Try our new research platform with insights from 80,000+ expert users
reviewer1715370 - PeerSpot reviewer
Project Manager, Consultant at a tech services company with 11-50 employees
Consultant
High ROI, user-friendly, and good licensing model for scalability
Pros and Cons
  • "From my perspective, because I've always done it as a consultant, I do like the way it is configured. They've gone into changing the application builder interface, so it is even easier. When you're working with users, it is really easy to show them how to do things quickly and how to configure, change, and design stuff quickly."
  • "Some of the error reporting isn't very clear. When you're looking for information on error codes, you got to do a lot of digging."

What is our primary use case?

It is used for enterprise risk audit, corporate compliance, and vulnerability reporting like threat management reporting. It is a whole suite that has different products depending on what you want to track and report on.

I do use the SaaS version, but I have also deployed it on-prem, and I also have experience with the original cloud version. The one that we deployed originally on the cloud was on AWS, but now they do everything on SaaS.

What is most valuable?

From my perspective, because I've always done it as a consultant, I do like the way it is configured. They've gone into changing the application builder interface, so it is even easier. When you're working with users, it is really easy to show them how to do things quickly and how to configure, change, and design stuff quickly.

What needs improvement?

Some of the error reporting isn't very clear. When you're looking for information on error codes, you got to do a lot of digging.

What do I think about the stability of the solution?

I've never seen any major issues.

Buyer's Guide
RSA Archer
January 2025
Learn what your peers think about RSA Archer. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

What do I think about the scalability of the solution?

Its scalability is very good. Because of the way they've set up their licensing, it's now very easy to scale, especially if you're using SaaS.

We have over 60,000 users across all departments. Some users just go to check the status. I would think it is being used extensively.

How are customer service and support?

It has changed over the last six months, and it is a little bit more challenging. When you have to report an error, you can't really find a lot of detail online. You have to open a case file, and then after opening a case file, it does take some time for resolution. From one to five, I'm going to rate them a 3.5.

How was the initial setup?

It is very straightforward. The documentation that they provide is clear in terms of the instructions that you have to follow through. It is very well documented. Most users and techs can follow it, even with very little experience.

For its deployment, usually, there are one or two people. You don't need more than that because it's a very easy product to upload. If you're doing it from scratch where you have absolutely nothing, it is about a half-day setup.

It requires very little maintenance. Their upgrade packages are pretty quick, and it is easy to do the upgrades. It is very user-friendly, and even if you have no tech background or you're a new Archer administrator, it is very easy to do.

What was our ROI?

Its ROI is quite high when you look at how long it takes for people to input stuff for compliance risk, vulnerability management, and threat management. The centralization of data allows you to get a pretty high return on your investment pretty quickly because it's really easy to implement. It doesn't take like a year. You can do it in less than two months, depending on the solution that you want to implement. The customization opportunities with reporting are also pretty high.

What's my experience with pricing, setup cost, and licensing?

I am not 100% familiar with that, especially with their new model. I just know that the way they've licensed per user to scale is good.

What other advice do I have?

I would advise others to know their requirements going in because there's so much flexibility with the product. You could over customize it just because it allows you to do so much, but sometimes too much of a good thing is not a good thing. If you know your requirements upfront, your road to success is short, but your return is high.

I would rate it a nine out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Real User
Good data integration and reporting, and responsive technical support
Pros and Cons
  • "One of the useful features is the ability to connect to various systems in order to accommodate data."
  • "I would like to see real-time data, from vulnerabilities, and threats."

What is most valuable?

The most valuable features of this solution are the Data integration, the different kinds of Data import, Data feeds, and the API. 

One of the useful features is the ability to connect to various systems in order to accommodate data.

Otherwise, all of our administrative functions, business apps, and application development are available, but this is the most important. 

It can integrate with other systems to get that data, as well as get data out of Archer and into other legacy systems.

Reporting is very good. You can have reports and IUs on your dashboard, as well as different types of IUs. 

Reporting is excellent for all types of aggregators, as well as for different types of integrators. That is one of the positive aspects.

What needs improvement?

I am not at the level to show someone how to improve whatever features they have. They are good if they work.

They are better now than previous versions. I am working on version 5, and they are now on version 6.9. They have made significant progress.

There should be an in-built feature that allows live data from vulnerabilities and threats from reliable sources to be streamed directly through their data field.

RSA can provide that kind of service, providing real-time data, vulnerability, and threats, without any local, asking for a contribution from someone else.

I would like to see real-time data, from vulnerabilities, and threats.

For how long have I used the solution?

I have been working with RSA Archer for 12 years.

