寓言

寓言构建一流的安全程序,超过企业客户的期望

商界女性从一个办公室召开远程会议。

Fable Tech Labs Inc. (“Fable”) connects digital teams to people with disabilities for the purpose of research and accessibility testing. Its platform enables an equitable exchange where businesses can benefit from the experiences of people with disabilities to build more inclusive products and people with disabilities can earn a source of income for their time and expertise. 

\r\n

Fable empowers some of the biggest Fortune 500 companies, including Slack, Shopify, and Walmart. The company wanted to get SOC 2 Type 2 compliance to provide their enterprise customers with an enterprise information security program.

\r\n

 

\r\n

Highlights

\r\n

 

\r\n

Challenges

\r\n
    \r\n
  • Maintain an InfoSec program without security expertise
  • \r\n
  • Meet and exceed the security needs of the company's Fortune 500 customers
  • \r\n
\r\n

 

\r\n

Solutions

\r\n
    \r\n
  • A single source of truth for all InfoSec program documentation
  • \r\n
  • A tool that integrates with the company’s team and reduces lift
  • \r\n
\r\n

 

\r\n

Results

\r\n
    \r\n
  • Simplified process to get and maintain compliance
  • \r\n
  • A hub for managing policies, onboarding and offboarding, and collecting evidence 
  • \r\n
  • Confidence and transparency when talking to customers
  • \r\n
\r\n

 

\r\n

Get a SOC 2 Type 2 audit and maintain an InfoSec program without security expertise

\r\n

Fable was looking to level-up their security posture to meet and exceed the security needs of their Fortune 500 customers.

\r\n

Naturally, there were concerns the company wouldn’t have the bandwidth or resources to commit to a full SOC 2 project. They needed a tool that would integrate with the team and reduce lift.

\r\n

A company that sells to enterprise companies, Fable was also overwhelmed by security questionnaires. 

\r\n

According to Abid Virani, the COO at Fable: "Every time we had to fill out a new security questionnaire, it felt like we were starting from scratch." 

\r\n

The company wanted to increase efficiency during the tech due diligence process, so they could spend more time building relationships and less time processing paperwork. 

\r\n

 

\r\n

A single source of truth for information security

\r\n

Fable now has what Virano calls a single source of truth for all their information security program documentation.

\r\n

They can easily manage policies, from assigning policy reviewers to versioning. Instant reminders enable them to stay on top of all their security and compliance tasks, which means they can confidently share their program with customers when needed.

\r\n

By automating security questionnaires and relying on the platform to surface the right answers, Fable’s account executives can cultivate stronger relationships with customers, pursue more opportunities, and increase sales output. 

\r\n

 

\r\n"}}" id="text-89bcf5f06e" class="cmp-text">

寓言科技实验室有限公司(“寓言”)连接数字团队残疾人为目的的研究和可访问性测试。其平台使乐动平台登录链接在哪一个公平的交换,企业可以受益于残疾人的经验建立更具包容性的产品和残疾人可以赚取的收入来源为他们的时间和知识。

寓言使一些最大的财富500强企业,包括松弛,Shopify和沃尔玛。该公司想要得到SOC 2 2型合规为企业客户提供一个企业信息安全项目。

突出了

挑战

  • 维护一个信息安全项目没有安全知识
  • 达到和超过公司的财富500强客户的安全需求

解决方案

  • 真理的单一来源的信息安全项目文档
  • 一个工具,集成了公司的团队,减少升力

结果

  • 简化流程和维护合规
  • 中心管理政策,新员工培训和offboarding,收集证据
  • 信心和透明度说话的时候给客户

得到一个SOC 2 2型审计和维护一个信息安全项目没有安全知识

寓言正在升级他们的安全态势,以满足和超过财富500强客户的安全需求。

自然,有担忧该公司不会有带宽或资源提交完整的SOC 2项目。乐动体育官方活动a他们需要一个工具,将整合与团队和减少升力。

公司销售企业公司,寓言也被安全调查问卷。

据阿比德Virani,首席运营官的寓言:“每一次我们必须填写一个新的安全调查问卷,感觉就像我们是从零开始。”

