Framework Compliance Platforms

Arrakis has worked with numerous clients helping them get ready for audits or bring them closer to becoming compliant on a continual basis.

In all cases, Arrakis runs across the similar situations where there is a lack of understanding of administrative controls, lack of visibility into risk or how to remediate risk, and how to plan for and create system security plans (SSPs).


Read the article from Kaseya about Compliance as a Service where we are the only named third party



Have a compliance question?  Ask our Compliance AI Chatbot


Arrakis has created a series of low cost platforms that can be utilized independently or together for increased visibility and an easier time to get compliant as well as provide ability for activity auditing.


How we suggest you use our platforms


Some of our platforms are completely independent of others while other platforms are designed to be used together or completely by themselves if you wish.  We have placed "steps" in the order of usage however all are suggested for subscription.  Regardless that we are offering platforms to reduce confusion and effort, that does not mean we are suggesting not having experienced and certified professionals to help your company get compliant and audit ready.  As a reminder, Arrakis Consulting has a 100% success rate since 2016 for companies seeking certification.

Compliance Chatbot (Step 1)

Completely free solution to ask compliance related questions. 

We built this for ourselves and are offering it free to the world.

Prosikon Vendor Due Diligence (Step 1)

Prosikon is a feature rich vendor due diligence platform that is designed to work completely independent of any other platform.

Regardless of your environment, we suggest you subscribe to Prosikon simply for better assurance of vendors.

Policy Forge (Step 1)

Much like Prosikon, Policy Forge is completely independent of any other platform.

Policy Forge is always suggested as this platform allows for creating/modifying policies dependent on your environment as well as attestation capabilities and control mapping.

Fortuna Risk Compass (Step 1)

Much like Prosikon, Fortuna is a feature rich risk assessment platform that has pre-built templates for risks and assets.  This platform allows for far greater understanding of risk and includes capabilities for all employees to be risk sensors.  Exporting risks to Prothesis is built in as well as legal research.

Prothesis PoAM Builder (Step 2)

While you can build your own PoAMs manually, you can also build PoAMs by importing risks from Fortuna. 

Very intuitive step by step process to build out PoAMs with less experience required to do so.

Mutina SecurePath SSP Platform (Step 3)

Required by CMMC, building out SSPs can be difficult. 

This platform reduces complexity and allows for cross-framework comparison to indicate what extra effort is required.  Once an SSP is finalized, versioning is possible for any previous SSP.


Contact us by filling out this form - Contact Us


Policy Forge

Policy Forge is a quick and easy policy and procedure creation platform with attestation capabilities, auditing, reporting, and RACI for each policy. This allows a company to utilize human generated policies that have passed numerous audits and associate them with their company. As policies are published, users are sent emails to attest to the policies with reminders sent.  

Policy Forge

Save time and effort

Spend less time and confusion wondering if your policies are sufficient.  Want to change the wording, go right ahead and adapt to your environment.

Policy Forge

Align with frameworks

When you enter our system, you declare the frameworks you are beholden to.  As policy language is created, we align the various control language to control requirements.

Policy Forge Features Video

Quick video on Policy Forge to reduce stress, effort, risk, and align with compliance needs faster.


Interested in Cybersecurity Awareness Training? Start your free Risk Assessment.


Prosikon

Prosikon is a feature rich vendor due diligence platform with numerous areas of information relating to your vendors or suppliers.  Vendor due diligence is a requirement by all regulatory environments and our platform is a time saver that increases visibility into the security posture of companies you work with.  

Prosikon

Make safer decisions

The information required to make safe decisions with onboarding vendors can never be enough.  Our platform greatly expands visibility into a vendors cybersecurity posture.

Prosikon

Want to do it yourself?

We can do it for you or you can do it yourself.  We charge $750 per vendor, per review or you can subscribe to the platform and have unlimited vendors by doing it yourself.

Need to validate your suppliers?  Sign up for our Custom built Vendor Due Diligence program (Prosikon)

From Risks to System Security Plans (without spreadsheets!)

Save time, effort, and reduce stress while still accomplishing required regulatory tasks.
Fortuna
Fortuna Risk Compass

Create and track your risks, assign assets to your risks, understand the dollar value of the risk not only from the risk itself but from the asset standpoint, have a review calendar with emailed reminders and a full RACI chart to assign risks to named individuals. 

Need to remediate risks?  Export them to Prothesis PoAM builder for an easier auditable form of documenting how you plan to remediate your risks!

Prothesis
Prothesis PoAM Builder

Build out your Plan of Action and Milestones (PoAMs) in an easier manner as well as understand the effort and cost to remediate.  This simply allows you to determine if acceptance of risk is more desirable than remediation.  Implement due dates and ensure that those responsible receive the notifications they need so PoAMs aren't forgotten. 

Auditing is enabled to demonstrate user and remediation activity.

Mutina
Mutina SecurePath SSP Platform

Mutina is a compliance timesaver.  Associate your company with a cybersecurity or regulatory framework and understand what you have to do in order to be compliant. 

Have more than one framework?  No problem, we can blend the effort and evidence to associate with similar controls. 

Once you are fully compliant, finalize your SSP across multiple frameworks to be compliant.  *note - an SSP is a required CMMC control item.


Need extra help?  Subscribe to our online practice test engine.  Hundreds of questions are designed to be more difficult than the actual test to increase chances of success. 

Subscribe here and gain access to all our practice tests.


We are masters at these frameworks and many more.

Our membership in professional organizations

Contact Us