HERE'S WHY
Connecting your Curricula account will automate the evidence collection process when your personnel completes an assigned security awareness training.
BEFORE DIVING IN
Ensure to create your account and complete the setup for personnel and assignments.
Verify there is an assignment in your account with one of the following statuses before connecting to Drata: In-Progress, Completed, or Draft.
Data from deleted assignments cannot be imported to Drata.
Ensure that all personnel are enrolled in the correct Curricula assignments.
How Drata Determines Training Compliance
For each individual, Drata uses a combination of campaign selection, enrollment, and completion status to determine their respective training compliance.
Selection
Drata will only consider campaigns that are selected within the connection settings.
Example:
βCampaign A
βCampaign B
βCampaign C
Enrollment and Completion
Drata takes the selected campaigns and checks which individuals are enrolled. Each individual is required to complete all of their selected and enrolled campaigns.
If an individual is only enrolled in one selected campaign, this campaign will determine their complete compliance (superhero below). If they are enrolled in more than one campaign, then they will have to complete all of the campaigns to be considered compliant (astronaut and wizard below).
Example
| Campaign A | Campaign B | Campaign C |
Enrollment | π©βππ§ββοΈπ¦ΈββοΈ | π©βππ§ββοΈπ₯· | π©βππ§ββοΈπ¦ΈββοΈπ₯· |
Completion | π’ππ’ | π’π’π | π’ππ’π |
Drata Compliance:
Taking these items together, we have 4 representative individuals.
π©βπ This individual is enrolled in both selected campaigns and has completed both. They will be marked as compliant in Drata.
π§ββοΈ This individual is enrolled in both selected campaigns, but has only completed one. They will not be marked as compliant in Drata.
π¦ΈββοΈ This individual is only enrolled in one selected campaign and has completed it. They will be marked as compliant in Drata.
π₯· This individual is only enrolled in one selected campaign, but has not completed it. They will not be marked as compliant in Drata.
Note: While all 4 individuals are enrolled in Campaign C, it is not selected and is therefore ignored.
Character | Campaign A | Campaign B | Campaign C | Overall Status |
π©βπ | Enrolled: π’ | Enrolled: π’ | Not Selected | π’ 2 |
π§ββοΈ | Enrolled: π | Enrolled: π’ | Not Selected | π 1/2 |
π¦ΈββοΈ | Enrolled: π’ | Not Enrolled | Not Selected | π’ |
π₯· | Not Enrolled | Enrolled: π | Not Selected | π |
Persistence
Drata only syncs security awareness training for individuals who are not yet compliant.
Once an individual is marked compliant for security awareness training, Drata will stop syncing their status from Curricula. This ensures that changes in Curricula do not errantly overwrite that individualβs compliant status in Drata.
To reset one or more individual's security awareness, refer to this article.
Connect Curricula to Drata
Select Connections on the left navigation menu.
Select Available Tabs and search for "Curricula".
Select Connect.
After selecting the Connect your Curricula Account button, you will be prompted to log in to Curricula to accept the required request.
Once Drata has established a connection with Curricula, you will need to select all assignments you wish to apply to security awareness training.
For more detail on assignment logic, refer to the previous How Drata Determines Training Compliance section.
Expired token
Ensure that your token is not expired so that your Curricula connection stays connected. To learn more, refer to Curricula's documentation Token Expiration.
Verify Settings
After connecting your Curricula account to Drata, we will automatically set Curricula as your training provider in the Internal Security page.
To go to the Internal Security page, select your account from the bottom left navigation and select Settings. Then select Internal Security.
Employee Onboarding
Once connected, your personnel will see a Curricula branded screen during their onboarding, asking them to complete their training in Curricula.
We will update personnel activity every night and retrieve completion certificates for anyone that has completed the assigned security training.