该公司想要提高效率在技术尽职调查过程中,这样他们就可以花更多的时间和更少的时间建立关系处理文书工作。

一个信息安全的事实来源

寓言现在Virano所说的真理的单一来源为他们所有的信息安全项目文档。

他们可以很容易地管理政策,从分配政策评论家版本控制。即时提醒使他们掌握的安全性和遵从性的任务,这意味着他们在需要的时候可以很自信地与客户分享他们的计划。

通过自动化安全调查问卷和依赖平台表面正确的答案,寓言的高管可以培养加强与客户的合作关系,寻求更多的机会,增加销售输乐动平台登录链接在哪出。

"[It’s a] tool we can rely on moving forward. It provides us with guidance and a bunch of useful project management features. For instance, it assigns tasks to individual stakeholders for evidence collection and includes due dates," said Virani. "It also integrates smoothly with our team. It ensures stakeholders understand their responsibilities and makes it easy to complete them."\r\n

Abid Virani, COO, Fable

\r\n"}}" id="text-7356a14a00" class="cmp-text">

“这是一个工具我们可以依靠前进。它为我们提供了指导和一堆有用的项目管理功能。例如,它将任务分配给个人的利益相关者进行证据收集,包括到期日期、“Virani说。“它还集成了顺利,我们的团队。它确保利益相关者理解他们的责任和使它容易完成。”

阿比德Virani,首席运营官,寓言

 

\r\n

An information security program to be proud of

\r\n

As of May 6, 2021, Fable is officially SOC 2 Type 2 compliant. Thanks to the team’s hard work, commitment to information security, and help from a dedicated platform, the process was painless. 

\r\n

After the audit process, Fable noted two significant benefits. First, software simplified the process getting and maintaining compliance, which is important, as Fable intends on staying SOC 2 compliant over the long-term.

\r\n

Second, the team now has a single source of truth for their entire information security program. Ongoing management of access policies, onboarding and offboarding, evidence collection tasks and policies is now easy for the team. 

\r\n

Virani is already looking to the future for ways to scale his program and continue offering his customers best-in-class security.

\r\n

Furthermore, these two benefits have given the team confidence. "When we talk to companies like Walmart or Shopify, they need to know our systems are secure. The platform allows us to talk to customers with confidence and provide them with complete transparency," said Virani. “We’re happy to show customers what’s under the hood because we’re proud of what they’ll find.”

\r\n

When a company invests in its information security off the bat the way Fable has, it becomes easier to maintain and scale. Today, Fable can provide its customers with a high level of security assurance and prove that when it comes to cybersecurity, it doesn’t just talk the talk.

\r\n"}}" id="text-be97a6d240" class="cmp-text">

一个信息安全项目值得骄傲的

截至2021年5月6日,寓言是正式SOC 2 2型的。感谢团队的辛勤工作,对信息安全的承诺,并帮助从一个专门的平台,这个过程是无痛的。乐动平台登录链接在哪

审计过程后,寓言指出两个重要的好处。首先,软件简化了过程和维护合规,这很重要,因为寓言打算长期住SOC 2兼容。

第二,真理的团队现在有单一来源的整个信息安全项目。持续管理的访问策略,新员工培训和offboarding、证据收集任务和政策现在是容易。

Virani已经展望未来扩展程序和方式不断向他的客户提供一流的安全。

此外,这两个好处给团队的信心。“当我们说话像沃尔玛这样的公司或Shopify,他们需要知道我们的系统是安全的。这个平台乐动平台登录链接在哪可以让我们跟客户提供信心和为他们提供完整的透明度,”Virani说。“我们高兴地展示客户外表之下的东西因为我们骄傲的他们会发现什么。”

当一个公司投资于信息安全立刻寓言的方式,它变得更容易维护和规模。今天,寓言可以为它的客户提供一个高水平的安全保证和证明网络安全时,它不只是说说而已。


你可能也喜欢

网络研讨会

第三方风险

现场演示:与OneTrust建立第三方风险管理程序

探讨OneTrust可以帮助您构建一个高效的第三方风险管理程序,简化手动流程和揭示隐藏的风险。

2023年9月28日

了解更多

网络研讨会

第三方风险

现场演示EMEA: OneTrust如何帮助推进第三方风险管理程序

加入我们的现场演示OneTrust第三方风险管理解决方案,看看它能帮助自动化和简化TPRM程序。

2023年9月19日

了解更多

网络研讨会

GRC &安全保证

让你的网络防御:关键洞察最新的NIST CSF更新

获得洞察即将到来的NIST CSF更新和学习如何有效地将其部署在您的组织。

2023年9月14日

了解更多
Baidu
map