What do I think about the stability of the solution?

RSA Archer is very stable.

The current versions are very stable.

Nothing is perfect, I would not give a rating of ten, but in terms of stability, I would rate it an eight out of ten.

What do I think about the scalability of the solution?

RSA Archer is scalable. The scalability is on various parameters. For user accounts, it is quite scalable.

I work with a large organization. We have 50,000 accounts.

How are customer service and support?

I have 12 years of experience in technical support. My job entails providing technical support for legacy systems as well as current systems. Archer, I work on both technical and functional support. In my case, I'm a CSA, CS, and Archer CISO candidate for all business applications.

Their technical support is good, they are very prompt.

Which solution did I use previously and why did I switch?

I have only ever worked with RSA Archer. I have not worked with other GRC systems, but I have seen other companies switch from other platforms to RSA Archer because it better met their needs.

How was the initial setup?

RSA Archer has been deployed both on-premises and in the cloud.

The cloud-based version is less painful for us.

The initial setup is straightforward. There are good manuals available. It is not that difficult. The configuration requires a person who has sufficient knowledge or experience.

Someone else should always have some experience on how to install it. The installation is simple, but the configuring is for the business requirements.

What's my experience with pricing, setup cost, and licensing?

I am not sure about other companies, but it's quite expensive.

What other advice do I have?

I would rate RSA Archer an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
RSA Archer
January 2025
Learn what your peers think about RSA Archer. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Security Specialist at a tech consulting company with 1-10 employees
Consultant
Configure security applications easily while retaining the capability to customize with and without coding
Pros and Cons
  • "The most valuable part of the product is the ease-of-use and the opportunity to create custom security applications easily."
  • "There are some issues with the interface for version 6.5 but these may already be repaired and simplified in the new versions that have been released."

What is our primary use case?

I am developing applications in Archer from RSA (Rivest, Shamir, and Adelman). It is quite easy to implement the application. You just configure the workflow, define the forms and how the data is processed in the application. Everything can be configured without coding. You can use a code also to create special functionalities, but it is easy to do almost everything without coding at all.  

How has it helped my organization?

It gives me the opportunity to create custom security applications easily.  

What is most valuable?

The most valuable part of the product is the ease-of-use.  

What needs improvement?

I am currently using an older version of the product so my installation is not current. There have already been two new versions of Archer released after the version I have. I use 6.5 and 6.6 and 6.7 have been released. These two are minor releases. They are not really affecting the inner workings of how to do tasks but improving certain features like the interface. When I am creating applications I like to have what I know is a stable and familiar version of the product, so I do not automatically upgrade to the newest versions available.  

Because I have not upgraded, the graphical user interface is not the current one. It is not very modern and as user-friendly as it could be. I heard that the new versions have improved the graphical interface very much in this respect, and it should no longer be a problem at all. So, for now, I have some issues with the interface for this version but it may already be repaired and simplified in the new versions that exist.  

One thing I might like added is the ability to record a workflow in another application. It is really a sort of very technical thing and it is possible to do it in other ways, but adding this to the product could really help with the simplification of creating new workflows. This could make it easier, to implement some technical things.  

For how long have I used the solution?

I have been using RSA Archer for one year.  

What do I think about the stability of the solution?

I have not experienced any problems with the stability of the product. It works as expected in accordance with the resources and feedback I received from my IT department. It can use a SQL server, a web server, or whatever I need. There is no problem with lag or overuse of resources on the server.  

What do I think about the scalability of the solution?

The product is flexible and scalable. The processes that are created with the product are going to be used by every manager in this company. That is a total of about forty to sixty people right now.  

As far as how extensively I will use RSA Archer in development, everything I develop is per request. When somebody requests functionality, I am the one responsible for implementing it. It is not really possible to predict how often or how many requests come in or how complicated they will be. Usually, I am using it at least a few days every month. But I may be asked to implement an application that the other employees may use daily.  

How are customer service and technical support?

I had a few problems initially understanding the sample they showed for the implementation. Once I contacted support they told me a few things to try and sent me links to additional documentation. When I read about it, I was able to easily resolve the issues I was having. When I was then also introduced to the community, I was able to continue to quickly solve any problems I had. There is a huge community of users that is quite active and can help other users to solve issues. It is great when others who have already solved similar problems in real life share their knowledge about how to solve those problems in your own environment.  

But in general, from my experiences, I would rate the support at RSA as very good.  

