
Framework Information
Understand the compliance frameworks supported within Drata
General
Background information on compliance frameworks and their role in Drata.
- FrameworksDrata is expanding into multiple security frameworks, navigate to yours
- Marking Requirements In and Out of ScopeHow to scope framework requirements to match your environment.
- Framework ReadinessUnderstand how framework readiness is calculated and what you can do to keep your frameworks on track.
- Framework RequirementsView and manage a framework's requirements.
- HITRUST e1/i1 OverviewOverview of HITRUST
- NIS2 Update: What ENISA’s New Guidance Means for You!
- Level Picker for Frameworks with Tiered RequirementsHow to scope frameworks with tiered requirements
Custom Frameworks
Guidance on creating and managing custom frameworks.
ACSC Essential Eight
ACSC Essential Eight is a cybersecurity framework developed by the Australian Cyber Security Centre (ACSC) to help organizations protect themselves against common cyber threats.
APRA CPS 230
Resources and instructions for APRA (Australian Prudential Regulation Authority) CPS 230
- APRA CPS 230 OverviewOverview of APRA’s (Australian Prudential Regulation Authority) Prudential Standard CPS 230 Operational Risk Management.
- APRA CPS 230: Set Up Guidance (APRA-Regulated Entity vs. Material Service Provider)How to scope Drata’s CPS 230 framework to match your organization’s role.
- APRA CPS 230: A Requirement-Level Guide
- Example Evidence for Not Monitored Controls (CPS 230)
CIS 8.1
Resources and instructions for meeting CIS 8.1 requirements with Drata.
CCPA
Resources and instructions for meeting CCPA requirements with Drata.
CMMC
Resources and instructions for meeting CMMC requirements with Drata.
Cyber Essentials
Resources and instructions for meeting UK Cyber Essentials requirements with Drata.
DORA
Resources and instructions for meeting DORA requirements with Drata.
- DORA ICT Risk Management Framework (RMF)
- EU DORA Framework Overview
- DORA's Five Pillars of ComplianceThe Digital Operational Resilience Act (DORA) is an EU Regulation aimed at ensuring financial entities can withstand, respond to, and recover from information and communication technology (ICT) disruptions.
FedRAMP
Resources and instructions for meeting FedRAMP requirements with Drata.
GDPR
Resources and instructions for meeting GDPR requirements with Drata.
HIPAA
Resources and instructions for meeting HIPAA requirements with Drata.
ISO 27001
Resources and instructions for meeting ISO 27001 requirements with Drata.
- ISO 27001:2013 Example ISMS Plan
- ISO 27001:2022 Example ISMS Plan
- ISO 27001:2022What you need to know about the latest version of ISO 27001
- Security Engineering Principles
- Transition Guidance for ISO 27001:2013 to ISO 27001:2022
- Questions to ask a Potential ISO 27001 Certification Body (i.e. Auditor)
- ISO 27001 Certification Review Template
- ISO 27001 Background Check FAQs
- Example Evidence for Not Monitored Controls (ISO 27001) - Revised (Following 5/7/2024 Updates)
ISO 27701:2019
Resources and instructions for meeting ISO 27701 requirements with Drata.
ISO 42001
Resources and instructions for meeting ISO 42001 requirements with Drata.
Microsoft SSPA
Resources and instructions for meeting Microsoft SSPA requirements with Drata.
NIST SP 800-171 Rev. 2
Resources and instructions for meeting 800-171 requirements with Drata.
NIST SP 800-53
Resources and instructions for meeting NIST 800-53 requirements with Drata.
- PCI DSS v4.0
- Required Documentation for PCI DSS
- PCI DSS v4.0.1 Updates: What You Need to KnowThis article provides an overview of the updates in PCI DSS v4.0.1.
- PCI DSS v4.0.1 Targeted Risk Analysis (TRA)
- PCI DSS v4.0.1 ChecklistA checklist for achieving PCI DSS within Drata
- PCI DSS v4.0.1 Responsibility Matrix Guidance
- Example Evidence for Not Monitored Controls (PCI DSS v4.0.1 )
SOC 2 2017
Resources and instructions for meeting SOC 2 requirements with Drata.
- SOC 2 Trust Services Categories Overview
- SOC 2 Background Checks FAQs
- Questions to ask a potential SOC 2 auditor
- What to look for when reviewing your draft SOC 2 report
- SOC 2 System Description
- Reviewing Your Vendors' SOC 2 Reports Using Drata
- SOC 2 Type 1 vs Type 2: Which Audit Type Should I Choose
- SOC 2: All controlsTemplated controls pre-mapped to SOC 2 criteria spanning all 5 TSCs
- Set SOC 2 Trust Service Criteria to Security Only
- What Is a SOC 2 Bridge Letter? [+ Template]SOC 2 Bridge Letter Guidance and Template
- Example Evidence for Not Monitored Controls (SOC 2)Example Evidence for Not Monitored Controls (SOC 2)
- Evidence for SOC 2 Compliance: Managed Platforms and Application Configurations
