Skip to main content
All CollectionsControl Tests
Test: Incident Response Plan (IRP)
Test: Incident Response Plan (IRP)

Drata inspects your company records to determine if an Incident Response Plan is in place and is before the policy renewal date.

Ashley Hyman avatar
Written by Ashley Hyman
Updated over a week ago

ASSOCIATED DRATA CONTROL

This test is part of the Incident Response Plan control that ensures your company has an established Incident Response Policy. This policy should outline management responsibilities and procedures to ensure a quick, effective, and orderly response to information security incidents and annual testing.

WHAT TO DO IF A TEST FAILS

If Drata finds that an Incident Response plan either does not exist or if the renewal date on the policy has passed, the test will fail.

To remediate a failed test, you will need to either upload or build the Incident Response plan within Drata, set a renewal date that aligns with your compliance program goals, and notify the owner to click 'Approve Policy' as soon as possible.

STEPS TO REMEDIATE

  1. Navigate to the Policy Center page

  2. Add an 'Incident Response Plan' and ensure that the newly added plan is approved

  3. Set a policy renewal date that aligns with your compliance program goals. Many frameworks require that policies are reviewed/approved annually

HELPFUL RESOURCES

Did this answer your question?