# Drata Help Center > Drata Help Center ## Getting Started - [Section 1: Drata Rollout Toolkit Overview](https://help.drata.com/en/articles/14491558-section-1-drata-rollout-toolkit-overview.md): A Champion's Guide to Successful Implementation - [Section 2: GRC Roles & Responsibilities](https://help.drata.com/en/articles/14492321-section-2-grc-roles-responsibilities.md): How to identify who owns what across every function — and how to brief your executive sponsor and core team - [Section 3: Change Management Guide](https://help.drata.com/en/articles/14604051-section-3-change-management-guide.md): Learn more about ADKAR framework, stakeholder messaging strategies, and communication best practices - [Section 4: Team Briefs & Email Templates](https://help.drata.com/en/articles/14604084-section-4-team-briefs-email-templates.md): Access our ready-to-customize collateral for Execs, GRC, IT, Engineering, HR, Sales, and General Staff. - [Section 5: Control Owners](https://help.drata.com/en/articles/14670605-section-5-control-owners.md): Collaborator Resources for our control owners who are driving Continuous Compliance - [Section 5: Policy Owners](https://help.drata.com/en/articles/14670610-section-5-policy-owners.md): Collaborator Resources for policy owners - [Section 5: Evidence Owners](https://help.drata.com/en/articles/14670617-section-5-evidence-owners.md): Collaborator Resources for users responsible for uploading and maintaining manual / non-automated evidence - [Section 5: Drata for Auditors](https://help.drata.com/en/articles/14670641-section-5-drata-for-auditors.md) - [Section 6: Implementation Roadmap + Success Metrics](https://help.drata.com/en/articles/14605081-section-6-implementation-roadmap-success-metrics.md) - [Section 7: Common Adoption Blockers Guide](https://help.drata.com/en/articles/14696472-section-7-common-adoption-blockers-guide.md): Overcoming Common Adoption Challenges: A Guide for Drata Champions - [Section 8: Key Resources](https://help.drata.com/en/articles/14605174-section-8-key-resources.md) - [Welcome to Drata](https://help.drata.com/en/articles/9941251-welcome-to-drata.md): Overview of what to expect and how to get started. - [Introducing the New Drata Experience](https://help.drata.com/en/articles/12440551-introducing-the-new-drata-experience.md): Drata has launched a unified experience that streamlines compliance workflows, improves usability, and scales with your team’s needs. - [Getting Started with Drata: Key Resources](https://help.drata.com/en/articles/8737254-getting-started-with-drata-key-resources.md): Essential resources to launch your compliance program. - [How to Access the New Drata Experience](https://help.drata.com/en/articles/13680441-how-to-access-the-new-drata-experience.md) - [Navigation Changes: Where Did Everything Go?](https://help.drata.com/en/articles/13680507-navigation-changes-where-did-everything-go.md) - [My Drata Overview: Complete Your Personal Compliance Tasks \(New Experience\)](https://help.drata.com/en/articles/13442440-my-drata-overview-complete-your-personal-compliance-tasks-new-experience.md) - [Navigate the Drata Help Center](https://help.drata.com/en/articles/12622412-navigate-the-drata-help-center.md): How to find guides and support articles. - [Access Drata as an auditor \(New Experience\)](https://help.drata.com/en/articles/13879709-access-drata-as-an-auditor-new-experience.md) - [Signing In to Drata \(New Experience\)](https://help.drata.com/en/articles/13801611-signing-in-to-drata-new-experience.md) - [Supported Internet Browsers](https://help.drata.com/en/articles/4686267-supported-internet-browsers.md): Recommended browsers for optimal performance. - [How to Allowlist Drata Email Domains and IP Addresses](https://help.drata.com/en/articles/12341144-how-to-allowlist-drata-email-domains-and-ip-addresses.md): Ensure Drata emails and traffic are not blocked. - [Compliance Program Migration Best Practices](https://help.drata.com/en/articles/10371583-compliance-program-migration-best-practices.md): Structured steps for migrating to Drata. - [Using AI Features in Drata](https://help.drata.com/en/articles/8854072-using-ai-features-in-drata.md): Overview of AI-powered capabilities. - [Working with an MSSP \(Managed Security Service Provider\)](https://help.drata.com/en/articles/10771929-working-with-an-mssp-managed-security-service-provider.md): Guidance for customers working with an MSSP. - [The JSON Web Token \(JWT\) Security Standard](https://help.drata.com/en/articles/5105350-the-json-web-token-jwt-security-standard.md) - [SafeBase Acquisition](https://help.drata.com/en/articles/10524109-safebase-acquisition.md) - [Getting Started with the Drata Academy](https://help.drata.com/en/articles/15437735-getting-started-with-the-drata-academy.md): Learn what Drata Academy is, who can use it, what you need before you begin, and how to access courses and live training. - [Use Markdown formatting in supported text areas](https://help.drata.com/en/articles/15170455-use-markdown-formatting-in-supported-text-areas.md): Markdown helps you add simple formatting to text so your content is easier to read and organize. - [Get support from Drata](https://help.drata.com/en/articles/13604132-get-support-from-drata.md): Contact support and review assistance options. - [Observed Holidays](https://help.drata.com/en/articles/14051779-observed-holidays.md) - [Drata Support: Conversations vs. Tickets](https://help.drata.com/en/articles/15526207-drata-support-conversations-vs-tickets.md): What happens when you contact Support in-app, when a request becomes a ticket, and where to track follow-up. - [Grant remote access to Drata Support](https://help.drata.com/en/articles/13604233-grant-remote-access-to-drata-support.md): Allow temporary access for troubleshooting. - [Submitting a Feature Request](https://help.drata.com/en/articles/15184119-submitting-a-feature-request.md) - [Introducing the updated Multi-instance Management Portal](https://help.drata.com/en/articles/13756061-introducing-the-updated-multi-instance-management-portal.md) - [MIM Dashboard](https://help.drata.com/en/articles/9677750-mim-dashboard.md): View compliance health metrics for all the accounts that you manage. - [Workspaces: Multiple product support](https://help.drata.com/en/articles/13604282-workspaces-multiple-product-support.md): Learn how to use Workspaces in the new Drata experience to manage multiple products with shared operations and separate compliance needs. - [Workspaces: Create and manage tickets in Drata](https://help.drata.com/en/articles/13756148-workspaces-create-and-manage-tickets-in-drata.md) - [Map control information and evidence across Workspaces](https://help.drata.com/en/articles/13604414-map-control-information-and-evidence-across-workspaces.md): Learn how to map control info, policies, and evidence across Workspaces and manage shared controls efficiently. - [Events: Workspace-aware events](https://help.drata.com/en/articles/13604533-events-workspace-aware-events.md) - [Manage workspace details \(New Experience\)](https://help.drata.com/en/articles/13567122-manage-workspace-details-new-experience.md): Update workspace URLs, frameworks, and managers. ## Understand the Drata Platform - [Training Video: Vendor Management Overview \(New Experience\)](https://help.drata.com/en/articles/14628472-training-video-vendor-management-overview-new-experience.md): Explore Third-Party Risk Management and adding current vendors to Drata in this training video. - [Training Video: Optimizing TPRM Through Vendor Settings \(New Experience\)](https://help.drata.com/en/articles/16889375-training-video-optimizing-tprm-through-vendor-settings-new-experience.md): Configure settings that shape vendor types, vendor risk levels, vendor inherent-risk classification. - [Training Videos: Review and Custom Vendor Criteria \(New Experience\)](https://help.drata.com/en/articles/14668066-training-videos-review-and-custom-vendor-criteria-new-experience.md): Learn how to review and customize AI-driven vendor assessment criteria. - [Training Videos: Add Prospective and Existing Vendors to Drata \(New Experience\)](https://help.drata.com/en/articles/16889540-training-videos-add-prospective-and-existing-vendors-to-drata-new-experience.md): Learn how to add prospective vendors to Drata, as well as existing vendors through connections, CSV, API, or manual entry. - [Training Video: Conducting an End-to-End Vendor Review with the Drata TPRM Agent \(New Experience\)](https://help.drata.com/en/articles/16875282-training-video-conducting-an-end-to-end-vendor-review-with-the-drata-tprm-agent-new-experience.md): Learn how to leverage the TPRM agent to collect documentation, assess vendors, and finalize review decisions. - [Drata Platform Overview Training Video \(New Experience\)](https://help.drata.com/en/articles/15073390-drata-platform-overview-training-video-new-experience.md): Learn Drata’s core compliance workflows and audit readiness basics in this platform overview training video. - [Drata Connections Training Video \(New Experience\)](https://help.drata.com/en/articles/13795856-drata-connections-training-video-new-experience.md): Learn how connections power automation and continuous compliance in Drata. - [Policy Management in Drata Training Video \(New Experience\)](https://help.drata.com/en/articles/13802573-policy-management-in-drata-training-video-new-experience.md): Explore how to build, publish, and manage policies in Drata, including setting up approval workflows. - [Managing Personnel Compliance in Drata Training Video \(New Experience\)](https://help.drata.com/en/articles/13798419-managing-personnel-compliance-in-drata-training-video-new-experience.md): Learn how to navigate the Personnel page, manage personnel compliance, and create personnel exclusions. - [Frameworks in Drata: Understanding Requirements and Control Readiness Training Video \(New Experience\)](https://help.drata.com/en/articles/13796037-frameworks-in-drata-understanding-requirements-and-control-readiness-training-video-new-experience.md): Learn how frameworks, requirements, and controls work together in Drata. - [Drata Controls \(DCFs\) Training Video \(New Experience\)](https://help.drata.com/en/articles/13795532-drata-controls-dcfs-training-video-new-experience.md): Learn how to manage, monitor, and remediate controls in Drata. - [Understanding Monitoring in Drata Training Video \(New Experience\)](https://help.drata.com/en/articles/13795706-understanding-monitoring-in-drata-training-video-new-experience.md): Learn how to navigate Drata's Monitoring page to help you understand tests and test results. - [Managing Evidence in Drata Training Video \(New Experience\)](https://help.drata.com/en/articles/13795912-managing-evidence-in-drata-training-video-new-experience.md): Understand how to navigate the evidence page and manage evidence in Drata to maintain continuous compliance. - [Risk Insights Training Video \(New Experience\)](https://help.drata.com/en/articles/14361514-risk-insights-training-video-new-experience.md): Learn how to visualize risk data in this comprehensive training video. - [Risk Management Training Videos \(New Experience\)](https://help.drata.com/en/articles/14365955-risk-management-training-videos-new-experience.md): Master risk management in Drata with our three-part training video series. - [Creating and Navigating an Audit in Drata Training Video](https://help.drata.com/en/articles/15521368-creating-and-navigating-an-audit-in-drata-training-video.md): Learn how to create an audit in Drata, invite your auditor, and manage requests, evidence, and communication throughout the audit process. - [SafeBase Trust Center Branding and URL Setup Training Video](https://help.drata.com/en/articles/16153617-safebase-trust-center-branding-and-url-setup-training-video.md): Learn how to customize Trust Center branding, legal links, email settings, and custom URLs. - [SafeBase Integrations Training Video](https://help.drata.com/en/articles/16153643-safebase-integrations-training-video.md): Learn how to access and configure SafeBase integrations, API keys, partners, SSO, and SCIM settings. - [SafeBase Trust Library Documents Training Video](https://help.drata.com/en/articles/16153648-safebase-trust-library-documents-training-video.md): Learn how to upload, configure, manage, and replace documents. - [SafeBase Trust Library Knowledge Base Management Training Video](https://help.drata.com/en/articles/16153656-safebase-trust-library-knowledge-base-management-training-video.md): Learn how to manage, review, and govern reusable questions and answers in SafeBase’s Trust Library Knowledge Base. - [SafeBase Trust Center Access Levels Training Video](https://help.drata.com/en/articles/16153632-safebase-trust-center-access-levels-training-video.md): Learn how to configure Trust Center access settings to control content visibility for public, approved, and permission-based users. - [SafeBase Trust Center NDA Set up Training