Non-conformities are important items in your ISMS which are especially managed in relation to internal audits. Non-conformities can be major, minor or morely "improvement potential".
All related places now display this vital type information better, so you can focus your attention on the most severe non-conformities.
You can now fetch units from AD and get current Cyberday users synced to the selected units. All AD groups are available to be used for syncing.
Find this feature from the new Edit structure -page.
You'll find a new page on the left menu, Organization -> Edit structure.
This page can be used to divide your organization into relevant units. Units are meant for e.g. delegating guidelines in a more targeted way. We're also developing a feature currently, where the implementation of a task can be separately delegated for selected units. This can be relevant in situations, where e.g. 2 clearly separate branches of your company have very different processes.
We rebuilt part of the SharePoint file linking logic, because the previously used ready-made libraries worked too in a too unstable way.
The feature of linking external files now works the same as it did before, but should fail a lot less. Also now you can complete the whole process inside Teams desktop app too, and don't need to jump to the browser Teams side. 👍
You can now connect multiple users to a single tasks, similarly as for documentation items previously.
You can use this feature e.g. when you have a large organization and need input from multiple units, or when you have e.g. a separate partner responsible for the technical implementation of a task, but your owner keeps the overall responsibility.
"Tasks you're participating in" will show up on the Taskbook for all users, but with a smaller emphasis than the tasks where you're the actual owner.
We regularly update Cyberday's content templates so that they remain in line with different security requirements and general good practices. Now it was time for the content update v46, during which we updated our documentation templates with numerous customer-wished improvements.
Changes are mostly "small but important". This update small summaries about the most notable changes.
We added the following sections:
The changes are intended to help identify critical partners and ensure that for important partners we have sufficient evidence gathered of their information security level.
We improved the management of other security requirements with the following additions:
With the help of these additions, it is possible to more clearly document, for example, additional commitments given to individual customers or own quality requirements - and related measures and other items in the management system.
Additions were made to the documentation cards of the units and sites, which will be included in the new "Organizational structure" page in the future. Through this page, you can more precisely define which units and sites your organization is made up of. Units can also be classified according to their nature (department, team, subsidiary, etc.) and into main units vs. sub-units.
Important small addition on the data store documentation cards:
We added an optional question on the data system card:
Topics related to user support can be addressed under the question.
We are just publishing 2 new frameworks to Cyberday!
NIS2 sets the baseline for cybersecurity measures, supply chain security and reporting obligations across critical industries, such as energy, transport, health, food, waste, public administration and digital infrastructure.
SOC 2 specifies how organizations should protect customer data from e.g. unauthorized access, security incidents or other vulnerabilities. It is developed by the American Institute of Certified Public Accountants (AICPA) and is especially popular in the USA.
Previously, when sharing reports from Cyberday, the listing was formed directly based on the selected framework and "starred" reports.
Now you can also choose another way for sharing reports, where you can freely pick the reports to be included. This method also supports all report types, i.e. you can also include list or item reports you have created yourself, as well as for example visual reports.
Some organizations run their own ISMS in Cyberday based on several different requirement frameworks.
In these situations, internal auditing separately for each framework can become an unnecessarily heavy process.
Now Cyberday also supports a operating method where audits can be targeted at selected Cyberday themes. In this way it is possible to audit, for example, 4 themes per year and achieve full coverage (12/12) for the internal audit of the ISMS every 3 years. 👍
We're going to be investing more and more on better help and support materials, which will guide you forward in your Cyberday usage, no matter if you're just getting started, already nicely running or an advanced ISMS admin looking for continuous improvement.
To support this, we renewed the concept in Cyberday Academy a bit. All Academy content is now categorized under topics like "risk management", "ISO 27001", "personnel security" or "getting started", so you can find just the right collection of different kind of materials you need. We also added an own left menu for the Academy, so you can easily navigate to all content. Menu lists the topics, but also the different content formats - help articles, video courses and blog articles. Academy will now regularly start getting new content updates.
So choose your topic or preferred learning type, and start learning with us. 🎓
We improved the usability of embed-type reports (e.g. privacy notices), which are designed to be embedded into your public websites to serve customers / other stakeholders publicly.
Now e.g. the scrollbar is more clearly visible but also matches your selected theme color, so it should nicely look like a natural part of your website.
Any wishes for further improvements are highly encouraged. 👍
Our team will start maintaining a list of upcoming new security frameworks both within Cyberday app and on the Cyberday.ai website.
As a user of Cyberday, you can influence our priorities by upvoting the frameworks that are important for you with short justifications.
You can now pick files from your SharePoint environment related to all the items in Cyberday (tasks, guidelines, documentation). These can be, for example, policy documents related to the task, process drawings describing the connections of a data system, PowerPoint instructions related to staff guidelines, or contracts related to the system provider's card.
To start using the feature, you must fill in the appropriate SharePoint site information under Organization settings in the Settings-page so we know where to retrieve the files from. 👍
We work regularly to identify views that work unnecessarily slowly in Cyberday. We recently made improvements to e.g. all views listing tasks and their assurance information and the Cyber security risks table.
We are also currently developing the speed of the app's first load. Within Teams, this also affects every tab change in the application (Guidebook, Taskbook, Dashboard).
Please feel free to contact our team if you notice points that repeatedly work too "calmly". 👍
When you work e.g. on the framework tasks table, we now better remember the selected filters and sortings you have chosen. When you navigate from a table to a task and back, you can continue directly from the same view.
The same now works better also better on the general Tasks-page.