Solutions · By role

Cybersecurity and continuity frameworks, controls and evidence together.

This page is for the information security officer and the business continuity lead at a bank or credit union. The Cybersecurity group opens with the Cybersecurity landing. It shows the security and continuity frameworks your institution has enrolled and keeps in scope, the open findings tagged to them and the controls crosswalked to them with their test status. From the landing you generate the annual information security program report to the board and see the open security incidents with the notices still due. The security incident register and the business continuity register sit beneath it in the same group.

Job familyCybersecurity
Line of defenseSecond line
My work
Open
Cybersecurity
Open
Every other group
Folded
Families arrange the sidebar. Permissions decide what you see.
01 · Cybersecurity

What opens first.

My work comes first, then the groups below, and only those groups start open. The All sections switch brings back the full order. A job family only arranges the sidebar, and your permissions still decide which items you see.

  • 01Cybersecurity. Cybersecurity · Security incidents · Continuity (BCM)

The dashboard shows Needs your attention, Overdue & at-risk, Findings tracker and Framework health. Your role still caps that set, and a panel you do not get is left out rather than shown as a zero.

02 · Features and docs

Where the work lives.

The feature pages and documentation this family uses most.

03 · Approvals

What your role can approve.

A job family never grants a permission, and it never changes the price. What you can approve comes from your role, and people in this family usually hold one of the roles below.

  • 01Compliance Analyst. The Compliance Analyst role writes drafts, findings, risk, controls and third-party records, but it approves nothing.
  • 02Risk Approver. The Risk Approver role approves risk acceptances, control effectiveness, finding closures, policies, mappings and routing decisions. It does not hold the owner’s write set, settings or examiner grants.

Whatever the role, the person who submits a decision cannot approve it. The only exception is a decision that no one else in your institution can approve. The submitter may then approve it with a recorded justification, and that override is audited. See Roles and permissions for the full model.

See Zovos the way your role will.

Bring your controls, a policy, and the work this family owns. We target two-week onboarding.