Video](https://help.drata.com/en/articles/16153625-safebase-trust-center-nda-set-up-training-video.md): Learn how to configure Clickwrap, DocuSign, Ironclad, default NDA settings, and NDA bypass options. - [Drata Connections](https://help.drata.com/en/articles/8508190-drata-connections.md): This training videos walks you through Drata’s Connections feature, showing how integrating your systems powers automation and continuous compliance. - [Drata Personnel Overview](https://help.drata.com/en/articles/8508192-drata-personnel-overview.md): Explore Drata’s Personnel feature in this training video series to streamline personnel compliance and employee onboarding. - [Drata Policy Center](https://help.drata.com/en/articles/8508194-drata-policy-center.md): Watch videos on how to build, publish, and manage policies in Drata’s Policy Center, including setting up approval workflows. - [Drata Controls](https://help.drata.com/en/articles/8532440-drata-controls.md) - [Drata Risk Assessment](https://help.drata.com/en/articles/10194103-drata-risk-assessment.md): This 3-part tutorial series will help you get started with Drata's Risk Assessment module. - [Connect your Google Workspace IdP to Drata](https://help.drata.com/en/articles/10207574-connect-your-google-workspace-idp-to-drata.md): In this article, we explain the concepts to consider and demonstrate how to connect your Google Workspace IdP to Drata - [Introduction to the Drata Platform](https://help.drata.com/en/articles/10223494-introduction-to-the-drata-platform.md): In this article, you'll get an overview of the Drata platform and its key features. - [GRC Before and After Automation](https://help.drata.com/en/articles/10275690-grc-before-and-after-automation.md): This short video describes the benefits of Drata Automation vs Manual GRC strategies - [GRC Gap Analysis](https://help.drata.com/en/articles/10282916-grc-gap-analysis.md): This video describes the considerations for performing a GRC Gap Analysis - [Getting Started with SOC 2](https://help.drata.com/en/articles/10283617-getting-started-with-soc-2.md): In this video we provide an overview of how to get started with your SOC 2 Compliance journey. - [Monitoring Video Tutorial](https://help.drata.com/en/articles/10318262-monitoring-video-tutorial.md): This video will walk you through an overview of Drata's Monitoring page and help you understand tests and test results. - [Evidence Library Video Tutorial](https://help.drata.com/en/articles/12333688-evidence-library-video-tutorial.md): The Evidence Library is your centralized repository for managing manual and automated test evidence, ensuring your controls stay audit-ready. - [Custom Workflows Training Video](https://help.drata.com/en/articles/13123691-custom-workflows-training-video.md): This training video series provides an overview of Drata’s Custom Workflows feature and how to configure workflows with with webhooks, trigger tasks, or Slack notifications when various events occu... - [Custom connections and test video overview](https://help.drata.com/en/articles/12609735-custom-connections-and-test-video-overview.md) - [Quick Start Guide](https://help.drata.com/en/articles/13265650-quick-start-guide.md): Get started with Drata by following the Quick Start guide. - [Complete the Provide Basic Info task in Quick Start](https://help.drata.com/en/articles/16915146-complete-the-provide-basic-info-task-in-quick-start.md): Learn which fields and documents complete the Provide Basic Info task. - [Dashboard overview](https://help.drata.com/en/articles/13259515-dashboard-overview.md): Get an overview of the Drata Dashboard, including compliance readiness, alerts, test trends, tasks, and key risk indicators. - [Workspaces Dashboard \(Beta\)](https://help.drata.com/en/articles/9774408-workspaces-dashboard-beta.md): View compliance health metrics for all the workspaces that you manage within a single account. - [AI-Assisted Custom Control Mapping to GRC Objects](https://help.drata.com/en/articles/16791453-ai-assisted-custom-control-mapping-to-grc-objects.md) - [Understanding Connections in Drata](https://help.drata.com/en/articles/13273728-understanding-connections-in-drata.md): Connections in Drata integrate your identity, HRIS, infrastructure, and development tools to automate evidence collection and continuously support compliance. - [Integrate Multiple Identity and HRIS Connections](https://help.drata.com/en/articles/13337738-integrate-multiple-identity-and-hris-connections.md): In this article, you learn how to integrate multiple identity and HRIS connections in Drata. - [How Drata Uses HRIS Data](https://help.drata.com/en/articles/13344234-how-drata-uses-hris-data.md): This article explains how Drata connects to HRIS systems, what employee data is accessed, how that data is stored and used, and what options are available if no HRIS integration is in place. - [Multiple MDM Support \(New Experience\)](https://help.drata.com/en/articles/13613980-multiple-mdm-support-new-experience.md): Connect multiple MDM providers to Drata to monitor devices across systems with automatic syncing and clear data priority rules. - [Partner Connections: Expanding Compliance with External Tools](https://help.drata.com/en/articles/12151473-partner-connections-expanding-compliance-with-external-tools.md) - [Manage connected infrastructure accounts](https://help.drata.com/en/articles/13278430-manage-connected-infrastructure-accounts.md): In this article, you learn how to manage connected infrastructure accounts. - [Manage connected version control](https://help.drata.com/en/articles/13296062-manage-connected-version-control.md): Learn how Drata displays and evaluates version control access, including write access, merge permissions, and MFA status - [Map accounts to personnel in Drata \(New Experience\)](https://help.drata.com/en/articles/13317861-map-accounts-to-personnel-in-drata-new-experience.md): Learn how to map accounts to personnel in Drata, handle service and system accounts and mark accounts out of scope. - [Ad-hoc identity and account resync](https://help.drata.com/en/articles/13337229-ad-hoc-identity-and-account-resync.md): Learn how to manually resync identity and account data in Drata to immediately reflect access and personnel changes. - [Connect your HRIS to Drata](https://help.drata.com/en/articles/8699680-connect-your-hris-to-drata.md): Learn how to connect HRIS providers to Drata and the available HRIS providers. - [GitHub Access: Should I use my personal account or a new company account?](https://help.drata.com/en/articles/4798202-github-access-should-i-use-my-personal-account-or-a-new-company-account.md): Use your personal GitHub account, but add your work email and set proper notification routing - [GitHub Rulesets Integration](https://help.drata.com/en/articles/9755132-github-rulesets-integration.md): How does Drata support GitHub rulesets - [GitLab MFA configurations](https://help.drata.com/en/articles/5362488-gitlab-mfa-configurations.md): GitLab MFA options for GitLab.com and Self-managed - [Allowlist IP Addresses for WAF Configurations](https://help.drata.com/en/articles/14049634-allowlist-ip-addresses-for-waf-configurations.md) - [Custom Device Connections](https://help.drata.com/en/articles/12014143-custom-device-connections.md) - [Part 1: Custom Connections and Tests](https://help.drata.com/en/articles/11995676-part-1-custom-connections-and-tests.md) - [Part 2: Automate Evidence Submission](https://help.drata.com/en/articles/11825486-part-2-automate-evidence-submission.md) - [Part 3: Create, Run, and Map a Custom Test](https://help.drata.com/en/articles/11825614-part-3-create-run-and-map-a-custom-test.md) - [Mark Controls In or Out of Scope](https://help.drata.com/en/articles/13381764-mark-controls-in-or-out-of-scope.md) - [Manage Scope and Exclusions in Drata](https://help.drata.com/en/articles/13252456-manage-scope-and-exclusions-in-drata.md) - [Apply Default Mappings for Controls](https://help.drata.com/en/articles/13381699-apply-default-mappings-for-controls.md): Restore Drata's default mappings between controls and framework requirements or monitoring tests. - [Create, Edit, and Manage Controls](https://help.drata.com/en/articles/13380335-create-edit-and-manage-controls.md) - [Map evidence and policies to controls \(New Experience\)](https://help.drata.com/en/articles/13416972-map-evidence-and-policies-to-controls-new-experience.md) - [Assess and Manage Individual Controls](https://help.drata.com/en/articles/13372784-assess-and-manage-individual-controls.md) - [Manage Required Approval and Control Readiness](https://help.drata.com/en/articles/13380564-manage-required-approval-and-control-readiness.md): Learn how to set up, manage, and delete required approvals for controls, and understand how approval stages affect control readiness. - [Manage Notifications for Required Approvals and Control Updates](https://help.drata.com/en/articles/13380918-manage-notifications-for-required-approvals-and-control-updates.md): Set up and manage notifications to keep control owners and approvers informed about required approvals and control changes. - [Import Controls in Bulk \(New Experience\)](https://help.drata.com/en/articles/13381439-import-controls-in-bulk-new-experience.md) - [Revert a Control to Drata's Latest DCF Template](https://help.drata.com/en/articles/13382020-revert-a-control-to-drata-s-latest-dcf-template.md): Restore a DCF control to Drata's latest published template when the language in your workspace has diverged. - [Export Control-to-Requirement Mappings](https://help.drata.com/en/articles/13381891-export-control-to-requirement-mappings.md) - [Controls and Tests Updated Between January 2024 and October 2025](https://help.drata.com/en/articles/12650128-controls-and-tests-updated-between-january-2024-and-october-2025.md): Summary of Controls and Tests Updated from January 2024 Through October 2025 - [Annotate a Control](https://help.drata.com/en/articles/5918311-annotate-a-control.md): Add internal notes, tickets, and tasks to controls to provide context for your team. - [Early Access for Monitoring and Controls](https://help.drata.com/en/articles/10258365-early-access-for-monitoring-and-controls.md): Learn more about the newest changes for our monitoring tests and controls. - [Introduction to the Drata Control Framework \(DCF\)](https://help.drata.com/en/articles/11632648-introduction-to-the-drata-control-framework-dcf.md): Drata's DCF: A proprietary, framework-agnostic control catalog to centralize and accelerate your compliance efforts. - [The Drata Control Framework & Requirement Relationship](https://help.drata.com/en/articles/11095971-the-drata-control-framework-requirement-relationship.md): Explain what the Drata Control Framework is, how it relates to requirements, and why multiple controls may map to a single requirement. - [DCF Library Updates on 1/18/2024](https://help.drata.com/en/articles/8840082-dcf-library-updates-on-1-18-2024.md) - [Understand the Difference: Terms of Service \(DCF-63\) vs. Master Service Agreements \(DCF-66\)](https://help.drata.com/en/articles/13162505-understand-the-difference-terms-of-service-dcf-63-vs-master-service-agreements-dcf-66.md) - [Monitoring Overview](https://help.drata.com/en/articles/13391811-monitoring-overview.md): Learn how to use Monitoring in Drata to review test results and maintain continuous audit readiness. - [Understanding Test Provisioning and the Test Library \(New Experience\)](https://help.drata.com/en/articles/13948946-understanding-test-provisioning-and-the-test-library-new-experience.md) - [Test Library \(New experience\)](https://help.drata.com/en/articles/13394386-test-library-new-experience.md) - [Filter and search tests in Monitoring \(New Experience\)](https://help.drata.com/en/articles/13392089-filter-and-search-tests-in-monitoring-new-experience.md): Learn how to filter, search, and narrow tests in Drata’s Monitoring page to quickly find results, review findings, and resolve compliance gaps. - [View and Manage Test Details \(New Experience\)](https://help.drata.com/en/articles/13392374-view-and-manage-test-details-new-experience.md): Learn how to use the test details page in Drata Monitoring to investigate test results, remediate issues, manage exclusions, and understand how tests impact control readiness and compliance. - [Manage Tests in Monitoring Page](https://help.drata.com/en/articles/13392191-manage-tests-in-monitoring-page.md): Manage individual and bulk test actions in Drata's Monitoring page, and understand test details including findings, exclusions, history, and controls. - [Enable AI Summaries for Tests](https://help.drata.com/en/articles/13394100-enable-ai-summaries-for-tests.md): Enable and use AI-generated summaries to quickly understand why custom tests failed, and export findings to CSV for analysis or auditor sharing. - [Add tests from the Test Library to a workspace \(New Experience\)](https://help.drata.com/en/articles/13948681-add-tests-from-the-test-library-to-a-workspace-new-experience.md) - [Map Tests