Bitsight Third-Party Risk Management vs RSA Archer comparison

Cancel
You must select at least 2 products to compare!
BitSight Logo
2,392 views|1,767 comparisons
100% willing to recommend
RSA Logo
3,365 views|1,370 comparisons
92% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Bitsight Third-Party Risk Management and RSA Archer based on real PeerSpot user reviews.

Find out in this report how the two IT Vendor Risk Management solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Bitsight Third-Party Risk Management vs. RSA Archer Report (Updated: March 2024).
767,847 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"Its customer service team responds quickly.""I prefer BitSight due to its patch management capabilities. The score is a valuable feature. I have contacted the customer support through e-mail and their response rate is fast. I rate the solution a nine out of ten.""The product helps us identify the vulnerabilities of internet-facing applications.""The solution is user-friendly.""Offers open ports from an external point of view."

More Bitsight Third-Party Risk Management Pros →

"This solution helped us with the centralization of our governance data, so we could house all of our controls in one place. We could use that central repository of all our controls to build our risk management strategy and our policy and governance. So we could use controls as a central library and build policy, and then build risk management around it.""Enables development of any application, automation of any workflow including the GRC work processes.""The integrated data model of a one-to-many/many-to-one relationship is quite useful.""The solution has helped our organization manage our internal and external activities.""Archer seamlessly integrates data systems without requiring additional software.""I have found all the features to be valuable, including those involving reporting, the dashboard, notifications, email modules, the database and data input.""It has the best workload management features.""First of all, its access control feature where it provides application level access, solution level access, and even recall access, as well."

More RSA Archer Pros →

Cons
"Data enrichment is the major issue.""At the moment, when the vulnerability score decreases, it remains the same for quite a while, even though issues are resolved in 24 hours.""There may be room for improvement in the methodology for identifying findings, as occasional errors occur on the technical side.""The solution’s benchmarking should be improved.""Its factor analysis feature could be better."

More Bitsight Third-Party Risk Management Cons →

"The bullet chart is the best graph for my purposes, and it should be available for inclusion in the dashboards.""In a future release, there should be an option to upload the main data.""Archer could be improved by having more customization. I'm not sure if the backend processes have API calls and those kinds of seamless integrations, but from the front, some of the solutions are very out-of-the-box. It's not customizable, so that could be a little problematic since you have to use their features. In terms of the backend structure, I'm not too sure because I'm not a developer—I was an end user and product owner of Archer—and I don't quite know the backend and developmental features. But since it's an out-of-the-box solution, sometimes customization was challenging and support was a little problematic because we had to reach out to them all the time.""There is no inbuilt alert in Archer to let us know that a data feed has failed or did not run for different reasons. So, we don't even get to know that a feed has not run until somebody reports it to us. This has been a problem all the time. Data feeds have always been a big headache for us because there is no feature to let us know if a feed has not run or has failed. If Archer had a feature to send us an email notification when a feed has failed, it would've been very helpful. This is the reason why our users are slowly moving away to another platform. Some of the modules that I have been managing are being moved to ServiceNow. Next year, a lot of our modules will be moved from RSA Archer to ServiceNow, and the data feed issue has been one of the main reasons.""When we have to do formulas or some other type of calculation in Archer, it sometimes doesn't work correctly. The fields don't display right, and we have to contact RSA Archer support to fix things. I think the calculation components are a bit complicated.""RSA Archer's best features are advanced workflow, reports, dashboards, and notifications.""The first improvement I would suggest for RSA Archer is a better search feature. The search criteria needs to be improved. Sometimes I do a search and the search doesn't return the exact item I'm looking for. RSA Archer could also be improved by being more user-friendly. Maybe I have been using a limited version of RSA Archer, but I'm not sure whether it has ESG, environmental and social governance. In the next couple of years, ESG is the next feature that will be integrated into GRC tools. I would recommend RSA Archer adds ESG.""Slow turnaround time from support team."

