<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wikki.cetbix.net/index.php?action=history&amp;feed=atom&amp;title=Cetbix_GRC</id>
	<title>Cetbix GRC - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wikki.cetbix.net/index.php?action=history&amp;feed=atom&amp;title=Cetbix_GRC"/>
	<link rel="alternate" type="text/html" href="https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;action=history"/>
	<updated>2026-05-11T14:57:02Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.34.2</generator>
	<entry>
		<id>https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;diff=247&amp;oldid=prev</id>
		<title>Richter at 22:22, 10 May 2026</title>
		<link rel="alternate" type="text/html" href="https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;diff=247&amp;oldid=prev"/>
		<updated>2026-05-10T22:22:53Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;a href=&quot;https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;amp;diff=247&amp;amp;oldid=243&quot;&gt;Show changes&lt;/a&gt;</summary>
		<author><name>Richter</name></author>
		
	</entry>
	<entry>
		<id>https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;diff=243&amp;oldid=prev</id>
		<title>Richter: Created page with &quot;==The basics== &lt;!--T:1--&gt;  ===What are the differences between Cetbix GRC, Cetbix GRC-R, Cetbix GRC-F and Cetbix GRC-ICS?=== &lt;!--T:2--&gt;  &lt;!--T:3--&gt;  All listed products are bu...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wikki.cetbix.net/index.php?title=Cetbix_GRC&amp;diff=243&amp;oldid=prev"/>
		<updated>2026-05-10T22:13:32Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==The basics== &amp;lt;!--T:1--&amp;gt;  ===What are the differences between Cetbix GRC, Cetbix GRC-R, Cetbix GRC-F and Cetbix GRC-ICS?=== &amp;lt;!--T:2--&amp;gt;  &amp;lt;!--T:3--&amp;gt;  All listed products are bu...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==The basics== &amp;lt;!--T:1--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===What are the differences between Cetbix GRC, Cetbix GRC-R, Cetbix GRC-F and Cetbix GRC-ICS?=== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--T:3--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
All listed products are built on the Cetbix GRC platform. This means that Cetbix GRC must be implemented first in order to activate additional modules and specialized extensions.&lt;br /&gt;
&lt;br /&gt;
==How Cetbix GRC differentiates itself== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Provides both qualitative and quantitative risk analysis (SLE, ARO, ALE, Cost-Benefit Analysis, IRR, and more)&lt;br /&gt;
* Available as both cloud-based and on-premises deployment&lt;br /&gt;
* Unified platform for project, risk, compliance, and incident management&lt;br /&gt;
* One system for all entities, branches, and locations – delivering a consolidated enterprise-wide risk and compliance view&lt;br /&gt;
* Cetbix GRC coordinates governance, risk, and compliance activities across technical, physical, and organizational domains in a consistent, auditable, and cost-efficient way&lt;br /&gt;
* Designed for practical usability and portability compared to traditional fragmented GRC tools&lt;br /&gt;
* Differentiates between applicable and non-applicable controls per organization, supporting dynamic risk-driven control selection&lt;br /&gt;
* Reduces unnecessary documentation effort through automation and structured workflows&lt;br /&gt;
* Provides ISO 27001-ready digital documentation and audit support&lt;br /&gt;
* Supports NIS2, NIST, ISO, and other international compliance frameworks&lt;br /&gt;
* Enhances alignment between information sources, organizational roles, and security decision-making processes&lt;br /&gt;
* Bridges the gap between human behavior and technology in governance and risk management&lt;br /&gt;
* Avoids overly generic compliance approaches by adapting to organization-specific risk environments&lt;br /&gt;
* Supports continuous improvement through a cycle of awareness, control integration, and gap remediation&lt;br /&gt;
* Strengthens organizational security culture through education, transparency, and employee engagement&lt;br /&gt;
* Improves cross-department collaboration for risk mitigation and compliance execution&lt;br /&gt;
* Identifies and addresses barriers to policy adherence across organizational structures&lt;br /&gt;
* Provides preventive governance capabilities through early risk detection and structured audit trails&lt;br /&gt;
* Supports decision-making for CISOs, CIOs, CSOs, and security managers with traceable evidence-based reporting&lt;br /&gt;
* Improves visibility into employee compliance behavior, communication, and accountability&lt;br /&gt;
* Reduces cost exposure from unexpected cyber incidents and compliance failures&lt;br /&gt;
* Helps reduce regulatory penalties including GDPR-related risks&lt;br /&gt;
&lt;br /&gt;
==Managing risks successfully with Cetbix GRC== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cetbix GRC provides a structured methodology for continuously improving governance, risk, and compliance maturity. It supports dynamic enterprise-wide risk management through awareness, control integration, and systematic gap closure. A unified dashboard provides visibility across multiple branches, locations, and entities.&lt;br /&gt;
&lt;br /&gt;
In addition to core governance and compliance functions, Cetbix GRC supports:&lt;br /&gt;
&lt;br /&gt;
* Identification of risks including type, cause, and potential impact&lt;br /&gt;
* Project governance and compliance-linked project tracking&lt;br /&gt;