to Controls](https://help.drata.com/en/articles/13394042-map-tests-to-controls.md): Manually map or unmap tests to controls to ensure monitoring results accurately reflect how your controls are implemented. - [Download Audit Evidence for a Custom Test \(New Experience\)](https://help.drata.com/en/articles/13414137-download-audit-evidence-for-a-custom-test-new-experience.md) - [Disable a Test](https://help.drata.com/en/articles/13394083-disable-a-test.md): Disable a test when it does not apply to your environment or when the control is monitored outside of Drata. - [Exclude Findings from Tests](https://help.drata.com/en/articles/13521711-exclude-findings-from-tests.md): Exclude specific items from a compliance test when they do not apply to your organization, and re-include them when needed. - [Exclusions vs. Disabling a Test \(Concept Guide\)](https://help.drata.com/en/articles/4939181-exclusions-vs-disabling-a-test-concept-guide.md): When should you use each option within Drata? - [Excluding Infrastructure resources](https://help.drata.com/en/articles/13274920-excluding-infrastructure-resources.md): Exclusions in Drata let you exclude specific resources or test findings from compliance monitoring to reduce noise, manage audit scope, and focus on relevant evidence. - [Exclusion labels within GCP](https://help.drata.com/en/articles/5539469-exclusion-labels-within-gcp.md): Implementing exclusion labels for specific resources - [Exclusion tags within AWS](https://help.drata.com/en/articles/5260549-exclusion-tags-within-aws.md): Implementing exclusion tags for specific resources - [Exclusion tags within Azure](https://help.drata.com/en/articles/5352047-exclusion-tags-within-azure.md): Implementing exclusion tags for specific resources - [Identify and Add Missing Azure Permissions for Drata](https://help.drata.com/en/articles/13454138-identify-and-add-missing-azure-permissions-for-drata.md): Understand why Drata Azure tests fail and how to add the required Microsoft Graph API and Azure RBAC permissions to restore monitoring. - [Identify and Add Missing AWS Permissions for Drata](https://help.drata.com/en/articles/13455970-identify-and-add-missing-aws-permissions-for-drata.md) - [Identify and Add Missing GCP Permissions for Drata](https://help.drata.com/en/articles/13456336-identify-and-add-missing-gcp-permissions-for-drata.md) - [Resolve SSL/TLS Compliance Testing Issues in Drata](https://help.drata.com/en/articles/12402142-resolve-ssl-tls-compliance-testing-issues-in-drata.md) - [Dratabot](https://help.drata.com/en/articles/5411182-dratabot.md): How to verify the Dratabot - [Manually Running a Control Test](https://help.drata.com/en/articles/4797007-manually-running-a-control-test.md): Tests automatically run every evening \(PST\) in Drata, but you're also able to manually trigger them anytime - [Conditions That Affect 'Fix Now' and 'Test Now' Button Visibility](https://help.drata.com/en/articles/12418345-conditions-that-affect-fix-now-and-test-now-button-visibility.md): Fix Now and Test Now Button Visibility in Drata Explained - [AWS Resource Permissions](https://help.drata.com/en/articles/8852274-aws-resource-permissions.md): The available supported AWS resources. - [Resource Guide for custom tests](https://help.drata.com/en/articles/9415404-resource-guide-for-custom-tests.md): The Resource Guide provides detailed information about available attributes and the structure of your data when you are creating custom test - [Common use cases for custom test](https://help.drata.com/en/articles/9415618-common-use-cases-for-custom-test.md): Learn the most common use cases for creating custom tests - [Create and Publish Custom Tests](https://help.drata.com/en/articles/13401776-create-and-publish-custom-tests.md): Create custom tests in Drata to monitor controls that are not covered by Drata's out-of-the-box tests, using your own logic and integrations. - [Edit a Custom Test](https://help.drata.com/en/articles/13403874-edit-a-custom-test.md): Update the logic of a published custom test by creating and editing a draft version, then publishing when ready. - [Advanced Editor in the Test Builder](https://help.drata.com/en/articles/13403932-advanced-editor-in-the-test-builder.md): Use the Advanced editor to write complex test logic with nested properties, arrays, and JSON-based rules that go beyond the Builder tab's capabilities. - [Evidence Overview](https://help.drata.com/en/articles/13404035-evidence-overview.md): Centralize, manage, and track audit-ready evidence across controls with Drata's Evidence Library. - [Evidence Renewal Date](https://help.drata.com/en/articles/13417542-evidence-renewal-date.md): Set and manage renewal dates for evidence to keep controls audit-ready and avoid compliance gaps. - [Create Evidence](https://help.drata.com/en/articles/13404476-create-evidence.md): Add and manage evidence in Drata's Evidence Library to support control readiness and audit preparation. - [Add Jira Tickets as Evidence](https://help.drata.com/en/articles/13444265-add-jira-tickets-as-evidence.md): Use Jira tickets as evidence to demonstrate how compliance and security work is tracked and completed. - [Delete Evidence \(New Experience\)](https://help.drata.com/en/articles/13404533-delete-evidence-new-experience.md) - [Manually Export Evidence Data from Drata](https://help.drata.com/en/articles/13464187-manually-export-evidence-data-from-drata.md): Learn how to manually download evidence from Drata using the Evidence Library, Controls, Event Tracking, or Audit Hub. - [Example Evidence for Not Monitored Controls Linked to Policies](https://help.drata.com/en/articles/8016471-example-evidence-for-not-monitored-controls-linked-to-policies.md) - [Drata Evidence Library Sync](https://help.drata.com/en/articles/13356790-drata-evidence-library-sync.md): Sync frequently-requested compliance and security documents from Drata's Evidence Library to SafeBase. - [New File Format Support](https://help.drata.com/en/articles/8500557-new-file-format-support.md): This article covers the new file formats supported in Evidence Library, Controls, and RIsk Management. - [Evidence Library: Multiple Artifacts & Multi-File Upload \(New Experience\)](https://help.drata.com/en/articles/15694170-evidence-library-multiple-artifacts-multi-file-upload-new-experience.md) - [Bulk Import Evidence](https://help.drata.com/en/articles/16989042-bulk-import-evidence.md): Upload a CSV of evidence items and artifacts using a guided, spreadsheet-style experience. - [Policy Center Overview](https://help.drata.com/en/articles/13541243-policy-center-overview.md): Use the Policy Center to manage the policies required for audit readiness and ongoing compliance. From a single place, you can create, edit, review, approve, publish, and track policies throughout ... - [Create a policy](https://help.drata.com/en/articles/13550137-create-a-policy.md): This article explains how to create a custom policy and replace an existing Drata template. - [Assigning Policies to Specific Groups](https://help.drata.com/en/articles/13551822-assigning-policies-to-specific-groups.md): Control which personnel must acknowledge each policy by assigning policies to specific identity provider groups, all personnel, or no personnel. - [View and edit a policy](https://help.drata.com/en/articles/13549259-view-and-edit-a-policy.md): This article explains who can edit a policy, how to make updates, and how approvals and versioning work in the new experience. - [Add comments in your policy](https://help.drata.com/en/articles/13549713-add-comments-in-your-policy.md): This article explains when you can comment or edit a policy, how comments work, and how Policy Owners manage edits during reviews. - [Delete a Policy Draft](https://help.drata.com/en/articles/13551276-delete-a-policy-draft.md): Learn how to delete a policy version in Draft status, including which policy types and versions can be deleted. - [Understanding the Approval Process](https://help.drata.com/en/articles/13549900-understanding-the-approval-process.md): Learn how policy approvals work in Drata, how to configure approvers and tiers, and how to publish a policy once approval is complete. - [Policy Owner Notifications](https://help.drata.com/en/articles/13553723-policy-owner-notifications.md) - [Map policies to controls in Drata](https://help.drata.com/en/articles/13557067-map-policies-to-controls-in-drata.md): Mapping policies to controls allows Drata to evaluate control readiness and run policy-related compliance tests. - [Manage policy renewals](https://help.drata.com/en/articles/13551591-manage-policy-renewals.md) - [Download your Policies](https://help.drata.com/en/articles/13756587-download-your-policies.md) - [Archive and restore policies](https://help.drata.com/en/articles/13550854-archive-and-restore-policies.md): This article explains when policies can be archived, why some policies can’t be archived, and how to restore archived or replaced policies. - [External Policy: Use BambooHR to manage your policies](https://help.drata.com/en/articles/13553241-external-policy-use-bamboohr-to-manage-your-policies.md): Use this workflow if your organization manages policies and acknowledgments in BambooHR and uses Drata for audit evidence and control mapping. - [External Policy: Use Confluence or Notion to manage your policies](https://help.drata.com/en/articles/13553508-external-policy-use-confluence-or-notion-to-manage-your-policies.md): Use this workflow if your organization manages policy content in Confluence or Notion and uses Drata as the system of record for audit evidence and control mapping. - [Managing Policies Synced from Confluence in Drata](https://help.drata.com/en/articles/12111728-managing-policies-synced-from-confluence-in-drata.md) - [Manage and Configure Policy Controls in Drata](https://help.drata.com/en/articles/12111663-manage-and-configure-policy-controls-in-drata.md) - [Creating an SLA for Employee Onboarding Completion](https://help.drata.com/en/articles/13553190-creating-an-sla-for-employee-onboarding-completion.md): Use this article to understand and configure the onboarding grace period that determines when compliance tests begin evaluating new personnel. - [AI-powered control suggestions for policies](https://help.drata.com/en/articles/12455211-ai-powered-control-suggestions-for-policies.md): Use AI suggestions to map policies to controls, reduce manual work, and keep compliance mappings accurate and up to date. - [Configure Policies to Support Compliance Test Completion in Drata](https://help.drata.com/en/articles/12111934-configure-policies-to-support-compliance-test-completion-in-drata.md) - [Linking directly to specific employee security policies](https://help.drata.com/en/articles/5283266-linking-directly-to-specific-employee-security-policies.md): Embedding links to Drata policies in other tools or locations - [Common Policy Management Issues in Drata \(and How to Resolve Them\)](https://help.drata.com/en/articles/13252508-common-policy-management-issues-in-drata-and-how-to-resolve-them.md) - [Compare Policy Versions with AI](https://help.drata.com/en/articles/15436872-compare-policy-versions-with-ai.md) - [Troubleshoot Blank Version History in Downloaded Policy PDFs](https://help.drata.com/en/articles/16045126-troubleshoot-blank-version-history-in-downloaded-policy-pdfs.md): This article applies when an existing published policy downloads with a blank version history table. - [General AI Policy](https://help.drata.com/en/articles/16044086-general-ai-policy.md) - [Personnel Overview](https://help.drata.com/en/articles/13467999-personnel-overview.md): Learn how to navigate Drata’s Personnel page, filter and view employee compliance data, and export records for audit readiness. - [Populating and Managing Personnel Data in Drata \(Concept Guide\)](https://help.drata.com/en/articles/5308992-populating-and-managing-personnel-data-in-drata-concept-guide.md): How Drata uses data from your HRIS to supplement personnel information - [Identity sync updates in Drata](https://help.drata.com/en/articles/5330216-identity-sync-updates-in-drata.md): Understand when personnel, user, and device changes will show in Drata - [Confirm your personnel](https://help.drata.com/en/articles/6679521-confirm-your-personnel.md): Confirm personnel hold the correct status in Drata - [Mark personnel as Out of Scope \(New Experience\)](https://help.drata.com/en/articles/13764544-mark-personnel-as-out-of-scope-new-experience.md) - [Personnel exclusions](https://help.drata.com/en/articles/13521706-personnel-exclusions.md): Create and manage personnel exclusions to document approved compliance exceptions while keeping users in audit scope. - [Bulk Import Personnel Training Records \(New Experience\)](https://help.drata.com/en/articles/12634309-bulk-import-personnel-training-records-new-experience.md): Upload training completion records for multiple personnel at once using a CSV or Excel file. - [Bulk Import Personnel Background Checks \(New