Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
From various assets and countermeasures to factoids, personas, and architectural components, you can enter or upload a diverse array of data related to security, usability, and requirements to uncover valuable insights, including the links between requirements and risks as well as the rationale behind persona traits. Since no single perspective can encompass the complexity of a system, you can effortlessly create 12 distinct views of your developing design that examine aspects such as people, risks, requirements, architecture, and even geographical location. Additionally, as your preliminary design progresses, you can automatically produce threat models like Data Flow Diagrams (DFDs). Utilize open-source intelligence regarding potential threats and viable security architectures to assess your attack surface effectively. Furthermore, you can visualize all the security, usability, and design factors related to the risks associated with your product and how they interact with one another. This comprehensive approach ensures a thorough understanding of your system's vulnerabilities and strengths.
Description
IriusRisk is an open Threat Modeling platform that can be used by any development and operations team – even those without prior security training. Whether your organization follows a framework or not, we can work with all the threat modeling methodologies, such as STRIDE, TRIKE, OCTAVE and PASTA. We support organisations in financial services, insurance, industrial automation, healthcare, private sector and more.
IriusRisk is the industry's leading threat modeling and secure design solution in Application Security. With enterprise clients including Fortune 500 banks, payments, and technology providers, it empowers security and development teams to ensure applications have security built-in from the start - using its powerful threat modeling platform.
Whether teams are implementing threat modeling from scratch, or scaling-up their existing operations, the IriusRisk approach results in improved speed-to-market, collaboration across security and development teams, and the avoidance of costly security flaws.
API Access
Has API
No
API Access
Has API
Yes
Integrations
AWS CloudFormation
No
Amazon Web Services (AWS)
No
Azure DevOps
No
CA Flowdock
No
Cucumber
No
CucumberStudio
No
FortifyData
No
GitHub
No
JUnit
No
Jira
No
Integrations
AWS CloudFormation
Yes
Amazon Web Services (AWS)
Yes
Azure DevOps
Yes
CA Flowdock
Yes
Cucumber
Yes
CucumberStudio
Yes
FortifyData
Yes
GitHub
Yes
JUnit
Yes
Jira
Yes
Pricing Details
Free
Free Trial
No
Free Version
Yes
Pricing Details
Enterprise licences can vary depending on integrations and threat modeling requirements. Please do contact us for a more detailed breakdown. Pricing is done by threat model and not by user to keep costs manageable and predictable.
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
Yes
Live Rep (24/7)
Yes
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
Yes
In Person
Yes
Vendor Details
Company Name
CAIRIS
Website
cairis.org
Vendor Details
Company Name
IriusRisk
Country
Spain
Website
www.iriusrisk.com/
Product Features
Requirements Management
Automated Functional Sizing
No
Automated Requirements QA
No
Automated Test Generation
No
Automated Use Case Modeling
No
Change Management
No
Collaboration
No
History Tracking
No
Prioritization
No
Reporting
No
Status Reporting
No
Status Tracking
No
Summary Reports
No
Task Management
No
To-Do List
No
Traceability
No
User Defined Attributes
No
Product Features
Risk Management
Alerts/Notifications
Yes
Auditing
Yes
Business Process Control
Yes
Compliance Management
Yes
Corrective Actions (CAPA)
Yes
Dashboard
Yes
Exceptions Management
Yes
IT Risk Management
Yes
Internal Controls Management
Yes
Legal Risk Management
No
Mobile Access
No
Operational Risk Management
Yes
Predictive Analytics
Yes
Reputation Risk Management
No
Response Management
No
Risk Assessment
Yes