More RSA Archer Cons →

Pricing and Cost Advice
  • "The solution's price is average."
  • "The product has a reasonable price."
  • More Bitsight Third-Party Risk Management Pricing and Cost Advice →

  • "The price of RSA Archer is good. The price isn't too high considering it is a leading tool in the market."
  • "As I am a developer and responsible for providing production support, I do not have personal knowledge of the pricing. However, my colleagues claim that it is very expensive in comparison with other tools."
  • "It is not expensive. It is reasonable. We only pay for the licensing."
  • "I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good."
  • "At the higher end of the price scale, but provides better, more accessible functionality and customization than cheaper products."
  • "Fairly highly-priced, especially for smaller companies."
  • "RSA Archer's price is justifiable and not as expensive, compared to ServiceNow. I have heard that the licensing for ServiceNow is much more expensive. I'm unaware whether there are any additional costs after licensing fees."
  • "The solution is not at all a cheap product."
  • More RSA Archer Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which IT Vendor Risk Management solutions are best for your needs.
    767,847 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The product is a little expensive and very oriented to large companies.
    Top Answer:We face difficulties in acquiring designs and findings. There may be room for improvement in the methodology for identifying findings, as occasional errors occur on the technical side of BitSight.
    Top Answer:It has various valuable features. For example, showing us if a control aligns with specific standards or frameworks helps us understand it better and verify its compliance.
    Top Answer:The user interface needs work. There are many small text boxes, like credit card size's boxes, where we need to input a lot of text. You can't see what you're typing beyond the tiny window, so you… more »
    Top Answer:We primarily use the system control module and specific IT control models for ongoing risk assessment activities. We use it on a day-to-day basis.
    Ranking
    Views
    2,392
    Comparisons
    1,767
    Reviews
    4
    Average Words per Review
    407
    Rating
    8.5
    Views
    3,365
    Comparisons
    1,370
    Reviews
    8
    Average Words per Review
    418
    Rating
    8.0
    Comparisons
    Also Known As
    Archer
    Learn More
    Overview

    BitSight transforms how organizations manage cyber risk. The BitSight Security Ratings Platform applies sophisticated algorithms, producing daily security ratings that range from 250 to 900, to help organizations manage their own security performance; mitigate third party risk; underwrite cyber insurance policies; conduct financial diligence; and assess aggregate risk. With over 2,100 global customers and the largest ecosystem of users and information, BitSight is the Standard in Security Ratings. For more information, please visit www.bitsight.com, read our blog or follow @BitSight on Twitter.

    RSA Archer is a solution designed to help your organization manage policies, controls, risks, assessments, and deficiencies across your lines of business. RSA helps you manage your digital risk with a range of capabilities and expertise including integrated risk management, threat detection and response, identity and access management, as well as fraud prevention.

    The solution also allows you to adapt a broad range of solutions to your requirements and is a good option for both big and small companies.

    RSA Archer Features

    RSA Archer has many valuable key features. Some of the most useful ones include:

    • Application builder
    • Advanced business workflow
    • System integration
    • Search, reports, and dashboards
    • Access control
    • Globalization
    • Audit management
    • Privacy program management
    • Security incident management

    RSA Archer Benefits

    There are many benefits to implementing RSA Archer. Some of the biggest advantages the solution offers include:

    • Taxonomy and data structure: With RSA Archer, you can build and maintain an inventory of personal data processing activities and assets, utilizing a purpose-built taxonomy and data structure.
    • Easy tracking: RSA Archer enables you to track data retention schedules and execute a checklist as it relates to processing activities.
    • Smooth management: By using RSA Archer, you can manage activities related to notifications and consents linked to the processing activity inventory.
    • Improve information assurance programs: RSA Archer enables agencies to improve information assurance programs for continuous monitoring and assessment and authorization.
    • Compliance: By providing compliance management, RSA Archer allows you to consolidate information from multiple regulatory bodies and establish a sustainable, repeatable, and auditable regulatory compliance program.
    • Business continuity: With RSA Archer, you can automate business continuity and disaster recovery planning to protect your organization in the event of a crisis.

    Reviews from Real Users

    Below are some reviews and helpful feedback written by PeerSpot users currently using the RSA Archer solution.