Experience\)](https://help.drata.com/en/articles/14142232-bulk-import-personnel-background-checks-new-experience.md): Upload completed background checks for multiple personnel at once using a CSV file, instead of updating each record individually. - [Send reminder email to personnel](https://help.drata.com/en/articles/13534745-send-reminder-email-to-personnel.md): Use this article to send reminders to personnel who haven’t completed required onboarding items in Drata. - [Reset recurring personnel trainings](https://help.drata.com/en/articles/13539499-reset-recurring-personnel-trainings.md): Reset configure recurring reset schedules. Some trainings must be completed on a recurring basis \(such as Security Awareness, HIPAA, or AI Awareness\) to maintain compliance and demonstrate ongoing ... - [Resume IdP and HRIS syncs for personnel](https://help.drata.com/en/articles/13538815-resume-idp-and-hris-syncs-for-personnel.md): Use this article to resume syncing personnel details from your connected identity provider \(IdP\) or human resources information system \(HRIS\). - [Why active employees may appear as former employees in Drata? \(Concept Guide\)](https://help.drata.com/en/articles/12939479-why-active-employees-may-appear-as-former-employees-in-drata-concept-guide.md): Use this article to understand why active employees may appear as Former Employee or not appear in the Personnel list in Drata. - [Troubleshoot employment status issues in Drata](https://help.drata.com/en/articles/15086075-troubleshoot-employment-status-issues-in-drata.md): Why am I not receiving authentication or login emails from Drata, and how can I resolve this? - [Assets](https://help.drata.com/en/articles/13557132-assets.md) - [Understanding Device Linking, Removal, and Visibility in Drata](https://help.drata.com/en/articles/12401019-understanding-device-linking-removal-and-visibility-in-drata.md): Learn how unlinking or removing a device affects compliance in Drata and follow troubleshooting steps if a device is missing from the Assets or Personnel pages. - [Virtual Asset Population: AWS](https://help.drata.com/en/articles/6250074-virtual-asset-population-aws.md): Drata automatic population of Virtual Assets - [Azure Virtual Asset](https://help.drata.com/en/articles/9057685-azure-virtual-asset.md) - [GCP Virtual Assets](https://help.drata.com/en/articles/9463084-gcp-virtual-assets.md): Learn how to automate your GCP asset inventory, how to mark assets our of scope, and how Drata automatically assigns asset owner. - [Bulk Import Assets](https://help.drata.com/en/articles/15399981-bulk-import-assets.md): Upload a CSV of custom assets using a guided, spreadsheet-style experience. - [Vulnerabilities](https://help.drata.com/en/articles/13557176-vulnerabilities.md) - [SafeBase Integration for TPRM Reviews](https://help.drata.com/en/articles/14446304-safebase-integration-for-tprm-reviews.md): Learn how to add a vendor’s SafeBase Trust Center in Drata so the TPRM Agent can automatically collect documentation and streamline security reviews. - [Vendors overview in Drata](https://help.drata.com/en/articles/13557179-vendors-overview-in-drata.md) - [Vendor insights](https://help.drata.com/en/articles/13557232-vendor-insights.md) - [Add a prospective vendor](https://help.drata.com/en/articles/13557260-add-a-prospective-vendor.md): Use prospective vendors to evaluate third parties before onboarding. - [Vendor risks](https://help.drata.com/en/articles/13557213-vendor-risks.md) - [Vendor suggestions](https://help.drata.com/en/articles/13557323-vendor-suggestions.md) - [Vendor Automated Impact Assessment](https://help.drata.com/en/articles/13557339-vendor-automated-impact-assessment.md) - [Create and Manage Vendor Questionnaires](https://help.drata.com/en/articles/13557330-create-and-manage-vendor-questionnaires.md) - [Start and manage security reviews for your vendors](https://help.drata.com/en/articles/13557334-start-and-manage-security-reviews-for-your-vendors.md) - [Customize the vendor questionnaire email subject line \(New Experience\)](https://help.drata.com/en/articles/13880127-customize-the-vendor-questionnaire-email-subject-line-new-experience.md): Only in the New experience, you can customize the subject line used for vendor questionnaire emails. - [Security Questionnaire Automation \(SQA\) Beta Sunset Notice](https://help.drata.com/en/articles/9554898-security-questionnaire-automation-sqa-beta-sunset-notice.md): Security Questionnaire Automation \(SQA\) Beta will officially sunset on April 30, 2026. - [Customizing Security Review Titles](https://help.drata.com/en/articles/14811526-customizing-security-review-titles.md): You can now customize the titles of Security, SOC, and Uploaded reviews in Drata. - [Bulk actions for Current Vendors \(New Experience\)](https://help.drata.com/en/articles/15032723-bulk-actions-for-current-vendors-new-experience.md) - [Internal Notes and Observations in Security Reviews \(New Experience\)](https://help.drata.com/en/articles/15349349-internal-notes-and-observations-in-security-reviews-new-experience.md) - [Automate Recurring Vendor Reviews with the TPRM Agent](https://help.drata.com/en/articles/15384160-automate-recurring-vendor-reviews-with-the-tprm-agent.md) - [Customize vendor types \(New Experience\)](https://help.drata.com/en/articles/14647131-customize-vendor-types-new-experience.md): Learn how to customize vendor types in Drata - [Tropic Integration Guide](https://help.drata.com/en/articles/16765259-tropic-integration-guide.md) - [Ironclad Integration Guide \(Procurement\)](https://help.drata.com/en/articles/16765899-ironclad-integration-guide-procurement.md) - [Ramp Integration Guide](https://help.drata.com/en/articles/16880123-ramp-integration-guide.md) - [Integrate Zip with Drata Vendor Management](https://help.drata.com/en/articles/11801416-integrate-zip-with-drata-vendor-management.md) - [Getting started with the TPRM Agent](https://help.drata.com/en/articles/16880143-getting-started-with-the-tprm-agent.md): Learn how to use the Drata AI chat panel to ask questions about your vendor portfolio and take action on vendors, reviews, criteria, and risks — in plain language. - [TPRM Agent Autonomy Settings](https://help.drata.com/en/articles/16880162-tprm-agent-autonomy-settings.md): Learn how to control how much the TPRM Agent does on its own — and where it stops to ask for your approval. - [Add a vendor or prospective vendor](https://help.drata.com/en/articles/16880268-add-a-vendor-or-prospective-vendor.md): Learn how to add vendors to Drata manually — either as a current vendor you already work with, or as a prospective vendor you're still evaluating. - [Configuring inherent risk](https://help.drata.com/en/articles/16880293-configuring-inherent-risk.md) - [TPRM Agent: Create a Criteria](https://help.drata.com/en/articles/16880318-tprm-agent-create-a-criteria.md): Learn how to configure the evaluation criteria the TPRM Agent uses to assess vendors — including inherent risk mapping, severity weighting, and vendor type scoping. - [Conducting a Security Review](https://help.drata.com/en/articles/16880358-conducting-a-security-review.md): Learn how to run an end-to-end vendor security review with the TPRM Agent — from starting the review in chat, through document collection, assessment, and residual risk scoring, to finalizing the r... - [SafeBase Trust Center document collection with the TPRM Agent](https://help.drata.com/en/articles/16892971-safebase-trust-center-document-collection-with-the-tprm-agent.md): This article explains how the TPRM Agent collects vendor security documentation from a SafeBase Trust Center and what you need to do at each stage, including the steps that happen in SafeBase itself. - [\(Legacy\) TPRM Agent: Create a Criteria](https://help.drata.com/en/articles/14446788-legacy-tprm-agent-create-a-criteria.md) - [Conducting a Security Review \(Legacy\)](https://help.drata.com/en/articles/14447644-conducting-a-security-review-legacy.md): Learn how to use the TPRM Agent in Drata to collect vendor documentation, run AI-powered security reviews, and interpret assessment results based on your evaluation criteria. - [Terminology Updates: Inherent and Residual Risk in Vendor Risk Management](https://help.drata.com/en/articles/14328058-terminology-updates-inherent-and-residual-risk-in-vendor-risk-management.md): To better align with industry-standard Governance, Risk, and Compliance \(GRC\) frameworks, Drata has updated the terminology used within the Vendor Risk Management \(VRM\) experience. - [Risk management in Drata: An overview](https://help.drata.com/en/articles/13355387-risk-management-in-drata-an-overview.md): This article provides the foundational workflow for managing your risk program within Drata. - [Risk insights overview](https://help.drata.com/en/articles/13764324-risk-insights-overview.md) - [Getting started with a risk assessment \(Concept Guide\)](https://help.drata.com/en/articles/9400813-getting-started-with-a-risk-assessment-concept-guide.md): Understanding how to apply risk management principles to Drata’s Risk Management Standard offering - [Your First Risk Assessment: A Step-by-Step Guide \(Concept Guide\)](https://help.drata.com/en/articles/11690433-your-first-risk-assessment-a-step-by-step-guide-concept-guide.md): New to risk assessments? This help article walks you through it, one simple step at a time. - [Integrating Fraud Risk into Your Risk Assessment \(Concept Guide\)](https://help.drata.com/en/articles/12662543-integrating-fraud-risk-into-your-risk-assessment-concept-guide.md): How to incorporate fraud risk into your organization’s standard risk assessment approach. - [Risk categories in Drata](https://help.drata.com/en/articles/14358614-risk-categories-in-drata.md): Risk categories in Drata help you organize, filter, and report on risks in your Risk Register. - [Streamlined Risk Register Set Up](https://help.drata.com/en/articles/13371754-streamlined-risk-register-set-up.md) - [Import Risk in Bulk \(New Experience\)](https://help.drata.com/en/articles/12260817-import-risk-in-bulk-new-experience.md): Custom risks can be uploaded quickly using our guided import flow, making it simple to bring your existing risk inventory into Drata. - [Drata's Risk Library \(New Experience\)](https://help.drata.com/en/articles/13371089-drata-s-risk-library-new-experience.md) - [Understanding the Drata Risk Register](https://help.drata.com/en/articles/11690245-understanding-the-drata-risk-register.md): Navigate Your Risk Landscape: Explore Drata's Risk Register Headers - [Assess and Manage Individual Risks](https://help.drata.com/en/articles/13370793-assess-and-manage-individual-risks.md) - [Add and View Residual Risk in the Risk Register \(New Experience\)](https://help.drata.com/en/articles/13371623-add-and-view-residual-risk-in-the-risk-register-new-experience.md) - [Custom Formulas for Risks](https://help.drata.com/en/articles/13372425-custom-formulas-for-risks.md) - [Risk Treatment Plan Guidance](https://help.drata.com/en/articles/6116040-risk-treatment-plan-guidance.md): Risk Assessment Results and Treatment Plan - [Manage Risk Across Workspaces](https://help.drata.com/en/articles/14895259-manage-risk-across-workspaces.md): Manage risk across your Drata workspaces to organize, track, and scale your risk management program. - [Manage multiple risk registers \(New Experience\)](https://help.drata.com/en/articles/13434682-manage-multiple-risk-registers-new-experience.md): Create and maintain multiple risk registers in Drata - [Risk Assessment overview](https://help.drata.com/en/articles/9354303-risk-assessment-overview.md) - [Events Overview](https://help.drata.com/en/articles/13557370-events-overview.md) - [Annotate an event](https://help.drata.com/en/articles/13557378-annotate-an-event.md): You can add notes to an event to provide additional context for auditors or internal reviewers. Notes are attached directly to the event and become part of the event’s audit evidence. - [Add an Application Manually for Access Reviews \(New Experience\)](https://help.drata.com/en/articles/13704629-add-an-application-manually-for-access-reviews-new-experience.md) - [Upload or Update Personnel Data for Access Reviews \(New Experience\)](https://help.drata.com/en/articles/13704660-upload-or-update-personnel-data-for-access-reviews-new-experience.md) - [Run an Access Review](https://help.drata.com/en/articles/13557396-run-an-access-review.md): Access Reviews help you review and validate user access across connected applications. - [Example Access Review Procedure](https://help.drata.com/en/articles/6026468-example-access-review-procedure.md) - [User Access Reviews for Microsoft 365](https://help.drata.com/en/articles/8895962-user-access-reviews-for-microsoft-365.md): Ensure the following prerequisites are met before setting up Microsoft 365 for user access reviews. - [Download Access Review Evidence and Review Details](https://help.drata.com/en/articles/13704766-download-access-review-evidence-and-review-details.md) - [Cyber