お知らせ • May 13
Rapid7 Launches Cyber Governance, Risk, and Compliance (GRC) Early Access Program to Unify Security Data, Risk Context, and Compliance Workflows
Rapid7, Inc. announced early access to its Cyber Governance, Risk, and Compliance (GRC) program, designed to unify security operations with governance, risk, and compliance workflows. Built on the Rapid7Command Platform, Cyber GRC uses real time exposure data as the operating foundation for both security and compliance; aligning controls, evidence, and risk decisions to live threats rather than static frameworks to help customers manage their GRC requirements. Regulatory requirements are expanding across jurisdictions and frameworks, while cyber risk continues to scale in complexity. Most compliance processes remain point-in-time and disconnected from live security operations, reinforcing reactive models that lag behind how risk develops. Rapid7’s Cyber GRC program replaces reactive compliance with a unified model for risk and controls. By combining AI-driven third-party risk management with a live, threat-aware risk register, it integrates GRC into security operations to provide executives with transparent, data-backed visibility. Rapid7 is building an ecosystem of audit, assurance, and GRC partners on the Command Platform to support continuous assurance: HITRUST: Provides the industry’s most rigorous, certifiable assurance, enabling organizations to demonstrate proven, defensible security and risk management aligned to recognized standards and requirements. Insight Assurance: A trusted independent assessor, delivering rigorous, technology-enabled assessments across SOC 2, ISO 27001/42001, HITRUST, CMMC and other frameworks It is focused on validating control effectiveness for organizations looking to simplify compliance. 360 Advanced: Delivers integrated compliance solutions to a global client base across industries ranging from technology startups to Fortune 500 organizations, with cybersecurity and compliance offerings that include ISO 27001, FedRAMP, HITRUST, SOC, penetration testing, risk assessments, and more. 360 Advanced operates under an alternative practice structure in accordance with all applicable laws, regulations, standards, and codes of conduct of the AICPA. In addition, Rapid7 is extending capabilities that support continuous control monitoring, evidence collection, and audit workflows, including: HITRUST e1, i1, and r2 Control Coverage: Continuously updated dashboards and queries monitor HITRUST controls, automate evidence collection, and detect control drift to support certification readiness. Audit-Ready User Access Exports: Self-service export provides a consolidated view of users, groups, roles, and access data to support access reviews and compliance audits. Unified Policy Bulk Export: Standardized bulk export consolidates agent and scan policy data into a single output to simplify policy reporting and support compliance workflows. VM Export MCP Server & Skill: Enables customers and agents to retrieve Rapid7 data for compliance, vulnerability management operations, and reporting in a highly efficient way. The Cyber GRC Program is currently available for early access, with broader availability planned for later in 2026.