    A Specialist, RSA Archer at a tech services company, says, “RSA Archer is a valuable tool because it can manage the end-to-end functioning of any enterprise GRC module, such as compliance and risk management or business continuity plans and the entire BCM module. RSA Archer also provides many out-of-the-box solutions, which are use cases derived from the standards for GRC or risk management, governance, and compliance. It provides an end-to-end mechanism for business users on a single platform. That includes reporting, managing workflow, creating documentation, or tracking a process where you need to get approval from the various levels within the organization's hierarchy.”

    PeerSpot user Krishnendu S., Vice President at a financial services firm, mentions, "It is enterprise-wide accessible. So, it is very helpful for all the employees in our bank. They can log in and do their risk management activities. It has a few inbuilt modules that are helpful for doing risk management activities, such as issue management, risk identification, risk assessment, and policy exception management. It also has some inbuilt workflows inside these modules. They are also helpful."

    A Sr. Internal Auditor at an energy/utilities company comments, "Its user interface is pretty neat, and there is flexibility in generating the data. You can customize reports at any level. You can directly get reports in Tableau format. If you want to generate statistical data, you can create reports with graphs. There is an adequate amount of flexibility for changing the format, the type of graphs, etc."

    Another PeerSpot user, Manash B., Technology Manager at a tech services company, explains, "RSA is a very rich application. I like its adaptive suggestion, where based on your users and the class of data, it can actually recommend you the proper control to choose. For example, we have been using PCI DSS as an NIST. So based on application feedback, it will provide you with a suggestion on which control objective needs to be set. Based on that, you can make a decision—you don't need to take the suggestion, but you can customize that particular provided suggestion. RSA Archer's workflow is also good, in terms of process automation."

    Sample Customers
    Fannie Mae, Cabela's, BNP Paribas, PWC, AIR Worldwide, Con Edison, The Container Store, OshKosh, Steris, University of South Florida, Emblem Health, Lloyds Bank
    T-Systems, Bridge Point, Equifax, First Data, Global Imaging Company, Manulife Financial
    Top Industries
    VISITORS READING REVIEWS
    Financial Services Firm15%
    Computer Software Company14%
    Insurance Company9%
    Healthcare Company8%
    REVIEWERS
    Financial Services Firm35%
    Insurance Company10%
    Energy/Utilities Company10%
    Retailer10%
    VISITORS READING REVIEWS
    Educational Organization45%
    Financial Services Firm13%
    Computer Software Company6%
    Manufacturing Company4%
    Company Size
    VISITORS READING REVIEWS
    Small Business20%
    Midsize Enterprise17%
    Large Enterprise64%
    REVIEWERS
    Small Business24%
    Midsize Enterprise14%
    Large Enterprise62%
    VISITORS READING REVIEWS
    Small Business9%
    Midsize Enterprise49%
    Large Enterprise42%
    Buyer's Guide
    Bitsight Third-Party Risk Management vs. RSA Archer
    March 2024
    Find out what your peers are saying about Bitsight Third-Party Risk Management vs. RSA Archer and other solutions. Updated: March 2024.
    767,847 professionals have used our research since 2012.

    Bitsight Third-Party Risk Management is ranked 2nd in IT Vendor Risk Management with 5 reviews while RSA Archer is ranked 1st in IT Vendor Risk Management with 38 reviews. Bitsight Third-Party Risk Management is rated 8.6, while RSA Archer is rated 8.0. The top reviewer of Bitsight Third-Party Risk Management writes "User-friendly solution with robust patch management capabilities". On the other hand, the top reviewer of RSA Archer writes "A rich application with good workflow, but search feature needs improvement". Bitsight Third-Party Risk Management is most compared with SecurityScorecard, RiskRecon, Microsoft Secure Score, UpGuard Vendor Risk and Tenable Lumin, whereas RSA Archer is most compared with OneTrust GRC, IBM OpenPages, MetricStream, Workiva Wdesk and AuditBoard. See our Bitsight Third-Party Risk Management vs. RSA Archer report.

    See our list of best IT Vendor Risk Management vendors.

    We monitor all IT Vendor Risk Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.