Leaders Lunch and Learn: Policy Guidance and Building Trust in the Age of AI](https://help.drata.com/en/articles/12602959-cyber-leaders-lunch-and-learn-policy-guidance-and-building-trust-in-the-age-of-ai.md): Cybersecurity Leadership in the Age of AI - [SOC 2 Express Webinar Recording](https://help.drata.com/en/articles/12335534-soc-2-express-webinar-recording.md): From Drata Setup to Audit-Ready - [Drata Pre-Audit Check Webinar Recording](https://help.drata.com/en/articles/12608925-drata-pre-audit-check-webinar-recording.md): How to Prepare for Your Audit with Drata - [Drata Customer Spotlight: Turning Compliance into Revenue](https://help.drata.com/en/articles/13062850-drata-customer-spotlight-turning-compliance-into-revenue.md): Explore this webinar recording to learn how LetzChat streamlined SOC 2 compliance with Drata, accelerated audit readiness, and turned security into a growth engine. - [Drata Expert Series: Scaling your GRC Program Post-Audit](https://help.drata.com/en/articles/13063792-drata-expert-series-scaling-your-grc-program-post-audit.md): Explore this webinar recording to learn how to scale your GRC program after an audit, streamline processes in Drata, and stay audit-ready year-over-year. - [From 0 to ISO 27001: The 5-Phase Blueprint Webinar Recording](https://help.drata.com/en/articles/13171544-from-0-to-iso-27001-the-5-phase-blueprint-webinar-recording.md): In this webinar recording, Drata’s Compliance Advisors break down the ISO 27001 5-phase blueprint, outlining the key steps to prepare for a successful ISO 27001 audit. - [The Hidden Cost of DIY Compliance Webinar Recording](https://help.drata.com/en/articles/13612116-the-hidden-cost-of-diy-compliance-webinar-recording.md): Explore the true cost of managing compliance in-house with Drata Partner, Trava Security - [Drata Onboarding Webinar Recording](https://help.drata.com/en/articles/12401592-drata-onboarding-webinar-recording.md): Getting Started with Drata: Customer Onboarding - [Getting Started with Drata: Controls & Monitoring - Webinar Recording](https://help.drata.com/en/articles/14542342-getting-started-with-drata-controls-monitoring-webinar-recording.md): Explore the framework relationship, control types, evidence collection, and the Controls and Monitoring pages in Drata. - [Getting Started with Drata: Personnel - Webinar Recording](https://help.drata.com/en/articles/14541853-getting-started-with-drata-personnel-webinar-recording.md): Learn core personnel compliance components with a guided Drata demo. - [Policy Power Hour Recording: March 2026](https://help.drata.com/en/articles/14026417-policy-power-hour-recording-march-2026.md): Practical guidance to draft and refine security policies - [Policy Power Hour Recording: October 2025](https://help.drata.com/en/articles/12735097-policy-power-hour-recording-october-2025.md): Practical guidance to draft and refine security policies - [Policy Power Hour Q&A: January 2025 Recap](https://help.drata.com/en/articles/10448085-policy-power-hour-q-a-january-2025-recap.md): Take a look at our recap of the questions answered during our last Policy Power Hour: Live Q&A. - [Policy Power Hour Q&A: November 2024 Recap](https://help.drata.com/en/articles/10185999-policy-power-hour-q-a-november-2024-recap.md): Take a look at our recap of the questions answered during our last Policy Power Hour: Live Q&A. - [Policy Power Hour Q&A: September 2024 Recap](https://help.drata.com/en/articles/9901323-policy-power-hour-q-a-september-2024-recap.md) - [Policy Power Hour Q&A: August 2024 Recap](https://help.drata.com/en/articles/9775478-policy-power-hour-q-a-august-2024-recap.md): A recap of our August 2024 Policy Power Hour: Live Q&A. - [Policy Power Hour Q&A: July 2024 Recap](https://help.drata.com/en/articles/9627439-policy-power-hour-q-a-july-2024-recap.md): A recap of our July 2024 Policy Power Hour: Live Q&A. - [Policy Power Hour Q&A: May 2024 Recap](https://help.drata.com/en/articles/9364100-policy-power-hour-q-a-may-2024-recap.md): Take a look at our recap of the questions answered during our May 2024 Policy Power Hour: Live Q&A. - [SafeBase Trust Center integration in Drata TPRM](https://help.drata.com/en/articles/15453390-safebase-trust-center-integration-in-drata-tprm.md) - [Trust Center Essential and Pro Plans](https://help.drata.com/en/articles/8067402-trust-center-essential-and-pro-plans.md) - [Managing and Updating Your Trust Page](https://help.drata.com/en/articles/8067413-managing-and-updating-your-trust-page.md) - [Public Trust page URL](https://help.drata.com/en/articles/8067414-public-trust-page-url.md) - [Publishing your Public Trust page](https://help.drata.com/en/articles/8067411-publishing-your-public-trust-page.md) - [Download reports from Trust Center](https://help.drata.com/en/articles/9797347-download-reports-from-trust-center.md) - [Announcements \(Trust Center Pro only\)](https://help.drata.com/en/articles/8067428-announcements-trust-center-pro-only.md) - [Compliance](https://help.drata.com/en/articles/8067433-compliance.md): In this article, you learn how to add compliance files and records to your Trust Center. - [Trust Center: Security](https://help.drata.com/en/articles/8067435-trust-center-security.md): In this article, you learn how to add security files to your Trust Center. - [Policies for Trust Center](https://help.drata.com/en/articles/8067437-policies-for-trust-center.md) - [Continuous Monitoring](https://help.drata.com/en/articles/8067440-continuous-monitoring.md): Continuous Monitoring within Trust Center - [Topics and Common Questions \(Trust Center Pro only\)](https://help.drata.com/en/articles/8067444-topics-and-common-questions-trust-center-pro-only.md) - [Privacy Details](https://help.drata.com/en/articles/8067448-privacy-details.md): In this article, you learn how to display privacy-related information in your Trust Center. - [Preview & View as Visitor](https://help.drata.com/en/articles/8067451-preview-view-as-visitor.md) - [Submitting and Approving Requests](https://help.drata.com/en/articles/8067477-submitting-and-approving-requests.md): In this article, you learn how to submit and approve access requests for private Trust Center content. - [Custom Access Length Expiration \(Trust Center Pro only\)](https://help.drata.com/en/articles/8067482-custom-access-length-expiration-trust-center-pro-only.md) - [Revoking Access](https://help.drata.com/en/articles/8067484-revoking-access.md): In this article, you learn how to display privacy-related information in your Trust Center. - [Pre-Approved Email Domains \(Trust Center Pro only\)](https://help.drata.com/en/articles/8067489-pre-approved-email-domains-trust-center-pro-only.md) - [Display Details](https://help.drata.com/en/articles/8067419-display-details.md) - [Document access management](https://help.drata.com/en/articles/8067507-document-access-management.md): Configure the privacy of your more sensitive documents with an NDA, configure email notifications, and set limits on document access length. - [Salesforce: Streamline your documentation access request](https://help.drata.com/en/articles/9796974-salesforce-streamline-your-documentation-access-request.md) - [Streamline your documentation access request](https://help.drata.com/en/articles/9797456-streamline-your-documentation-access-request.md): Connect a CRM, such as Salesforce, to Drata to provide more context to, and streamline, document access requests. - [Trust Center Analytics Dashboard](https://help.drata.com/en/articles/10192920-trust-center-analytics-dashboard.md) - [Trust Center - Web Analytics Tracking](https://help.drata.com/en/articles/10192925-trust-center-web-analytics-tracking.md): Track Trust Center insights with your web analytics provider - [Trust Center: Custom Titles and Descriptions](https://help.drata.com/en/articles/10514469-trust-center-custom-titles-and-descriptions.md): Learn how to customize your public Trust Center page by updating your section titles and descriptions to align with your business. - [Trust Center: Reorder your sections and documents](https://help.drata.com/en/articles/10514561-trust-center-reorder-your-sections-and-documents.md): Learn how to reorder your sections and documents on your Trust Center page to highlight key information and content for your visitors. - [Security Report](https://help.drata.com/en/articles/4827067-security-report.md): Drata provides you with a security report summarizing your current status for distribution to auditors, customers or others - [What should be included in the annual BCP/DR test and Incident Response test?](https://help.drata.com/en/articles/5396377-what-should-be-included-in-the-annual-bcp-dr-test-and-incident-response-test.md) ## Settings - [Settings Page](https://help.drata.com/en/articles/13563975-settings-page.md): Overview of the Settings page and available configuration options. - [Find your Account ID](https://help.drata.com/en/articles/13755424-find-your-account-id.md) - [Organization settings: Organization Details \(New Experience\)](https://help.drata.com/en/articles/13565986-organization-settings-organization-details-new-experience.md): Manage your company information, locate your Account ID, and configure audit-facing details - [Organization settings: Key Personnel Information \(New Experience\)](https://help.drata.com/en/articles/13566374-organization-settings-key-personnel-information-new-experience.md): Define leadership and accountability roles used in audits and compliance reporting. - [Organization settings: Security awareness, HIPAA, and AI training](https://help.drata.com/en/articles/13566994-organization-settings-security-awareness-hipaa-and-ai-training.md) - [Organization settings: Human Resources Settings \(New Experience\)](https://help.drata.com/en/articles/13566413-organization-settings-human-resources-settings-new-experience.md): Configure personnel-related controls used for audit evidence and compliance reporting. - [Organization settings: Internal Security](https://help.drata.com/en/articles/13566935-organization-settings-internal-security.md): The Internal Security settings define how employee-related security evidence is sourced and tracked across your organization. - [Organization settings: Notifications rules](https://help.drata.com/en/articles/13566136-organization-settings-notifications-rules.md): Organization notifications rules let you configure automated compliance updates to Slack or Microsoft Teams. - [Personal settings: Notifications \(New Experience\)](https://help.drata.com/en/articles/13566050-personal-settings-notifications-new-experience.md) - [Your Drata Domain](https://help.drata.com/en/articles/10197849-your-drata-domain.md) - [Drata Compliance as Code](https://help.drata.com/en/articles/9930785-drata-compliance-as-code.md) - [Drata MCP — Setup & Usage Guide](https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide.md) - [Drata AI: Technical & Security Details](https://help.drata.com/en/articles/14628390-drata-ai-technical-security-details.md) - [Microsoft Copilot MCP Integration Guide](https://help.drata.com/en/articles/15369685-microsoft-copilot-mcp-integration-guide.md) - [Resolve Authorization Errors in Drata](https://help.drata.com/en/articles/12418856-resolve-authorization-errors-in-drata.md) - [Add guest administrators with a different domain](https://help.drata.com/en/articles/12889081-add-guest-administrators-with-a-different-domain.md) - [Manage user roles in Drata](https://help.drata.com/en/articles/13604055-manage-user-roles-in-drata.md): Use this article to assign, change, or remove roles for users in your organization. - [Roles and permissions overview \(New Experience\)](https://help.drata.com/en/articles/13578465-roles-and-permissions-overview-new-experience.md): Use this article to understand which role to assign and what access each role provides in the new experience. - [Admins overview](https://help.drata.com/en/articles/13604014-admins-overview.md) - [Workspace Manager overview](https://help.drata.com/en/articles/13603882-workspace-manager-overview.md) - [Manage guest administrators](https://help.drata.com/en/articles/13580839-manage-guest-administrators.md): Invite a guest administrator to manage compliance on your behalf, or remove access when it’s no longer needed. - [Checklist: Before the Admin Leaves \(New Experience\)](https://help.drata.com/en/articles/14142997-checklist-before-the-admin-leaves-new-experience.md) - [Read-Only and Restricted-View Roles](https://help.drata.com/en/articles/15122885-read-only-and-restricted-view-roles.md): Use this article to understand how Read-only and Restricted-view roles work, which roles are available, and how to assign them. - [Map IdP Groups to Drata Roles](https://help.drata.com/en/articles/15235029-map-idp-groups-to-drata-roles.md) - [Role Administration & RBAC](https://help.drata.com/en/articles/8319053-role-administration-rbac.md): Find your assigned roles and learn the available roles. - [Information security leads