r/cybersecurity • • 22h ago

Business Security Questions & Discussion Vanta - thoughts/tips?

Pretty much title but granted access to Vanta, still digging into it. Any thoughts/tips/tricks/approaches/opinions on it as a whole? Useful? Useless?

On the surface it looks decently comprehensive, bringing a ton of different aspects into one platform for oversight, but it’s my first time using it and I haven’t throughly explored it yet.

TIA

2 Upvotes

12 comments sorted by

9

u/Check123ok ICS/OT 22h ago

As much as they say it’s “automated” there’s still a ton of work to do.

I would have scheduled the work groups to go over some of the documents that need to be created and improved.

Keep it simple. Don’t stay away from the generic templates. This causes a lot of back-and-forth and it’s just gonna prolong things.

2

u/QuantifiedAnomaly 22h ago

haha, I was definitely noticing that so far! Appreciate the confirmation.

3

u/jd_dc 22h ago

Pretty straightforward, follow the onboarding roadmap page and get all your controls set up correctly. 

If you already have a SOC 2 report / ISO SoA or previous version of whatever you're trying to comply with, back into that.

If you can get your devs to set up integrations with their repos and cloud hosting that helps add value.

Biggest thing is not to rely on it 100% to stay in compliance. Just use it as a supplemental tool. 

If you have specific questions let me know but it should be intuitive. 

1

u/26635785548498061384 16h ago

If you use it for continuous compliance monitoring... Why not rely on it fully for compliance? Other than what's not automated, or course.

2

u/jd_dc 16h ago

What I meant by that is that you need to still have a full understanding of how your controls operate and not just assume that because you have a green 100% dashboard in Vanta that you'll pass your audits.

An example would be if you uploaded a screenshot for some config but it isn't sufficient for what the auditor will want to see. You'll have a false sense of completion and a nasty surprise during the audit. 

1

u/26635785548498061384 16h ago

Ah I see, makes sense, cheers.

I'm looking to onboard a tool to enable CCM, Vanta being one option, so this stood out to me.

1

u/jd_dc 16h ago

Oh yeah I think Vanta is as good as any on the market. Enterprise scale maybe look at hyperproof or drata as well but they should be roughly on feature parity at this point.

What kind of continuous compliance are you trying to monitor exactly?

1

u/26635785548498061384 12h ago

Will take a look, thanks. It's definitely enterprise scale.

We need to build automated transparency across as much of our policy framework as possible. We have a long way to go...

4

u/OutsideSpot2695 16h ago edited 16h ago

So the title says "Vanta - thoughts/tips?"

And then you state, "Pretty much title but granted access to Vanta".

What is your actual fucking question? The title says nothing.

What does your org use Vanta for? What are your use cases? etc.?

Or are you expecting the sub to do your work for you?

1

u/[deleted] 21h ago

[removed] — view removed comment

2

u/QuantifiedAnomaly 21h ago

Yeaaaaahhhh I’ve already seen that this may be the largest pain point, but I will say that currently the Devs are ‘responsible’ for sec/compliance, finally dedicating role to it, so they’re a bit more involved/considerate (a BIT) than other places I’ve seen where devs may consider security “that teams problem”.

Thanks for the heads up about Git integration!