ASSOCIATED DRATA CONTROL
This test is part of the Organizational Chart Maintained control that ensures your company performs an annual review of its organizational structure, reporting lines, authorities, and responsibilities in terms of information security.
WHAT TO DO IF A TEST FAILS
If Drata finds that your Org Chart is either older than 12 months or has not been uploaded to Drata the test will fail. Drata also provides notifications when the related test fails, prompting you to update the organizational chart. You can view the most recently uploaded chart with Drata. Additionally, uploading the organizational chart to the wrong location, such as directly to a control or the Evidence Library, will also cause the test to fail. If the test is disabled, you can link the org chart URL as evidence to meet the requirement.
To remediate a failed test, you will need to ensure that your latest Org Chart has been uploaded to Drata.
STEPS TO REMEDIATE
New Experience
Log in to Drata as an admin.
Go to Settings page > Personnel Compliance page > Human Resources tab.
Scroll down to Company org chart section to upload your file. If you have previously uploaded an org chart that is older than 12 months, delete the ORG chart before uploading the newer version. You can delete the ORG chart by select the trash icon.
Save your changes to ensure the new chart is properly stored.
Classic Experience
Log in to Drata as an admin.
Go to Settings > Human Resources page (account-settings/human-resources).
Select Browse under Company ORG Chart to upload the file. If you have previously uploaded an org chart that is older than 12 months, delete the ORG chart before uploading the newer version. You can delete the ORG chart by select the trash icon.
Save your changes to ensure the new chart is properly stored.