overview](https://help.drata.com/en/articles/8863846-information-security-leads-overview.md): Learn more about information security lead role, permissions, and functionality in Drata. - [Risk managers overview](https://help.drata.com/en/articles/8885241-risk-managers-overview.md): Learn more about risk managers role, permissions, and functionality in Drata. - [Access reviewer overview](https://help.drata.com/en/articles/8885250-access-reviewer-overview.md): Learn more about access reviewers role, permissions, and functionality in Drata. - [Control managers overview](https://help.drata.com/en/articles/8885256-control-managers-overview.md): Learn more about control managers role, permissions, and functionality in Drata. - [Personnel compliance managers overview](https://help.drata.com/en/articles/8885268-personnel-compliance-managers-overview.md): Learn more about personnel compliance manager role, permissions, and functionality in Drata. - [Policy managers overview](https://help.drata.com/en/articles/8885275-policy-managers-overview.md): Learn more about policy manager role, permissions, and functionality in Drata. - [DevOps engineer overview](https://help.drata.com/en/articles/9548104-devops-engineer-overview.md) - [Trust Center Managers](https://help.drata.com/en/articles/10478927-trust-center-managers.md): In this help article, learn and discover the functionalities available to the Trust Center manager roles within Drata. - [Trust Center Reviewers](https://help.drata.com/en/articles/10478941-trust-center-reviewers.md): In this help article, learn and discover the functionalities available to the Trust Center reviewer role within Drata. ## Framework Information - [Frameworks](https://help.drata.com/en/articles/5329593-frameworks.md): Drata is expanding into multiple security frameworks, navigate to yours - [Marking Requirements In and Out of Scope](https://help.drata.com/en/articles/13765784-marking-requirements-in-and-out-of-scope.md): How to scope framework requirements to match your environment. - [Framework Readiness](https://help.drata.com/en/articles/13765790-framework-readiness.md): Understand how framework readiness is calculated and what you can do to keep your frameworks on track. - [Framework Requirements](https://help.drata.com/en/articles/6219885-framework-requirements.md): View and manage a framework's requirements. - [HITRUST e1/i1 Overview](https://help.drata.com/en/articles/12111426-hitrust-e1-i1-overview.md): Overview of HITRUST - [NIS2 Update: What ENISA’s New Guidance Means for You!](https://help.drata.com/en/articles/12150854-nis2-update-what-enisa-s-new-guidance-means-for-you.md) - [Level Picker for Frameworks with Tiered Requirements](https://help.drata.com/en/articles/6267523-level-picker-for-frameworks-with-tiered-requirements.md): How to scope frameworks with tiered requirements - [How to collect evidence for DCF-574: Mobile device management software](https://help.drata.com/en/articles/16402161-how-to-collect-evidence-for-dcf-574-mobile-device-management-software.md): Use this article to prepare evidence for DCF-574 in Drata. The control focuses on managing and protecting mobile devices used for company purposes. - [Troubleshooting Login Issues: Browser, Cache & Session Problems](https://help.drata.com/en/articles/16988712-troubleshooting-login-issues-browser-cache-session-problems.md): Step-by-step fixes for login failures caused by browser cache, cookies, sessions, or extensions. Try these before contacting support. - [Custom Framework](https://help.drata.com/en/articles/6346623-custom-framework.md): This article covers creating and managing Custom Frameworks. - [Framework Mapping Agent: AI-Assisted Control Mapping for Custom Frameworks](https://help.drata.com/en/articles/16630433-framework-mapping-agent-ai-assisted-control-mapping-for-custom-frameworks.md) - [ACSC Essential Eight Overview](https://help.drata.com/en/articles/12246682-acsc-essential-eight-overview.md): Overview of the ACSC Essential Eight cybersecurity strategies. - [ACSC Essential Eight: A Requirement-Level Guide](https://help.drata.com/en/articles/12430948-acsc-essential-eight-a-requirement-level-guide.md) - [Example Evidence for Not Monitored Controls \(Essential Eight\)](https://help.drata.com/en/articles/13112197-example-evidence-for-not-monitored-controls-essential-eight.md) - [APRA CPS 230 Overview](https://help.drata.com/en/articles/15863357-apra-cps-230-overview.md): Overview of APRA’s \(Australian Prudential Regulation Authority\) Prudential Standard CPS 230 Operational Risk Management. - [APRA CPS 230: Set Up Guidance \(APRA-Regulated Entity vs. Material Service Provider\)](https://help.drata.com/en/articles/15863587-apra-cps-230-set-up-guidance-apra-regulated-entity-vs-material-service-provider.md): How to scope Drata’s CPS 230 framework to match your organization’s role. - [APRA CPS 230: A Requirement-Level Guide](https://help.drata.com/en/articles/15865490-apra-cps-230-a-requirement-level-guide.md) - [Example Evidence for Not Monitored Controls \(CPS 230\)](https://help.drata.com/en/articles/15865530-example-evidence-for-not-monitored-controls-cps-230.md) - [CIS v8.1 Framework Overview](https://help.drata.com/en/articles/11145651-cis-v8-1-framework-overview.md) - [Example Evidence for Not Monitored Controls \(CIS 8.1\)](https://help.drata.com/en/articles/11510355-example-evidence-for-not-monitored-controls-cis-8-1.md): The following is a list of example evidence for controls not monitored in Drata for CIS 8.1. - [2023: CCPA Updates](https://help.drata.com/en/articles/7966747-2023-ccpa-updates.md): What you need to know about the latest updates to the CCPA framework in Drata - [CCPA 2026 Regulatory Updates: Recommended Enhancements to Drata Privacy Policy Templates](https://help.drata.com/en/articles/14080205-ccpa-2026-regulatory-updates-recommended-enhancements-to-drata-privacy-policy-templates.md) - [CMMC Framework Updates](https://help.drata.com/en/articles/9889456-cmmc-framework-updates.md): What you need to know about the CMMC framework updates releasing on 10/16/2024. - [Cyber Essentials v3.2: What’s Changed and How to Prepare](https://help.drata.com/en/articles/13188560-cyber-essentials-v3-2-what-s-changed-and-how-to-prepare.md): CE is a UK government-backed certification that helps organizations protect themselves from cyber threats. It focuses on 5 key areas: firewalls, secure setup, keeping software updated, controlling ... - [DORA ICT Risk Management Framework \(RMF\)](https://help.drata.com/en/articles/10512075-dora-ict-risk-management-framework-rmf.md) - [EU DORA Framework Overview](https://help.drata.com/en/articles/10512090-eu-dora-framework-overview.md) - [DORA's Five Pillars of Compliance](https://help.drata.com/en/articles/13346306-dora-s-five-pillars-of-compliance.md): The Digital Operational Resilience Act \(DORA\) is an EU Regulation aimed at ensuring financial entities can withstand, respond to, and recover from information and communication technology \(ICT\) dis... - [A guide to Drata's FedRAMP Readiness Framework](https://help.drata.com/en/articles/9095570-a-guide-to-drata-s-fedramp-readiness-framework.md) - [FedRAMP 20x: A Modernized Path to Federal Cloud Security Overview](https://help.drata.com/en/articles/12169241-fedramp-20x-a-modernized-path-to-federal-cloud-security-overview.md) - [GDPR: Where do I Start?](https://help.drata.com/en/articles/6116924-gdpr-where-do-i-start.md) - [Example Evidence for Not Monitored GDPR Controls](https://help.drata.com/en/articles/6468474-example-evidence-for-not-monitored-gdpr-controls.md) - [GDPR Requirements and Best Practices](https://help.drata.com/en/articles/13162424-gdpr-requirements-and-best-practices.md) - [HIPAA Checklist](https://help.drata.com/en/articles/12166173-hipaa-checklist.md) - [Example Evidence for Not Monitored Controls \(HIPAA\)](https://help.drata.com/en/articles/9421032-example-evidence-for-not-monitored-controls-hipaa.md): Example Evidence for Not Monitored Controls \(HIPAA\) - [ISO 27001:2022 Checklist](https://help.drata.com/en/articles/6129189-iso-27001-2022-checklist.md) - [ISO 27001:2013 Example ISMS Plan](https://help.drata.com/en/articles/7208412-iso-27001-2013-example-isms-plan.md) - [ISO 27001:2022 Example ISMS Plan](https://help.drata.com/en/articles/7208186-iso-27001-2022-example-isms-plan.md) - [ISO 27001:2022](https://help.drata.com/en/articles/6854626-iso-27001-2022.md): What you need to know about the latest version of ISO 27001 - [ISO 27001:2022 Updates as of 5/7/2024](https://help.drata.com/en/articles/9266246-iso-27001-2022-updates-as-of-5-7-2024.md) - [Security Engineering Principles](https://help.drata.com/en/articles/5732619-security-engineering-principles.md) - [Transition Guidance for ISO 27001:2013 to ISO 27001:2022](https://help.drata.com/en/articles/6871897-transition-guidance-for-iso-27001-2013-to-iso-27001-2022.md) - [Questions to ask a Potential ISO 27001 Certification Body \(i.e. Auditor\)](https://help.drata.com/en/articles/6967761-questions-to-ask-a-potential-iso-27001-certification-body-i-e-auditor.md) - [ISO 27001 Certification Review Template](https://help.drata.com/en/articles/7792143-iso-27001-certification-review-template.md) - [ISO 27001 Background Check FAQs](https://help.drata.com/en/articles/8032201-iso-27001-background-check-faqs.md) - [Example Evidence for Not Monitored Controls \(ISO 27001\) - Revised \(Following 5/7/2024 Updates\)](https://help.drata.com/en/articles/11895559-example-evidence-for-not-monitored-controls-iso-27001-revised-following-5-7-2024-updates.md) - [How to provide evidence for DCF-72: Root access control](https://help.drata.com/en/articles/16402002-how-to-provide-evidence-for-dcf-72-root-access-control.md): This article explains what evidence to provide in Drata when your organization needs to demonstrate that root access to production resources is restricted. - [ISO 27701:2019 Framework Updates](https://help.drata.com/en/articles/9592460-iso-27701-2019-framework-updates.md): What you need to know about the ISO 27701:2019 framework updates released on 7/11/2024 - [ISO 42001 Framework Overview](https://help.drata.com/en/articles/10927318-iso-42001-framework-overview.md) - [Ready for ISO 42001? Let’s Talk Next Steps](https://help.drata.com/en/articles/12591328-ready-for-iso-42001-let-s-talk-next-steps.md) - [Example Evidence for Not Monitored Controls \(ISO 42001\)](https://help.drata.com/en/articles/13874376-example-evidence-for-not-monitored-controls-iso-42001.md): Example Evidence for Not Monitored Controls \(ISO 42001\) - [Microsoft Supplier Security & Privacy Assurance \(SSPA\) Program v11 Overview](https://help.drata.com/en/articles/12480900-microsoft-supplier-security-privacy-assurance-sspa-program-v11-overview.md) - [Example Evidence Not Monitored Controls \(Microsoft Supplier Security and Privacy Assurance \(SSPA\)\)](https://help.drata.com/en/articles/12785838-example-evidence-not-monitored-controls-microsoft-supplier-security-and-privacy-assurance-sspa.md) - [NIST CSF 2.0](https://help.drata.com/en/articles/9854381-nist-csf-2-0.md) - [Example Evidence for Not Monitored Controls \(NIST CSF 2.0\)](https://help.drata.com/en/articles/15193889-example-evidence-for-not-monitored-controls-nist-csf-2-0.md) - [NIST SP 800-171 Rev. 2 Framework Updates](https://help.drata.com/en/articles/9833774-nist-sp-800-171-rev-2-framework-updates.md) - [Example Evidence for Not Monitored Controls \(NIST 800-171 Rev 3\)](https://help.drata.com/en/articles/11818965-example-evidence-for-not-monitored-controls-nist-800-171-rev-3.md) - [NIST SP 800-171 Rev. 2 Self-Assessment](https://help.drata.com/en/articles/14724964-nist-sp-800-171-rev-2-self-assessment.md) - [NIST SP 800-53 \(Rev. 5\) Control & Policy Mapping Updates](https://help.drata.com/en/articles/6933260-nist-sp-800-53-rev-5-control-policy-mapping-updates.md): What you need to know about the latest updates to the NIST SP 800-53r5 framework in Drata - [System Security Planning Policy Guidance](https://help.drata.com/en/articles/9981031-system-security-planning-policy-guidance.md) - [Example Evidence for Not Monitored Controls \(NIST 800-53r5\)](https://help.drata.com/en/articles/8381076-example-evidence-for-not-monitored-controls-nist-800-53r5.md) - [PCI DSS v4.0](https://help.drata.com/en/articles/8732413-pci-dss-v4-0.md) - [Required Documentation for PCI DSS](https://help.drata.com/en/articles/6038558-required-documentation-for-pci-dss.md) - [PCI DSS v4.0.1 Updates: What You Need to Know](https://help.drata.com/en/articles/10670101-pci-dss-v4-0-1-updates-what-you-need-to-know.md): This article provides an overview of the updates in PCI DSS v4.0.1. - [PCI DSS v4.0.1 Targeted Risk Analysis \(TRA\)](https://help.drata.com/en/articles/11327376-pci-dss-v4-0-1-targeted-risk-analysis-tra.md) - [PCI DSS v4.0.1 Checklist](https://help.drata.com/en/articles/11725681-pci-dss-v4-0-1-checklist.md): A checklist for achieving PCI DSS within Drata - [PCI DSS v4.0.1 Responsibility Matrix Guidance](https://help.drata.com/en/articles/11734403-pci-dss-v4-0-1-responsibility-matrix-guidance.md) - [Example