CRISAM® Explorer Version 3.0
Press release August 2007
The new generation of CRISAM® Explorer offers you a great many new and powerful functions. The main new features concern multi-user capability, offline capabilities, integrated security and the integration of further meaningful reports on ISO 27001 as well as Sarbanes-Oxley.
Multi-user capability, multi-project capability
CRISAM® Explorer can now be used optionally in server mode or in single workstation mode as before.
In server mode, Microsoft SQL Server is supported from the version 2000.
Different CRISAM® projects can be managed at the same time on the server.
Offline capabilities
So that you can work wherever you want, a universal offline capability is also available in server mode. Synchronisation optionally takes place automatically in the background or manually, following activation by the user.
Integrated security
Authentication takes place via Microsoft Active Directory.
The server is accessed using standard Internet protocols (https) encrypted via a webservice.
The offline cache is likewise encrypted.
Improved interfaces
A universal webservice interface is available on the server for synchronisation with Business Process Management (BPM) systems or Configuration Management Databases (CMDB).
A first implementation of the interface is initially available for the innovative BPM solution by process4.biz.
New Excel export for measures is available.
New and improved reports
New compliance report ‘IT Control Objectives for Sarbanes-Oxley’: This report contains the evaluation for the COBIT Controls relevant to Sarbanes-Oxley.
New compliance report ‘ISO 27001:2005’: This report contains the evaluation of the relevant control goals from the CRISAM® ISMS catalogue in the structure of the norm.
New report ‘ISO 27001 Statement of Applicability (SOA)’: With this report, you get an out-of-the-box statement of applicability – a document required within the context of ISO 27001 certification.
New report ‘ISO 27001 Scope Document’: With this report, you get an out-of-the-box scope document – a document required within the context of ISO 27001 certification.
Improved report ‘IT Risk Analysis’: The criteria to be displayed (availability, confidentiality etc.) are dynamically selectable.


