ASSOCIATED DRATA CONTROL
This test is part of the Security Policies control that ensures your company has approved security policies, and that all employees accept these procedures when hired. This control also checks to make sure that Management has reviewed and approved these policies and that they are made accessible to all employees and contractors.
WHAT TO DO IF A TEST FAILS
If Drata finds that your security policies have not been approved within the last 12 months the test will fail. With a failed test you will receive a list of policies that are passed the policy renewal date.
To remediate a failed test, you will need to notify the policy owner(s) and ask that they review, update the renewal date, and click 'Approve Policy' on those that are outdated.
STEPS TO REMEDIATE
Navigate to the Policy Center page
Ensure that the following policies have been uploaded and approved:
Acceptable Use Policy
Asset Management Policy
Backup Policy
Business Continuity Plan
Code of Conduct
Data Classification Policy
Data Deletion Policy
Data Protection Policy
Disaster Recovery Plan
Encryption Policy
Incident Response Plan
Information Security Policy
Password Policy
Physical Security Policy
Responsible Disclosure Policy
Risk Assessment Policy
Software Development Lifecycle Policy
System Access Control Policy
Vendor Management Policy
Vulnerability Management Policy
HELPFUL RESOURCES
Policy Renewal Date