Home Page | Previous Page |
What is Drata?
Drata is a security and compliance automation platform that continuously monitors your controls, collects evidence from your tech stack, and maps it to frameworks like SOC 2, ISO 27001, HIPAA, GDPR, and others to keep you audit-ready year-round.
Drata’s Evidence Library is the single place where all manual evidence (reports, screenshots, exports, tickets, PDFs, evidence docs, etc.) is stored, organized, and mapped to controls, policies, risks, and audits with renewal dates and ownership.
Why it matters to you
It gives you one central queue of evidence work—what you own today, what’s coming due, and what auditors will rely on you for.
It reduces rework by letting you reuse a single artifact across multiple controls/frameworks instead of hunting for or recreating the same proof many times.
It makes your contribution to audit success visible and trackable through tasks and renewal schedules, rather than hidden in inboxes and shared folders.
Drata’s Evidence Library is your centralized repository for:
All manual evidence: screenshots, reports, exports, tickets, PDFs, HR docs, etc.
Evidence linked to controls, policies, risks, and audits.
Evidence with associated renewal dates and tasks for future refreshes.
Your Primary Focus
Upload, maintain, and organize evidence artifacts for the controls / policies / risks you support.
Ensure evidence is current, complete, and correctly mapped, especially for “not automated” controls.
Respond to evidence renewal tasks and audit requests on time.
What You Can Do in Drata
As an Evidence Owner you can:
Upload new evidence artifacts into the Evidence Library and categorize them (type, owner, renewal date, related controls/frameworks).
Link existing evidence to multiple controls or frameworks where appropriate.
Respond to evidence renewal tasks (e.g., quarterly export from HRIS, MDM reports, manual screenshots).
Attach tickets (e.g., Jira) or other records as evidence where configured.
How to Access Drata
You’ll usually sign in via your company SSO (Okta/Azure AD/etc.) or using your normal work account and be taken into your organization’s Drata tenant and workspace(s).
Your internal Drata Admin / Security team controls your role assignment and which workspaces you can see.
Notifications
Under Settings → Notifications, strongly consider:
Evidence renewal tasks – to ensure you’re reminded when evidence must be refreshed.
Task reminders (upcoming and past-due tasks) – Drata sends weekly / bi-weekly emails for upcoming and overdue tasks when enabled.
Admin-configured company notifications may also send Slack/Teams summaries of tests with errors or controls not ready that indirectly drive evidence work.
Key First-Actions in Drata
Go to Evidence Library and filter by:
Owner = you or your team
Renewal date to see upcoming work.
Review any evidence renewal tasks in the Tasks module and plan collection windows with system owners.
For high‑impact controls that are not monitored, coordinate with Control Owners to:
Identify reliable manual evidence sources.
Agree on format (PDF, screenshot, export).
Set appropriate renewal frequencies.
