Release Notes - 2022-NOV-18
Added
Issues and remediation
The Issues and Remediation feature is now available for all customers!
Enhanced the issues grid with proof, tasks, and affected objects columns.
Added support for filtering issues by program, audit, or source type (i.e. where the issue was created: audit, program, etc).
See Work items: Issues for more information.
Rich text edit
The rich text editor is now available for all customers!
Customers can now use this feature in the following areas of Hyperproof: task descriptions, Program details > description field, Control details tab > description field, and Control notes field, as well as Requirement details fields applicable to CMMC, NIST 800-53, and FedRAMP. A WYSIWYG editor is now available and Markdown is now supported.
Exporting rich text fields to Microsoft Word DOCX files (program reports) or to Microsoft Excel files (grid reports) now preserves the rich text formatting.
Hypersync shared connections
Users can now share Hypersync connections with other users!
This feature is intended to make it easier for companies to set up Hypersyncs. For example, instead of asking the VP of Engineering for AWS credentials, a Compliance Manager can ask the VP of Engineering to create an AWS connection and then share it with them. This process ensures that the Compliance Manager never has access to AWS except via Hyperproof.
Users can be added to the shared connection via a new facepile. Members of the shared connection are shown in the relevant service app’s place card as well as in Settings > Shared connections.
Two roles are supported: Manager and Viewer. The only permission Viewers have is to create a Hypersync via the shared connection. Managers can add members to the connection, change member roles, and create Hypersyncs.
See, Connecting apps for more information.
Improved
Risk
Added support for individual risk permissions. Users can now be added to an individual risk via the new risk facepile without being added to the entire Risk Register. Users will only see the risks that they are explicitly added to.
Rationale can now be edited from the list view while editing Impact and Likelihood.
Control-based assessments
Control assessments now have a fully working dashboard.
Evaluation activities now show activity from the object being evaluated.
This feature remains in Managed Rollout (MRO).
Notifications
Users now have more control over when they receive notifications!
When a task is linked to a Jira or Asana issue, Hyperproof now sends fewer notifications since Jira and Asana send their own notifications.
In Settings > Notifications, task creators can now turn on a notification for when their tasks are past due, i.e. the assignee hasn’t completed it by the due date.
Hypersyncs and integrations
New Hypersync: Snowflake. Users can collect proof based on the following proof types: List of Users and Get View (a generic query proof; views are defined within the Snowflake user interface).
Updated Hypersync: Google Cloud Platform. The Compute Engine Service has three new proof types: Minimum TLS Version, Firewall Info, and List of Instance Groups.
Added support for new folder sync: SharePoint, OneDrive, and OneDrive for Business.
The Jira Server task integration now supports personal access tokens, allowing users to use Hyperproof’s Jira integrations in instances where basic auth has been turned off by Jira administrators. Note that personal access tokens will be supported in the Jira Server Hypersync in the near future.
Addressed issues
Hyperproof’s Okta SSO integration is now available in the Okta marketplace. Customers can add Hyperproof directly from the marketplace, making configuration much easier.
Users can now create a new questionnaire directly from within Hyperproof—no import required! Custom fields can now be attached to general settings. This adds the custom field to Settings > General on a per-organization basis.
Fixed an issue where the issues grid had a limit of 100 issues. Now all issues are listed.
Fixed an issue with issues and remediation where the Affected objects list includes archived objects.
Fixed an issue with the Risk Register where bulk edit of Tolerance sometimes failed.
Fixed an issue where, in some cases, the audit and assessment cards (i.e. the top-level Audits tab) showed 0 requests or evaluations closed when actually many were closed.
Fixed an issue where automated control testing (ACT) didn’t show the correct row that caused the test to fail.
Fixed bugs in the link back feature where users sometimes encountered an error.
Fixed an issue with requirement grid filtering, where Show only requirements without controls was not displaying the correct set.