Que problemas é Paramify E como isso está te beneficiando?
We use Paramify for FedRAMP SSP documentation generation and maintenance...have not used their other offerings - standards (FISMA, CMMC) nor tool integrations (to Jira, ServiceNow). We've seen the POAM Management functionality but are not licensed for it.
Without Paramify, maintaining a ~50 file SSP (base doc + 10 attachments + 18 control family Policies + 18 Procedures) properly, is a near impossible task. The sheer # of controls (+ sub parts), depending on the FedRAMP impact level, plus the overlap in topics across the control implementation statements, causes most SSPs to erode in quality and accuracy quickly over time. IMO, Paramify simplifies / streamlines this maintenance in a few ways:
1. puts a web UI in front of 95% of these documents - no more editing word docs directly.
2. parameterizes the dozens of supporting tool / party names - simplifies reference searching and bulk updates...across the multiple documents.
3. provides ability to re-use implementation statement (parts) - we found this not as feasible as hoped...not because of the tool functionality but because our advisor was particular that most controls require unique implementation.
4. status / progress tracking - especially during initial authoring.
5. review workflow - ability to have users review implementation statements and add comments.
The tool has a modern look-and-feel, and we've found the Paramify staff to be knowledgeable, responsive and very engaged in the security compliance field. I know they've done a lot of work for FedRAMP 20x already, and we anticipate leveraging that when we make the 20x adaption in the future. Análise coletada por e hospedada no G2.com.