ASSOCIATED DRATA CONTROL
This test is part of the Incident Response Plan control that ensures your company has an established Incident Response Policy. This policy should outline management responsibilities and procedures to ensure a quick, effective, and orderly response to information security incidents and annual testing.
WHAT TO DO IF A TEST FAILS
If Drata finds that an Incident Response plan either does not exist or if the renewal date on the policy has passed, the test will fail.
To remediate a failed test, you will need to either upload or build the Incident Response plan within Drata, set a renewal date that aligns with your compliance program goals, and notify the owner to click 'Approve Policy' as soon as possible.
STEPS TO REMEDIATE
Navigate to the Policy Center page
Add an 'Incident Response Plan' and ensure that the newly added plan is approved
Set a policy renewal date that aligns with your compliance program goals. Many frameworks require that policies are reviewed/approved annually
HELPFUL RESOURCES