1 Triggers from across the platform
Classic ISMS triggers via answered question, overdue measure, high risk score and new record. Plus technical ones: correlated SIEM incident, new device, DNS change, port difference, outage, recovery, expiring certificate and two behaviour-analytics triggers.
2 Ten object areas as targets
A chain acts on checklists, audits, risk analyses, assets, data protection, tasks, notifications, incidents, licences or processing records instead of merely sending mail.
3 Four action types and real escalation
Create a measure, create a task, escalate or notify. Escalation policies work in stages, so a stalled case moves onward instead of quietly dying.
4 Traceable in an audit
An execution log records which rule fired when and why, and what came of it. Action templates keep the results consistent.