Another benefit is that — although there are many features already — you can propose new features directly to the company. There is a place in the user community to propose those features where they can be discussed. If they are popular features with users, they are implemented. So you can ask for anything and if you have an idea which is good — something which is required by others — it is usually implemented. I have recommended about four or five features that are in the process of being considered. It is a really good way for the company to guide their efforts in improving the product.  

Which solution did I use previously and why did I switch?

A similar product that we used before RSA Archer was LDRPS (Living Disaster Recovery Planning System). We had to move from LDRPS to the RSA product because LDRPS went to the cloud. The security requirements of our management and of our customers are generally that they do not want to have very critical information on the cloud. In some cases, they can not have it there at all. We have to use a tool that is possible to install on-premises. When we were evaluating solutions, I was testing several of the products. I chose RSA Archer because it met this requirement and other needs we had for flexibility.  

I chose RSA Archer because I was tasked to find a tool that could implement business continuity planning. Archer can implement more processes in many ways, so it not difficult to implement anything from incident management to business continuity, to change management. Anything somebody asks me to do, they provide the requirements and it is really easy to implement it in this. On top of that, it is easy to customize.  

So this is the reason why we chose Archer. It is easy to implement, it is easy to change the workflow, and it is easy to customize the processes.  

How was the initial setup?

Archer can be set up for use in very small environments and you can use one tool for several installations. It can be installed on several servers concurrently, so every server might be configured to have special features and styles and the instances of the installations cooperate together to provide the functionality of the tool. So the complexity of the setup depends on how large an environment you have. At this moment, I have experience only with very small environments, running the product on one computer. But the product also has great documentation. Just using the documentation alone I was able to install the product really easily and get it up and running on the one server.  

It took me a little more than one day to install. The deployment really depends on the use case. The use case is processing or the kind of process you are creating. For example, processing may need to analyze requirements supplied by customers. The more requirements and more processes you need in Archer the more complex the setup will be. Usually, it takes a few days to create a process. I would say on average that processes are implemented in five days. The options and features that the tool has are really quite vast. There are lots of features and every company only chooses to use some of them, which they license and use separately. It can be compared to something like Jira.  

What about the implementation team?

I did not have to consider using an outside vendor for the installation and I was able to complete the install by myself with the help of the documentation.  

Which other solutions did I evaluate?

Many tools that I tested had processes wired into the application without any option to change them. When I needed to fill requirements that differed even slightly from what was already implanted in the tool I would need to make a workaround or need to implement another tool. This would not have been the best way to go about what I would need to accomplish regularly.  

What other advice do I have?

For people considering this product, they have to be sure that it is a product that could really do what they need it to do. Mostly any workflow can be implemented in the process in the application if they want to build it. The best thing would probably be that they should just try it and see. I would definitely recommend this product, but it may not be the tool everyone likes the best.  

On a scale from one to ten where one is the worst and ten is the best, I would rate RSA Archer as a nine-out-of-ten.  

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Naresh Yarlagadda - PeerSpot reviewer
Technology Lead at Sun Life
Real User
Great advanced workflow, reports, and dashboards
Pros and Cons
  • "RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."
  • "RSA Archer's best features are advanced workflow, reports, dashboards, and notifications."

What is most valuable?

RSA Archer's best features are advanced workflow, reports, dashboards, and notifications.

What needs improvement?

There is some lag and instability with the platform when using the cloud version. I would also like the look and feel of the layout to be updated and made more customizable. 

For how long have I used the solution?

I've been using RSA Archer for eight to nine years.

What do I think about the scalability of the solution?

RSA Archer is scalable.

How are customer service and support?

RSA Archer's technical support is a little disappointing because the first level is always manned by junior members who don't have much technical expertise.

How would you rate customer service and support?

Neutral

How was the initial setup?

The initial setup was straightforward.

What other advice do I have?

I would give RSA Archer a rating of eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Manager in Risk Advisory at a consultancy with 10,001+ employees
Real User
Offers a high degree of automation with easy implementation
Pros and Cons
  • "Easy to implement with a high level of automation."
  • "The design and advanced workflow need to be improved."

What is our primary use case?

Our use cases for Archer include third-party management, enterprise risk management, and compliance management. We have a partnership with RSA Archer and I'm a manager in risk advisory.

What is most valuable?

Among the most valuable features of this solution is the easy implementation and the degree of automation that it offers. This product is very compatible with our business processes and the dashboarding features are creative. This is an easy tool to learn and to work on. They have a great community where you can ask any question and be sure to get some responses. 

What needs improvement?

