ASSOCIATED DRATA CONTROL
This test is part of the Incident Response Team control that ensures your Incident Response Plan identifies a team responsible for quantifying and monitoring incidents involving security, availability, processing integrity, and confidentiality.
WHAT TO DO IF A TEST FAILS
If Drata finds that an Incident Response plan either does not exist or has not been approved within the last 12 months the test will fail.
To remediate a failed test, you will need to either upload or build the Incident Response plan within Drata or notify the owner to click 'Approve Policy' as soon as possible.
STEPS TO REMEDIATE
Navigate to the Policy Center page
Add an 'Incident Response Plan' and ensure that the newly added plan is approved
HELPFUL RESOURCES