Collaborating closely with the client, Taazaa’s team designed a modular, web-based platform with a microservices architecture.
The solution’s tech stack includes Angular 11, .Net Core, and PostgreSQL, as well as other supporting technologies.
Platform users can view analytics reports for all their compliance frameworks from the software’s dashboard. The dashboard can be customized to display the type of data desired in the format the user chooses.
From the dashboard, the user can click on tabs in the top navigation to view and manage six different categories:
- Compliance
- Assets
- Document Management
- Vulnerabilities
- Custom Systems of Records (SoR)
- Security Content Automation Protocol (SCAP)
The platform is preloaded with the most common cybersecurity frameworks, including CMMC, NIST, HIPAA, HITRUST, and FEDRAMP.
Assets can be added to the system by barcode scanning or importing the data from a CSV file. Vulnerabilities are linked to a Common Vulnerabilities and Exposures (CVE) ID number, and the system suggests remediations for each risk.
The platform uses a complex algorithm to evaluate all vulnerabilities and generate an overall risk score for the business. The SCAP module is next-level engineering. It allows ATO management teams to automatically map highly technical data into undefined high-level cyber frameworks using natural language processing and artificial intelligence. This is a key differentiator for the client, because it is not a capability available with standard GRC software.