Archer has evolved significantly over the last five to eight years, but there are still some areas that could be improved. We've noticed recently with the advanced workflow jobs that we're receiving some errors. It's a showstopper for us and it's clear that some kind of development support is needed. If there were an improvement in the design and the advanced workflow, jobs would run more smoothly, and a lot of value would be added to the business. Another aspect that could be improved is the UI which has a very old generation feel. For additional features, I'd very much like to see tools added in the next release. This could include a live connection that could be built in order to bring all the client data from the legacy system directly into Archer. Right now it's a data feed. There are currently some ActiveX options for live collections, but not for all the products. 

For how long have I used the solution?

I've been using this solution for five years. 

What do I think about the stability of the solution?

The solution is stable, it's a very mature product and if anything goes wrong we can provide the answers or the Archer community has the answers. We are currently having some problems with performance and our clients are complaining. The issues are with calculations and advanced workflows and it's creating a slow down in the system. We probably have around 5,000 users through our client companies.

What do I think about the scalability of the solution?

The solution is very scalable. The design approaches Archer provides are very easy to change and scale. In an agile project, it's very easy to handle or develop with most of the configurations based on drag and drop as per the document framework.

How are customer service and support?

Most of the issues we've had to escalate to RSA support belong to the advanced workflow section. These problems cannot be solved by Archer's UI and require back-end support or technical support from RSA. We're satisfied to a degree, it can take a few days to get a response. 

How was the initial setup?

The initial setup is straightforward, the complexity lies in the operations. The entire configuration project requires minimal manpower. Archer has a built-in wizard where you can either create a package and send it to the higher environment or just install the package. It doesn't take more than half a day. In the latest versions, we've seen that some of the features are not automatically deployed and manual checks are required. We're expecting to see that rectified in future versions. 

What's my experience with pricing, setup cost, and licensing?

The licensing is more expensive than other similar products and it often makes our clients step back and go for cheaper options. That said, the company is very clean and transparent in terms of pricing. There are no additional costs.

Which other solutions did I evaluate?

I have experience working with other GSU products and as a competitive analysis, I'd rate RSA's capability above that of other products. RSA Archer is more mature in terms of providing solutions. It's only when you compare the UI between solutions that Archer's competitors have an advantage. 

What other advice do I have?

This is an easy solution and it's very good for agile projects when requirements can change abruptly. The only concern we have is with the advanced workflow which should be simplified so that if any errors come up, it's easier to change or modify. I recommend checking the target environment for all the configuration areas, making sure that it has been properly deployed, and checking whether it needs some post-deployment checks.

I would rate the solution very high but because of the error messages we've been receiving which require technical support and cannot be fixed by the Archer UI or the Archer configuration interface, I have to bring the rating down. If they improve the UI, I'd rate them more highly. 

For now, I rate this solution eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Margareth Fabiola Dos Santos Carneiro - PeerSpot reviewer
Governance Coordinator at a government with 201-500 employees
Real User
Top 5Leaderboard
A scalable and flexible product that easily connects with other tools
Pros and Cons
  • "The product is very flexible."
  • "It would be useful for customers if COBIT 2019 could be translated into different languages."

What is our primary use case?

We use the product for policy management, vulnerabilities and risk management. We also use it for business continuity.

What is most valuable?

It is a good tool to use. The product is very flexible. It can easily connect to other tools like ServiceNow and Nexus. The workflow feature is very interesting. We can automate a lot of stuff using the workflow. The product makes it very easy to publish dashboards.

What needs improvement?

We are implementing COBIT 2019. It is in English. It would be useful for customers if COBIT 2019 could be translated into different languages.

What do I think about the scalability of the solution?

The product’s scalability is pretty good.

How was the initial setup?

The initial setup is not complex, but you need some knowledge of the methodologies in the market to implement the product. These methodologies are in English. We have to translate the methodologies to use in Brazil. It would be better if it were available in different languages.

What other advice do I have?

Overall, I rate the solution an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1721031 - PeerSpot reviewer
RSA archer at a engineering company with 10,001+ employees
Real User
Scalable, reliable, overall great functionality, and beneficial assessments, raise dispensation for application as well as other securty controls
Pros and Cons
  • "RSA Archer is a good tool and I have found performing the application, ISMS, and TPRM assessments beneficial."
  • "In a future release, there should be an option to upload the main data."

What is our primary use case?

We use RSA Archer in my organization for assessments (ISO, GDPR, PCIDSS, etc.) or to raise dispensation for any application, security-related controls.

How has it helped my organization?

If we want to perform the application assessment or any ISMS assessment, earlier, we had to do it manually. The RSA Archer tool gives us the output in an automated manner, it is beautiful and has helped our organization.

What is most valuable?

