GetApp offers objective, independent research and verified user reviews. We may earn a referral fee when you visit a vendor through our links. Learn more
Our commitment
Independent research methodology
GetApp’s researchers use a mix of verified reviews, independent research and objective methodologies to bring you selection and ranking information you can trust. While we may earn a referral fee when you visit a provider through our links or speak to an advisor, this has no influence on our research or methodology.
How GetApp verifies reviews
GetApp carefully verified over 2.5 million+ reviews to bring you authentic software and services experiences from real users. Our human moderators verify that reviewers are real people and that reviews are authentic. They use leading tech to analyze text quality and to detect plagiarism and generative AI.
How GetApp ensures transparency
GetApp lists all providers across its website—not just those that pay us—so that users can make informed purchase decisions. GetApp is free for users. Software and service providers pay us for sponsored profiles to receive web traffic and sales opportunities. Sponsored profiles include a link-out icon that takes users to the provider’s website.

Blue Lava

(0)
Write a Review!
Risk management and cybersecurity software

About Blue Lava

Blue Lava provides CISOs the ability to measure, optimize, and communicate the business value of security. Board and C-Suite reporting aligns security initiatives to business areas, coverage against frameworks such as NIST-CSF, risk-based prioritization, peer benchmarking, and target progress over time.

Blue Lava supports assessments aligned to multiple industry standards and best practices. NIST CSF assessments are available with pre-populated questions, requirement content, evidential matter recommendations for validation, and recommended actions for unmet requirements. Assessments can be scoped for full coverage or tailored to focus on specific areas of security before assigning to subject matter experts (SMEs) for completion. Clone features are available for quickly repeating security evaluations over time.

Blue Lava includes a proprietary framework called the Blue Lava cybersecurity maturity model (BL CMM) that natively maps to NIST CSF. This crosswalk provides a bridge to track program coverage against NIST while aligning the cybersecurity maturity of the program in a single assessment.

Additional pre-packaged content includes the cloud security alliance assessments for SaaS and IaaS, NIST 800-53 rev 5, HIPAA, and ISO 27001/2. Content for targeted activities such as mergers and acquisitions, geopolitical conflict preparedness, and the ability to create and import custom content for more targeted assessments are also available. Evidential proof can be linked to each question as a reference.

Reports, report templates, visualizations, and custom reports are available for all supported frameworks. This includes assessment progress, scores breakdown, peer benchmarking, alignment reports, and graphic visualizations of scores by disciplines and capabilities.

Blue Lava supports a cyber risk-based view of the organization by providing content and workflow for a pre-populated risk catalog of individual risk events based on the Verizon data breach report and aligning to the vocabulary for event recording and incident sharing (VERIS) framework. Assessment questions and framework requirements are mapped to the risk register items and weighted by relevance. Based on the assessments performed, a control design effectiveness score is calculated for each risk event. Security and risk professionals can define the inherent and residual risk posture based on the impact and likelihood of each risk item. The control design effectiveness and risk ratings, as well as risk heat maps, can be viewed on the risk dashboard, along with risk relevance and peer benchmarking for individual risk event items.

Post-assessment, findings are auto-created for unmet requirements. Recommendations for how to triage and manage findings by grouping them into projects are provided through pre-templated views grouped by maturity, common security themes, and risk prioritization. The simulation engine can then calculate potential outcomes for different groups of findings in order to plan projects and optimize the resources required based on priority, maturity, or framework coverage scores.

After triage, findings can be grouped into tactical projects for remediation. Integrations with ticketing tools, such as Jira Cloud, to bidirectionally manage the workflow through to closure are available. Projects can be grouped into higher-level strategic action plans composed of goals and initiatives tied to business objectives. The progress and status of each of the security program initiatives can be shared with stakeholders using roadmaps. This presentation-ready visualization allows CISOs to dynamically select different areas of the business, key initiatives, and attributes of that initiative to share with the board, their executive peers, business stakeholders, or members of the security team.


Images

Blue Lava Software - Board and C-Suite Reporting of progress over time
Blue Lava Software - Board and C-Suite Reporting of risk-based security prioritization
Blue Lava Software - Peer Benchmarking, Risk Exposure
Blue Lava Software - NIST CSF Assessment for Incident Reporting
View 5 more

Not sure about Blue Lava? Compare with a popular alternative Show more details

Blue Lava

0 (0)
VS.
Highly reviewed

Starting Price

No pricing found
No pricing found

Pricing Options

Free version
Free trial
Free version
Free trial

Features

18
65

Integrations

No integrations found
2

Ease of Use

0,0 (0)
4,8 (25)

Value for Money

0,0 (0)
4,9 (25)

Customer Service

0,0 (0)
4,7 (25)
Green rating bars show the winning product based on the average rating and number of reviews.

Alternatives

Show more details

ManageEngine Log360

4,7
#1 Alternative to Blue Lava
ManageEngine Log360 is a log management and SIEM (security information and event management) platform which helps...

Netwrix Auditor

4,5
#2 Alternative to Blue Lava
Gain control over what's going on in your hybrid cloud IT environment to protect data regardless of its location.

Splunk Enterprise

4,6
#3 Alternative to Blue Lava
Splunk Enterprise is a cloud-based platform designed to assist businesses with big data management and analysis of...

Feedzai

4,7
#4 Alternative to Blue Lava
Feedzai is a cloud-based risk management software that helps businesses leverage artificial intelligence (AI) technology...

Overall rating

0 /5
(0)
Value for Money
0/5
Features
0/5
Ease of Use
0/5
Customer Support
0/5

%
recommended this app

Filter by

0 Reviews

There are currently 0 user reviews for Blue Lava

Blue Lava FAQs

Below are some frequently asked questions for Blue Lava.

Blue Lava has the following typical customers:

51–200

Related categories

See all software categories found for Blue Lava.

powered by