Brooks and his team found Secureframe so easy to use that they were able to get onboarded and kick off their ISO 27001:2002 compliance efforts immediately.
“The platform is very easy to understand and to use. The onboarding is a good example. It was so well done that we didn’t need any help — we could just get started using the platform right away.”
Arbor’s compliance roadmap also included ISO 9001, ISO 27701, PCI DSS, and GDPR, all of which have a significant amount of overlap. With Secureframe, the team could log in and see at-a-glance which controls and tests are required, which are common across frameworks, and what their next steps should be as they move forward. For Brooks, this ease of use made a big difference.
“We approach all our frameworks as part of the same management system, but the auditing cycle is different for each one. So we often need to kind of focus on an individual framework at any given time,” he says. “You’ve got a really easy way of breaking down all of the work for a specific framework. We started just with ISO 27001:2022, but were able to add more frameworks over time. Secureframe helped us manage that workload incrementally. It makes the process so much easier.”
Because Arbor has multiple products and business units, it has a complex and broad tech stack that would be difficult to monitor manually. Secureframe’s tests made it easier to identify where issues are in the company and how to fix them. For example, as they implemented ISO 27001, Secureframe automatically ran tests against AWS, Google, and Azure and provided clear recommendations for implementation changes for each cloud environment. Rather than searching for specific issues or manually taking screenshots of bucket policies, the team could quickly delegate tasks and remediate the issues.
The visibility that Secureframe provides has helped Arbor approach compliance more holistically as a company. This includes identifying which employees have read and approved policies, something they previously had to do manually.
“We used to have to gather evidence via lots of roundabout ways to prove to the auditor that people had seen our policies and they were up-to-date,” says Brooks. “Now, it’s all in the system. You can just show the auditor that it was done and dusted. That really stood out to me.”
Having every piece of information in one place also helped Arbor integrate their risk management and compliance efforts. Using Secureframe’s end-to-end risk management solution, they could track the actual work that goes into risk remediation directly with the JIRA integration.
“It’s a really thorough and clear way of showing that you’ve actually captured the risk and you’re doing things to remediate it, which makes evidencing to the auditor very easy,” he says.