RSA Archer is the most usable GRC tool and leading tool and I have found performing the application, ISMS, and TPRM assessments beneficial.

What needs improvement?

In a future release, there should be an option to upload the main data.

For how long have I used the solution?

I used RSA Archer within the last 12 months.

What do I think about the stability of the solution?

Early on we faced lots of issues because the communicating with the RSA Archer, the database was not synced properly. Two times when we installed RSA Archer in an environment a few settings and configuration was not correct, this caused the passwords not to match.

The stability could improve.

What do I think about the scalability of the solution?

The scalability is easy to achieve.

Most of our clients are large businesses. I have plans to continue the usage of RSA Archer.

How are customer service and support?

The technical support is good, but they respond a little late, sometimes it can be a few days to have a response.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is a bit complex. The whole process can take approximately three hours with one or two people.

We have faced challenges. For example, the database is not synced with the RSA Archer. A few services were not running if the RSA Archer was logged in through local admin or the specific user, we have received few errors. 

What about the implementation team?

Archer is responsible for the maintenance of the solution.

What was our ROI?

The ROI depends on the company's needs as RSA has 7 solutions, the company can pay based on the subscription. 

What's my experience with pricing, setup cost, and licensing?

The solution's price should be reduced. You only have to pay the license and there are no additional fees.

Which other solutions did I evaluate?

I did not previously evaluate any other solutions.

What other advice do I have?

They have to use RSA Archer if they use the automated tools, their data will be safe.

Though there are some issues with the technicality of the solution, such as errors. The solution provides great features, such as customization, we can customize it as per our requirements.

I rate RSA Archer a ten out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Team Leader at a tech services company with 10,001+ employees
Real User
User-friendly, secure, and reasonably priced
Pros and Cons
  • "It is a very friendly tool. We can easily understand what is going on inside the tool. I like this tool. We can work with the tool for the ERP platform. We can create automated applications based on the requirements."
  • "There were so many problems that we had found. One time, the search index was not working. We also faced slowness in Archer, but I resolved this issue."

What is our primary use case?

I work with user management, policy management, enterprise management, risk management, and third-party management.

We are using its service version. We have to buy that license, and based on the license, they're providing us with the application.

What is most valuable?

It is a very friendly tool. We can easily understand what is going on inside the tool. I like this tool. We can work with the tool for the ERP platform. We can create automated applications based on the requirements.

It is very secure with three levels of access. We can give three levels of access in Archer. We can give access at the field level, application level, and code level. So, it is very secure.

What needs improvement?

There were so many problems that we had found. One time, the search index was not working. We also faced slowness in Archer, but I resolved this issue. The queue services were running on two servers, whereas they should have been running only on one server. There were also many duplicate records. I had to go and check the specific field and update that. After that, we removed all duplicate records from Archer.

What do I think about the stability of the solution?

We faced performance issues only in the lower version. The reason was that they were using only three servers and one database. We increased the services and RAM, and we had two application servers, three web servers, and one database. Whenever there are any performance issues, we need to check the jobs in the server backend. Sometimes, jobs are running for the last five days and that's why new jobs are not being picked up. In such cases, we have to prioritize the jobs that will go first and that will go second.

What do I think about the scalability of the solution?

It is easy to scale. If we want to increase the number of users in Archer, we have so many tools. We can create more than 1,000 users in Archer at one time. We only need a license. 

Currently, more than 30,000 users are using Archer. We plan to keep using this solution. It is being used by so many companies.

How are customer service and support?

When we face any issues related to the application, RSA is there immediately. We can raise a ticket and after that, they help us. Everything is fine in terms of support.

Which solution did I use previously and why did I switch?

Previously, they were storing the data in Excel sheets, but when they wanted to move to Archer, based on the requirements, I created the fields, and I created the workflow and access control for that.

I have worked on SAP ERP in my previous company. I started to work on Archer after I moved to this company.

How was the initial setup?

In our team, we have only three members. I am from India and two more people are from the US. Because our team size is very small, we have to perform every activity. We take care of the administrative work, development work, and support work. If anything happens in the system, we will check why it is happening and sort it out.

An application's deployment typically takes one month, but it will vary based on the requirement. If we are working on one application with more than 100 fields or critical workflows, it will take time. For fewer fields or workflows, we can create an application within a week, and we can move it to production.

What's my experience with pricing, setup cost, and licensing?

It is not expensive. It is reasonable. We only pay for the licensing.

What other advice do I have?

I would rate RSA Archer an eight out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free RSA Archer Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free RSA Archer Report and get advice and tips from experienced pros sharing their opinions.