Cybersecurity & Privacy
Cybersecurity and privacy workflows for security incidents, data breaches, privacy requests, access controls, vulnerability remediation, and privacy risk assessments.
Cybersecurity & Privacy Templates(6)
Vulnerability Remediation Workflow
Tracks a reported vulnerability from intake through validation, prioritisation, owner assignment, remediation planning or risk acceptance, fix verification, and closure. Applies a severity-based due date so overdue items can be escalated.
Privacy Impact Assessment Workflow
Enables a privacy team to intake initiatives involving personal information, screen them for privacy risk, conduct a full privacy impact assessment where required, obtain reviewer sign-off, record residual risk acceptance and treatment actions, close the assessment, and schedule a future reassessment.
Data Subject Access Request Workflow
Handles individuals' requests to access their personal information: captures identity details, request scope and contact preference; verifies identity; collects and redacts relevant records; routes the response through privacy review; delivers it securely; tracks the statutory deadline; and closes the request.
Data Breach Response Workflow
Manages the end-to-end privacy incident response process: intake of a suspected data breach report, responder investigation and impact assessment, legal/privacy review with a notification decision, remediation and required communications, and formal incident closure with corrective actions recorded.
Security Incident Response Workflow
Enables a security team to intake suspected cyber events, automatically classify severity, assign a responder to contain/investigate/eradicate the threat, escalate high-severity events, assess breach notification requirements, and record lessons learned before closing the incident.
Software Access Request Workflow
Employees request access to applications by specifying the user, application, access level, business justification, and whether privileged access is needed. The request goes through manager approval, then system owner approval, with an additional security review for privileged access requests. On full approval, access is provisioned, verified, and the user is notified. If rejected at any stage, the request is returned to the requester with the reason.