Evidence for Not Monitored Controls \(PCI DSS v4.0.1 \)](https://help.drata.com/en/articles/11090161-example-evidence-for-not-monitored-controls-pci-dss-v4-0-1.md) - [SOC 2 Checklist](https://help.drata.com/en/articles/8168169-soc-2-checklist.md): A checklist for achieving SOC 2 within Drata - [SOC 2 Trust Services Categories Overview](https://help.drata.com/en/articles/5947518-soc-2-trust-services-categories-overview.md) - [SOC 2 Background Checks FAQs](https://help.drata.com/en/articles/5732624-soc-2-background-checks-faqs.md) - [Questions to ask a potential SOC 2 auditor](https://help.drata.com/en/articles/5732618-questions-to-ask-a-potential-soc-2-auditor.md) - [What to look for when reviewing your draft SOC 2 report](https://help.drata.com/en/articles/5566748-what-to-look-for-when-reviewing-your-draft-soc-2-report.md) - [SOC 2 Updates as of 5/7/2024](https://help.drata.com/en/articles/9265872-soc-2-updates-as-of-5-7-2024.md) - [SOC 2 System Description](https://help.drata.com/en/articles/6458424-soc-2-system-description.md) - [Reviewing Your Vendors' SOC 2 Reports Using Drata](https://help.drata.com/en/articles/7065036-reviewing-your-vendors-soc-2-reports-using-drata.md) - [SOC 2 Type 1 vs Type 2: Which Audit Type Should I Choose](https://help.drata.com/en/articles/8272685-soc-2-type-1-vs-type-2-which-audit-type-should-i-choose.md) - [SOC 2: All controls](https://help.drata.com/en/articles/5329618-soc-2-all-controls.md): Templated controls pre-mapped to SOC 2 criteria spanning all 5 TSCs - [Set SOC 2 Trust Service Criteria to Security Only](https://help.drata.com/en/articles/8892480-set-soc-2-trust-service-criteria-to-security-only.md) - [What Is a SOC 2 Bridge Letter? \[+ Template\]](https://help.drata.com/en/articles/10697841-what-is-a-soc-2-bridge-letter-template.md): SOC 2 Bridge Letter Guidance and Template - [Example Evidence for Not Monitored Controls \(SOC 2\)](https://help.drata.com/en/articles/9421165-example-evidence-for-not-monitored-controls-soc-2.md): Example Evidence for Not Monitored Controls \(SOC 2\) - [Evidence for SOC 2 Compliance: Managed Platforms and Application Configurations](https://help.drata.com/en/articles/11887346-evidence-for-soc-2-compliance-managed-platforms-and-application-configurations.md) ## Connection Support - [Understanding Azure Permissions and How Drata Integrates with Azure \(Concept Guide\)](https://help.drata.com/en/articles/13455183-understanding-azure-permissions-and-how-drata-integrates-with-azure-concept-guide.md): Learn how Azure tenants, subscriptions, Microsoft Graph permissions, and RBAC roles work together in the Drata Azure integration. - [Understanding AWS Permissions and How Drata Integrates with AWS \(Concept Guide\)](https://help.drata.com/en/articles/13455825-understanding-aws-permissions-and-how-drata-integrates-with-aws-concept-guide.md) - [Understanding GCP Permissions and How Drata Integrates with GCP \(Concept Guide\)](https://help.drata.com/en/articles/13456365-understanding-gcp-permissions-and-how-drata-integrates-with-gcp-concept-guide.md) - [Workday Implementation Best Practices](https://help.drata.com/en/articles/14092393-workday-implementation-best-practices.md) - [Drata Public API](https://help.drata.com/en/articles/6695964-drata-public-api.md): This article covers how to configure Drata Public API - [Drata Public API: Upload Evidence for a User](https://help.drata.com/en/articles/7213389-drata-public-api-upload-evidence-for-a-user.md): This article shows how to upload training-related evidence \(for example, Security, HIPAA, or NIST AI training\) for a specific Drata user. - [Drata Public API: Workspace ID for POST or PUT Requests](https://help.drata.com/en/articles/7213398-drata-public-api-workspace-id-for-post-or-put-requests.md): This article covers how to identify your workspace ID to make a POST or PUT request using the Drata Open API. - [Drata Public API: Get Event Data from Drata](https://help.drata.com/en/articles/7213411-drata-public-api-get-event-data-from-drata.md): This article shows how to retrieve event tracking data from Drata. - [Drata Public API: Get All Controls](https://help.drata.com/en/articles/7213418-drata-public-api-get-all-controls.md): This article shows how to retrieve all controls from Drata. - [Set up OAuth for the Drata API](https://help.drata.com/en/articles/13521519-set-up-oauth-for-the-drata-api.md): Learn how to configure and use OAuth 2.0 Client Credentials to securely authenticate API requests to Drata, which is the recommended method for machine-to-machine and enterprise integrations. - [CyberArk Integration Guide](https://help.drata.com/en/articles/9572918-cyberark-integration-guide.md) - [Google Workspace Integration Guide](https://help.drata.com/en/articles/4663303-google-workspace-integration-guide.md): Learn how to connect Google Workspace to Drata as an Identity Provider \(IdP\). - [JumpCloud IdP Integration Guide](https://help.drata.com/en/articles/6994385-jumpcloud-idp-integration-guide.md) - [Manual Import \(CSV\) Identity Provider Integration Guide](https://help.drata.com/en/articles/8231902-manual-import-csv-identity-provider-integration-guide.md): In this article, you learn how to upload personnel data into Drata using a CSV file when your organization uses an unsupported Identity Provider. - [Microsoft 365 Integration Guide](https://help.drata.com/en/articles/4797766-microsoft-365-integration-guide.md): Making the initial connection to Microsoft 365 - [Okta Integration Guide \(Identity Management Provider\)](https://help.drata.com/en/articles/5608136-okta-integration-guide-identity-management-provider.md) - [OneLogin Integration Guide](https://help.drata.com/en/articles/6848987-onelogin-integration-guide.md) - [PingOne Integration Guide](https://help.drata.com/en/articles/10478681-pingone-integration-guide.md): Connecting PingOne to Drata allows personnel to be synchronized into Drata and to provision accounts for each. - [AWS Org Units Connection Instructions](https://help.drata.com/en/articles/8981943-aws-org-units-connection-instructions.md) - [AWS GovCloud Integration Guide](https://help.drata.com/en/articles/8579862-aws-govcloud-integration-guide.md) - [Azure Integration Guide](https://help.drata.com/en/articles/5032404-azure-integration-guide.md): Connect Azure \(Microsoft Entra\) to perform streamlined access reviews and automate evidence collection for infrastructure security controls. - [Azure Management Groups Integration Guide](https://help.drata.com/en/articles/9762686-azure-management-groups-integration-guide.md) - [Cloudflare Integration Guide \(Infrastructure and UAR\)](https://help.drata.com/en/articles/5455086-cloudflare-integration-guide-infrastructure-and-uar.md): Making the initial connection to Cloudflare - [DigitalOcean Integration Guide](https://help.drata.com/en/articles/5108924-digitalocean-integration-guide.md): Making the initial connection to DigitalOcean - [GCP Integration Guide \(Manual\)](https://help.drata.com/en/articles/4994112-gcp-integration-guide-manual.md): How to manually connect GCP to Drata. - [GCP Integration Guide \(Script Setup\)](https://help.drata.com/en/articles/4663373-gcp-integration-guide-script-setup.md): Use Drata’s automated script to connect GCP for access reviews and infrastructure monitoring. - [Heroku Integration Guide](https://help.drata.com/en/articles/5155248-heroku-integration-guide.md): Making the initial connection to Heroku - [MongoDB Atlas Integration Guide](https://help.drata.com/en/articles/5310322-mongodb-atlas-integration-guide.md): Making the initial connection to Mongo DB Atlas - [AWS CodeCommit Integration Guide](https://help.drata.com/en/articles/5867505-aws-codecommit-integration-guide.md): This article walks through the details of configuring AWS CodeCommit to connect to Drata. - [Azure Repos \(DevOps\) Integration Guide](https://help.drata.com/en/articles/5495253-azure-repos-devops-integration-guide.md): Making the initial connection to Azure Repos \(DevOps\) - [BitBucket Integration Guide](https://help.drata.com/en/articles/4939180-bitbucket-integration-guide.md): Learn how to connect BitBucket to Drata. This connection supports the following types: Codebase, Ticketing, User Access Review, Version Control. - [GitHub Integration Guide](https://help.drata.com/en/articles/4663377-github-integration-guide.md): Making the initial connection to GitHub - [GitHub Enterprise Server Integration Guide](https://help.drata.com/en/articles/9265902-github-enterprise-server-integration-guide.md) - [GitLab Integration Guide](https://help.drata.com/en/articles/5188769-gitlab-integration-guide.md): Learn how to connect GitLab to Drata. - [GitLab self-managed Integration Guide](https://help.drata.com/en/articles/9777474-gitlab-self-managed-integration-guide.md) - [Asana Integration Guide](https://help.drata.com/en/articles/5008063-asana-integration-guide.md): Making the initial connection to Asana - [Azure Boards \(DevOps\) Integration Guide](https://help.drata.com/en/articles/5495282-azure-boards-devops-integration-guide.md): Making the initial connection to Azure Boards \(DevOps\) - [ClickUp Integration Guide](https://help.drata.com/en/articles/10105116-clickup-integration-guide.md): Learn how to connect ClickUp to Drata to create and manage security tasks directly from Drata. - [Fibery Integration Guide](https://help.drata.com/en/articles/5968610-fibery-integration-guide.md): Making the initial connection to Fibery - [GitHub Issues Integration Guide](https://help.drata.com/en/articles/4806987-github-issues-integration-guide.md): Making the initial connection to GitHub Issues - [GitHub Issues Enterprise Integration Guide](https://help.drata.com/en/articles/10003287-github-issues-enterprise-integration-guide.md): Making the initial connection to GitHub Issues Enterprise - [GitLab Issues Integration Guide](https://help.drata.com/en/articles/5193741-gitlab-issues-integration-guide.md): Making the initial connection to GitLab Issues - [GitLab Issues \(Self-Managed\) Integration Guide](https://help.drata.com/en/articles/10003324-gitlab-issues-self-managed-integration-guide.md): Making the initial connection to GitLab Issues self-managed - [Jira Data Center Integration](https://help.drata.com/en/articles/13918516-jira-data-center-integration.md) - [Jira Integration Guide](https://help.drata.com/en/articles/4663378-jira-integration-guide.md) - [Linear Integration Guide](https://help.drata.com/en/articles/5224671-linear-integration-guide.md): Making the initial connection to Linear - [ServiceNow Integration Guide](https://help.drata.com/en/articles/7939967-servicenow-integration-guide.md) - [Shortcut Integration Guide](https://help.drata.com/en/articles/4663379-shortcut-integration-guide.md): Making the initial connection to Shortcut - [Target Process Integration Guide](https://help.drata.com/en/articles/5350736-target-process-integration-guide.md): Making the initial connection to Target Process - [Trello Integration Guide](https://help.drata.com/en/articles/5176303-trello-integration-guide.md): In this article, you learn how to connect Trello to Drata for vulnerability management monitoring. - [Zoho Bug Tracker Integration Guide](https://help.drata.com/en/articles/5455033-zoho-bug-tracker-integration-guide.md): Making the initial connection Zoho BugTracker - [Zoho Desk Integration Guide \(Ticketing & UAR\)](https://help.drata.com/en/articles/10984714-zoho-desk-integration-guide-ticketing-uar.md): Create Zoho Desk tickets through Drata associated with risks, controls, or tests. - [Freshservice Integration Guide](https://help.drata.com/en/articles/13611532-freshservice-integration-guide.md) - [Ticket Automation \(Jira-only\) \(New experience\)](https://help.drata.com/en/articles/13688644-ticket-automation-jira-only-new-experience.md): Configure rules to automatically create Jira tickets based on control and test events. - [1Password Integration Guide](https://help.drata.com/en/articles/9868870-1password-integration-guide.md) - [15Five Integration Guide](https://help.drata.com/en/articles/9773995-15five-integration-guide.md): Connect 15Five to Drata with an API key to automate user access reviews. - [360Learning Integration Guide](https://help.drata.com/en/articles/12591181-360learning-integration-guide.md) - [ADP Workforce Now Integration Guide](https://help.drata.com/en/articles/6134114-adp-workforce-now-integration-guide.md): Integrate ADP Workforce Now with Drata to sync hire dates, terminations, and employment status for access reviews. - [Aikido Integration Guide](https://help.drata.com/en/articles/9791674-aikido-integration-guide.md): Category Type: CSPM & Vulnerability Scanning. - [Aircall Integration Guide](https://help.drata.com/en/articles/9967703-aircall-integration-guide.md): Connect Aircall to Drata with API credentials to automate user access reviews and reduce manual work. - [Ansible Tower Integration Guide](https://help.drata.com/en/articles/9971446-ansible-tower-integration-guide.md) - [Anthropic Integration