S3 Ltd

KnowBe4 Compliance Manager (KCM) - Governance, Risk & Compliance (GRC) for the UK Public Sector

Challenging compliance requirements ? Not enough time to get audits done ? The KCM GRC platform helps you get audits done quicker, is easy to use and very affordable.
UK templates: GDPR, PCI-DSS, Cyber Security Essentials, ISO27001, Lexcel, multiple public sector frameworks are available. Custom templates built free of charge.

Features

  • Managing Governance, Risk, Compliance, and Audits
  • Manage Policy Workflow
  • Vet, Manage, and Monitor Vendor Risk
  • Dashboards with Automated Reminders
  • Easy Risk Identification and Response
  • Evidence Repository and DocuLinks
  • Manage and Automate Compliance and Audit Cycles
  • Centralize Policy Distribution and Tracking
  • Identify, Respond, and Monitor Your Risk
  • Efficiently Manage Third-Party Vendor Risk

Benefits

  • Reduce the time you need to satisfy compliance requirements
  • Save time when you manage distribution of policies
  • Simplify risk initiatives with an easy-to-use wizard
  • Easily prequalify, assess, and conduct remediation
  • Effectively reduce the time to satisfy all of the requirements
  • Central repository to store, organize and distribute compliance policies
  • Easily manage the entire lifecycle of your vendors
  • Dashboards are simple to use and easy to understand
  • Intuitive console interface for ease of use
  • Multiple ways of maintaining audit evidence and documentation

Pricing

£190 to £899.75 a person a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tony.mason@s3-uk.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 12

Service ID

8 8 6 9 7 1 9 7 9 0 3 0 7 5 2

Contact

S3 Ltd Tony Mason
Telephone: 01628 362784
Email: tony.mason@s3-uk.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
None

User support

Email or online ticketing support
Email or online ticketing
Support response times
UK business hours
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
1st level support to include best practice advice through S3 (reseller), escalation to KnowBe4 as required. UK business hours, telephone and email.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
A dedicated customer success manager will be assigned to each new customer who will 'hand hold' through kickoff of the service. Very little is required to get up an running - whitelisting and uploading of a users email address is all that is required to get started.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data can be reported on and stored by the customer. After expiration the data is securely deleted from the KnowBe4 servers.
End-of-contract process
As above

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Safari 9+
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
API
No
Customisation available
Yes
Description of customisation
Compliance templates can be added and customised, schedules, stakeholders etc Risk register entries, third party vendors and associated Q&A can all be customised and configured

Scaling

Independence of resources
Instantly scalable architecture within datacentre, no restrictions.

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
KnowBe4

Staff security

Staff security clearance
Other security clearance
Government security clearance
Up to Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 3.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Direct exporting in CSV or PDF format
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.9% uptime
Approach to resilience
AWS load balancing, multi zone, mirrored databases, snapshots, WAF, redundant DNS
Outage reporting
Outages reported by email and on status webpage

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
Single sign on SAML with access based on role. administrators of the console can have privileges set according to function
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
Yes
CSA STAR accreditation date
11-12-2018
CSA STAR certification level
Level 4: CSA C-STAR Assessment
What the CSA STAR doesn’t cover
Unknown
PCI certification
No
Other security certifications
Yes
Any other security certifications
  • GDPR Compliant
  • US/EU Privacy shield

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
CISO - Brian Jack. there are a large number of formal policies followed in the KnowBe4 data security strategy. including, incident response plan, build process automation, authentication, audits etc for further details: https://www.knowbe4.com/scurity

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes are approved, peer reviewed, tested and put onto staging environments. QA tests changes in staging and approved for production. changes deployed to production using Jira and GIT repositories
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Annual, quarterly and monthly security scans and reviews and testing. vulnerability scans, risk assessments and other configuration and security testing
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Centralized logging with alerts and dashboards. Anomaly detection and daily reviews
Incident management type
Supplier-defined controls
Incident management approach
Based on alerts, we investigate and follow our IR procedures. Notifications to customers within 48hrs.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Price
£190 to £899.75 a person a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Please contact us for a free trial. A 2 week trial is available with support.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tony.mason@s3-uk.com. Tell them what format you need. It will help if you say what assistive technology you use.