Skip to main content

Frameworks

Drata is expanding into multiple security frameworks, navigate to yours

Updated over 2 weeks ago

The 'Frameworks' page allows you to navigate to the specific security framework you are working towards. Drata allows you to pursue or maintain multiple security frameworks without duplicating efforts.

BEFORE DIVING IN

Only Account Administrators and Information Security Leads have access to this section within Drata.

Frameworks page overview

On the 'Frameworks' page, you will select the particular framework you'd like to review or work towards. You can also enable, disable, and remove frameworks directly on that specific framework page, streamlining compliance management. Learn more at Custom Framework.

Drata currently supports two types of frameworks:

  1. Pre-mapped frameworks: Pre-mapped frameworks are mapped to DCF controls.

  2. Requirement-only frameworks: Requirement-only frameworks are not pre-mapped to DCF controls, however you can easily map them to any DCF control you already have or to custom controls.

Framework

Mapped Controls

CCPA

Pre-mapped

CCM

Pre-mapped

CIS 8.1

Pre-mapped

CMMC 2.0

Pre-mapped

COBIT

Requirements Only

Cyber Essentials

Pre-mapped

Cyber Essentials v3.2

Pre-mapped

DORA

Pre-mapped

Drata Essentials

Pre-mapped

FedRAMP

Pre-mapped

FFIEC

Requirements Only

GDPR

Pre-mapped

HIPAA

Pre-mapped

ISO 27001:2013

Pre-mapped

ISO 27001:2022

Pre-mapped

ISO 27017

  • ISO 27017 is add-on to ISO 27001 and can be audited as part of ISO 27001.

Pre-mapped

ISO 27017:2015

  • ISO 27017 is add-on to ISO 27001 and can be audited as part of ISO 27001.

Pre-mapped

ISO 27018

  • ISO 27018 is add on to ISO 27001 and can be audited as part of ISO 27001.

Pre-mapped

ISO 27701:2019

Pre-mapped

ISO 42001:2023

Pre-mapped

Microsoft SSPA

Requirements Only

NIS 2

Pre-mapped

NIST AI RMF

Pre-mapped

NIST CSF 2.0

Pre-mapped

NIST SP 800-171 Rev 2

Pre-mapped

NIST SP 800-171 Rev 3

Pre-mapped

NIST SP 800-53

Pre-mapped

PCI DSS v3.2.1

Pre-mapped

PCI DSS v4.0

Pre-mapped

SOC 2

Pre-mapped

SOX ITGC

Requirements Only

UK Cyber Essentials

Pre-mapped

Additional information

To learn more about framework requirements and mapping controls to requirements, go here.

If you'd like to learn more about expanding your usage of Drata to include SOC 2, ISO 27001:2013, ISO 27001:2022, ISO 42001:2023, DORA, HIPAA, PCI DSS, GDPR, CCPA, ISO 27701, Microsoft SSPA, NIST CSF, NIST 800-171, NIST 800-53, FFIEC, CMMC, SOX ITGC or COBIT, please contact your Customer Success Manager.

Did this answer your question?