* Incident lifecycle management&lt;br /&gt;
* Risk analysis based on probability and impact evaluation&lt;br /&gt;
* Structuring of complex risk events into manageable components&lt;br /&gt;
* Risk evaluation against predefined acceptance criteria&lt;br /&gt;
* Risk treatment and control implementation&lt;br /&gt;
* Integration with Internal Control Systems (ICS)&lt;br /&gt;
* Risk categorization, aggregation, and enterprise capability mapping&lt;br /&gt;
* Automated risk monitoring with alerts, reminders, and workflows&lt;br /&gt;
* Centralized risk documentation and audit trails&lt;br /&gt;
* Predefined and customizable reporting (Report Designer)&lt;br /&gt;
* Advanced 3D risk visualization dashboards&lt;br /&gt;
&lt;br /&gt;
==About Cetbix Hybrid GRC== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cetbix enables organizations to strengthen compliance and cybersecurity through a hybrid GRC approach covering more than 40 regulatory and industry frameworks. The platform also supports:&lt;br /&gt;
&lt;br /&gt;
* High-Level Risk Assessment (HLRA) for OT environments&lt;br /&gt;
* Integrated Document Management System (DMS)&lt;br /&gt;
* Quality Management System (QMS)&lt;br /&gt;
* Third-Party Risk Assessment and Vendor Risk Management&lt;br /&gt;
&lt;br /&gt;
==Systematically manage and improve information security based on ISO 27001== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cetbix GRC is designed for cyber risk prevention and compliance alignment with ISO/IEC 27001 and BSI standards. It is widely used across organizations in Europe and globally.&lt;br /&gt;
&lt;br /&gt;
The ISO 27001:2022 aligned capabilities enable organizations to:&lt;br /&gt;
&lt;br /&gt;
* Control and manage information security documentation (policies, specifications, verification records)&lt;br /&gt;
* Manage information security risks aligned with ISO 27001 and ISO 27005&lt;br /&gt;
* Track and record security controls and mitigation measures&lt;br /&gt;
* Maintain asset inventories and classification with inheritance of protection requirements&lt;br /&gt;
* Manage security incidents through structured workflows&lt;br /&gt;
* Handle exceptions to security policies (Exception Management)&lt;br /&gt;
* Generate Statements of Applicability (SoA)&lt;br /&gt;
* Perform gap analysis and internal audits based on ISO 27001 and ISO 27002&lt;br /&gt;
* Evaluate overall information security compliance posture&lt;br /&gt;
* Provide dashboards and reporting for security governance&lt;br /&gt;
* Enable fully paperless ISO 27001 documentation processes&lt;br /&gt;
&lt;br /&gt;
==Asset Classification== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The asset classification process in Cetbix GRC enables structured and scalable data governance:&lt;br /&gt;
&lt;br /&gt;
* Repository: Central system containing information assets (description, owner, location, access rights)&lt;br /&gt;
* Data Type: Classification including personal data identification and sensitivity attributes&lt;br /&gt;
* Personal Information ID: Definition of personal data, usage purpose, and policy alignment&lt;br /&gt;
* Confidentiality Classification Scheme: Classification based on legal, business, and sensitivity requirements&lt;br /&gt;
* Asset Handling Procedures: Rules for processing, storing, and transmitting data based on classification&lt;br /&gt;
* Sensitivity Level: Defines protection requirements for each dataset&lt;br /&gt;
* Retention Period: Ensures compliance with legal and organizational data retention policies&lt;br /&gt;
* Data Utilization Rules: Defines access control, logging, auditing, and usage constraints&lt;br /&gt;
* Backup Management: Defines backup frequency, storage, and recovery processes&lt;br /&gt;
* Storage Media Management: Controls for secure storage, transport, and disposal of media&lt;br /&gt;
* Electronic Data Transfers: Secure handling of digital transmissions&lt;br /&gt;
* Secure Disposal of Media and Data&lt;br /&gt;
* Risk Register Integration&lt;br /&gt;
* Confidentiality Level Assignment&lt;br /&gt;
* Risk Acceptance Methodology (standard or customized)&lt;br /&gt;
* Digital and Manual Risk Acceptance Processes&lt;br /&gt;
* Control Assignment and Mapping&lt;br /&gt;
* Asset-to-Control Mapping&lt;br /&gt;
* Quantitative Risk Assessment&lt;br /&gt;
* Qualitative Risk Assessment&lt;br /&gt;
* Single and Multi-Asset Evaluation&lt;br /&gt;
* Integrated Risk Register Management&lt;br /&gt;
&lt;br /&gt;
==National Institute of Standards and Technology (NIST)== &amp;lt;!--T:2--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Cetbix GRC supports alignment with NIST cybersecurity and governance frameworks by enabling organizations to:&lt;br /&gt;
&lt;br /&gt;
* Classify sensitive data and critical information assets&lt;br /&gt;
* Define baseline security controls&lt;br /&gt;
* Conduct structured risk assessments to refine controls&lt;br /&gt;
* Document security policies and control frameworks&lt;br /&gt;
* Implement and manage security controls across systems&lt;br /&gt;
* Continuously monitor control effectiveness and performance&lt;br /&gt;
* Evaluate risks at governance and executive level&lt;br /&gt;
* Authorize systems for secure operation and processing&lt;br /&gt;
* Perform Cyber Threat Intelligence maturity assessments&lt;br /&gt;
* Enable continuous monitoring and improvement of security posture&lt;br /&gt;
* Support compliance with federal requirements including FISMA (Federal Information Security Modernization Act) compliance frameworks&lt;/div&gt;</summary>
		<author><name>Richter</name></author>
		
	</entry>
</feed>