Skip to main content
All CollectionsControl Tests
Test: Internal Password Policy for Employees
Test: Internal Password Policy for Employees

Drata inspects your company records to determine if a Password Policy is in place and is before the policy renewal date.

Ashley Hyman avatar
Written by Ashley Hyman
Updated over a week ago

ASSOCIATED DRATA CONTROL

This test is part of the Password Policy control that ensures your company has established formal guidelines for passwords to govern the management and use of authentication mechanisms.

WHAT TO DO IF A TEST FAILS

If Drata finds that a Password Policy either does not exist or has not been approved within the last 12 months the test will fail.

To remediate a failed test, you will need to either upload or build a Password Policy within Drata, set a renewal date that aligns with your compliance program goals, and notify the owner to click 'Approve Policy' as soon as possible.

STEPS TO REMEDIATE

  1. Navigate to the Policy Center page

  2. Add a 'Password Policy' and ensure that the newly added policy is approved

  3. Set a renewal date that aligns with your compliance program goals. Many frameworks require policy review/approval annually

HELPFUL RESOURCES

Did this answer your question?