we are highly focused on building something that's easy to use and maintain. We typically do it by analysing each use case separately. It's…Commented on Add option to manually enable/disable "Upload Evidence" buttonThanks for the insight Arnold Tim. It's something we recently discussed in product review. We'll reach out when this becomes a high priority. If any other customer would like this, please upvote and we will reach out to you as well :)Commented on Automatic owner assignment for specific areasHi Michelle H. I assume you are talking about cloud assets. Are you already leveraging the Bulk Tagging? By tagging the cloud resources in Terraform or IaC native to your cloud, you can consistently prove the auditors that you are correctly following labeling best practices and t…Commented on Add button/ability to send reminders to assigned owners of Risks & VendorsIf any of the voters have a specific problem occurring from not having a reminder feature, it would be greatly appreciated if you could share it.Commented on Add button/ability to send reminders to assigned owners of Risks & VendorsThanks for your feedback Paulo So.. How would you expect this email reminder to go automatically and periodically? If yes, how often?Commented on Improvement: Show Jira ticket key and title, opt. URL instead of ticket ID in results of failing automated tasksCommented on Improvement: Show Jira ticket key and title, opt. URL instead of ticket ID in results of failing automated tasksThis potential for improvement will be considered next time we work on Jira integration.Created Improvement: Show Jira ticket key and title, opt. URL instead of ticket ID in results of failing automated tasksCommented on Option to add reason when I set an automated tasks as 'Not applicable'Commented on Add Risk ID# field to the Risk Register to enable easier tracking & management of RisksPaulo So. in this case would you like to add your own risk ID or would you prefer Secfix to create a risk ID automatically for every risk?Commented on Add custom manual evidence records to listMichael Niemand: Thank you, now it's loud and clear. I completely understand. You’re right—every auditor has their own approach, and it’s challenging to predict what additional evidence they might request. Based on your feedback, I have a suggestion: Would it help if we allowed y…Commented on Add custom manual evidence records to listHi Michael Niemand thank you for your feedback. I'd love to review this for you. Can you please provide 2-3 specific examples of links or files that you wanted to add to the security report under A8 (Tech Controls)? Thank you