Guide](https://help.drata.com/en/articles/10595356-anthropic-integration-guide.md) - [Arnica Integration Guide](https://help.drata.com/en/articles/10258613-arnica-integration-guide.md): Connect Arnica to Drata to sync vulnerabilities with an API token and automate evidence for vulnerability scanning. - [Articulate Integration Guide](https://help.drata.com/en/articles/9971410-articulate-integration-guide.md) - [Ashby Integration Guide](https://help.drata.com/en/articles/9300531-ashby-integration-guide.md) - [Atlassian Integration Guide](https://help.drata.com/en/articles/9242322-atlassian-integration-guide.md) - [Attio Integration Guide](https://help.drata.com/en/articles/9300539-attio-integration-guide.md) - [Autodesk Integration Guide](https://help.drata.com/en/articles/9437789-autodesk-integration-guide.md): Follow these steps to connect Autodesk - [AWS Inspector \(Amazon Inspector\) Integration Guide](https://help.drata.com/en/articles/6619770-aws-inspector-amazon-inspector-integration-guide.md): This article walks through the details of configuring AWS Inspector to connect to Drata. - [AWS Integration Guide \(Infrastructure, User Access Review\)](https://help.drata.com/en/articles/5048935-aws-integration-guide-infrastructure-user-access-review.md): This article walks through the details of configuring AWS to connect to Drata. - [BambooHR Integration Guide](https://help.drata.com/en/articles/5122726-bamboohr-integration-guide.md): Making the initial connection to BambooHR - [Bitwarden Integration Guide](https://help.drata.com/en/articles/9300550-bitwarden-integration-guide.md): Learn how to connect Bitwarden to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Bob \(HiBob\) Integration Guide](https://help.drata.com/en/articles/5457902-bob-hibob-integration-guide.md): Making the initial connection to Bob - [Box Integration Guide](https://help.drata.com/en/articles/10594278-box-integration-guide.md): Learn how to connect Box to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Bullhorn Integration Guide](https://help.drata.com/en/articles/9774077-bullhorn-integration-guide.md): Learn how to connect Bullhorn to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Canva Integration Guide](https://help.drata.com/en/articles/9300560-canva-integration-guide.md): Learn how to connect Canva to Drata. This connection supports the following types: Access Reviews \(UAR\) - [Certn Integration Guide \(Background Check\)](https://help.drata.com/en/articles/4972294-certn-integration-guide-background-check.md): Learn how to connect Certn to Drata to background checks and store screening summaries for compliance workflows. - [Checkr Integration Guide](https://help.drata.com/en/articles/5409416-checkr-integration-guide.md): Making the initial connection to Checkr \(BG Checks\) - [ClearCompany \(formerly Brainer\)](https://help.drata.com/en/articles/12590328-clearcompany-formerly-brainer.md) - [Confluence Integration Guide](https://help.drata.com/en/articles/9293760-confluence-integration-guide.md) - [Contentful Integration Guide](https://help.drata.com/en/articles/9300564-contentful-integration-guide.md) - [Cornerstone Integration Guide](https://help.drata.com/en/articles/12590630-cornerstone-integration-guide.md) - [Coursera Integration Guide](https://help.drata.com/en/articles/12591186-coursera-integration-guide.md) - [Coverdash Integration Guide](https://help.drata.com/en/articles/9307061-coverdash-integration-guide.md) - [CrowdStrike Falcon Exposure Management Integration Guide](https://help.drata.com/en/articles/9750517-crowdstrike-falcon-exposure-management-integration-guide.md): This article walks through the details of configuring CrowdStrike Falcon Exposure Management to connect to Drata. - [CrowdStrike Integration Guide](https://help.drata.com/en/articles/9175449-crowdstrike-integration-guide.md) - [Databricks Integration Guide \(UAR\)](https://help.drata.com/en/articles/9971603-databricks-integration-guide-uar.md) - [Datadog Integration Guide](https://help.drata.com/en/articles/6414118-datadog-integration-guide.md): This article describes how to set up a Datadog Connection for the first time within Drata. - [Dayforce Integration Guide \(HRIS\)](https://help.drata.com/en/articles/13172315-dayforce-integration-guide-hris.md) - [Dialpad Integration Guide](https://help.drata.com/en/articles/9774311-dialpad-integration-guide.md): Learn how to connect Dialpad to Drata. This connection supports the following types: User Access Reviews \(UAR\) - [Dixa Integration Guide](https://help.drata.com/en/articles/9300568-dixa-integration-guide.md): Learn how to connect Dixa to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Docebo Integration Guide](https://help.drata.com/en/articles/12590631-docebo-integration-guide.md) - [DocuSign Integration Guide](https://help.drata.com/en/articles/6513179-docusign-integration-guide.md): Learn how to connect DocuSign to Drata to automatically send NDAs to Trust Center requesters before granting access to private documents. - [Domo Integration Guide](https://help.drata.com/en/articles/9769700-domo-integration-guide.md) - [Dropbox Integration Guide](https://help.drata.com/en/articles/10594382-dropbox-integration-guide.md) - [Dropbox Sign Integration Guide](https://help.drata.com/en/articles/10594472-dropbox-sign-integration-guide.md) - [Duo Integration Guide](https://help.drata.com/en/articles/9788421-duo-integration-guide.md) - [EasyLlama Integration Guide](https://help.drata.com/en/articles/12048164-easyllama-integration-guide.md) - [Egnyte Integration Guide \(UAR\)](https://help.drata.com/en/articles/9769774-egnyte-integration-guide-uar.md) - [Elastic Integration Guide](https://help.drata.com/en/articles/9737185-elastic-integration-guide.md): Learn how to connect Elastic to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Envoy Integration Guide](https://help.drata.com/en/articles/9769744-envoy-integration-guide.md) - [Fivetran Integration Guide](https://help.drata.com/en/articles/9773743-fivetran-integration-guide.md): Learn how to connect Fivetran to Drata. This connection supports the following types: Access Reviews \(UAR\). - [Freshsales Integration Guide \(UAR\)](https://help.drata.com/en/articles/9300570-freshsales-integration-guide-uar.md) - [Freshteam Integration Guide](https://help.drata.com/en/articles/5216108-freshteam-integration-guide.md): Making the initial connection to Freshteam - [Greenhouse Integration Guide](https://help.drata.com/en/articles/9300574-greenhouse-integration-guide.md): Learn how to reconnect your Greenhouse connection in Drata using Harvest v3 \(OAuth\). This connection supports the following types: User Access Reviews \(UAR\). - [GitLab VMS Integration Guide](https://help.drata.com/en/articles/13563755-gitlab-vms-integration-guide.md): Connection type: Vulnerability - [GO1 Integration Guide](https://help.drata.com/en/articles/12590635-go1-integration-guide.md) - [Gong Integration Guide](https://help.drata.com/en/articles/9788444-gong-integration-guide.md): Learn how to connect Gong to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Google Workspace Integration Guide \(User Access Reviews\)](https://help.drata.com/en/articles/9912594-google-workspace-integration-guide-user-access-reviews.md) - [Gusto Integration Guide](https://help.drata.com/en/articles/4663382-gusto-integration-guide.md): Making the initial connection to Gusto \(HRIS\) - [Harvest Integration Guide](https://help.drata.com/en/articles/10595243-harvest-integration-guide.md) - [Hexnode UEM \(macOS\) Integration Guide](https://help.drata.com/en/articles/6063710-hexnode-uem-macos-integration-guide.md): This article covers setting up Hexnode UEM and connecting that to Drata - [Hexnode UEM \(Windows\) Integration Guide](https://help.drata.com/en/articles/6093793-hexnode-uem-windows-integration-guide.md): This article covers how to connect Hexnode UEM \(Windows\) to Drata. - [HireRight Integration Guide](https://help.drata.com/en/articles/9797693-hireright-integration-guide.md) - [HR Cloud Integration Guide](https://help.drata.com/en/articles/5523165-hr-cloud-integration-guide.md): Making the initial connection to HR Cloud - [HubSpot Integration Guide \(UAR\)](https://help.drata.com/en/articles/8987926-hubspot-integration-guide-uar.md): User Access Review connection: Connect Hubspot to Drata to review the list of users with access to Hubspot in your organization. - [Huntress \(Security Training\) Integration Guide](https://help.drata.com/en/articles/6005532-huntress-security-training-integration-guide.md): This article covers steps to connect Huntress security training to Drata. - [Infosec IQ Integration Guide](https://help.drata.com/en/articles/12694474-infosec-iq-integration-guide.md) - [Intercom Integration Guide](https://help.drata.com/en/articles/9773756-intercom-integration-guide.md): Learn how to connect Intercom to Drata to automate User Access Reviews by syncing Intercom user data. - [Ironclad Integration Guide \(UAR\)](https://help.drata.com/en/articles/9971800-ironclad-integration-guide-uar.md) - [Jamf Integration Guide](https://help.drata.com/en/articles/5456409-jamf-integration-guide.md): This article walks through the details of configuring Jamf to connect to Drata. - [JetBrains Integration Guide](https://help.drata.com/en/articles/9773698-jetbrains-integration-guide.md): Learn how to connect JetBrains Space to Drata. This connection supports the following types: Access Reviews \(UAR\). - [Jit Integration Guide](https://help.drata.com/en/articles/10924492-jit-integration-guide.md): Learn how to connect Jit to Drata to automatically send SOC 2 security evidence and technical control reports. - [JumpCloud Integration Guide \(MDM\)](https://help.drata.com/en/articles/5872265-jumpcloud-integration-guide-mdm.md): This article walks through the details of configuring JumpCloud MDM to connect to Drata. - [Justworks Integration Guide](https://help.drata.com/en/articles/5216094-justworks-integration-guide.md): Learn how to connect Justworks to Drata. This connection supports the following types: HRIS. - [Kameleoon Integration Guide](https://help.drata.com/en/articles/10706532-kameleoon-integration-guide.md): Learn how to connect Kameleoon to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Kandji \(now Iru\) Integration Guide \(MDM\)](https://help.drata.com/en/articles/5831405-kandji-now-iru-integration-guide-mdm.md): This article covers how to connect Kandji to Drata. - [KarmaCheck Integration Guide](https://help.drata.com/en/articles/4663387-karmacheck-integration-guide.md): Making the initial connection to KarmaCheck \(BG Checks\) - [Klaviyo Integration Guide](https://help.drata.com/en/articles/9300607-klaviyo-integration-guide.md): Learn how to connect Klaviyo to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [1Password Device Trust \(Kolide\) Integration Guide](https://help.drata.com/en/articles/10298210-1password-device-trust-kolide-integration-guide.md) - [KnowBe4 Integration Guide](https://help.drata.com/en/articles/6204182-knowbe4-integration-guide.md): This article covers steps to connect KnowBe4 security training to Drata. - [Lacework Integration Guide \(UAR\)](https://help.drata.com/en/articles/9868921-lacework-integration-guide-uar.md) - [Lattice Integration Guide](https://help.drata.com/en/articles/9868995-lattice-integration-guide.md) - [Lattice HRIS Integration Guide](https://help.drata.com/en/articles/13922636-lattice-hris-integration-guide.md) - [LastPass Integration Guide](https://help.drata.com/en/articles/9300616-lastpass-integration-guide.md) - [Leapsome Integration Guide](https://help.drata.com/en/articles/9300676-leapsome-integration-guide.md) - [Lever Integration Guide](https://help.drata.com/en/articles/9300698-lever-integration-guide.md): Learn how to connect Lever to Drata. This connection supports the following types: HRIS - [LinkedIn Learning Integration Guide](https://help.drata.com/en/articles/12590650-linkedin-learning-integration-guide.md) - [Make Integration Guide](https://help.drata.com/en/articles/10595092-make-integration-guide.md) - [MeisterTask Integration Guide \(UAR\)](https://help.drata.com/en/articles/9774138-meistertask-integration-guide-uar.md) - [Miro Integration](https://help.drata.com/en/articles/8987864-miro-integration.md): User Access Review connection: Connect Miro to Drata to review the list of users with access to Miro in your organization. - [Microsoft Defender Vulnerability Management Integration Guide](https://help.drata.com/en/articles/9750519-microsoft-defender-vulnerability-management-integration-guide.md): This article walks through the details of configuring Microsoft Defender Vulnerability \(MS Defender VMS\) Management to connect to Drata. - [Microsoft Intune Integration guide](https://help.drata.com/en/articles/16190016-microsoft-intune-integration-guide.md): Use this guide to connect Microsoft Intune to Drata so Drata can evaluate device compliance for supported policy checks. - [Legacy: Microsoft Intune Integration Guide \(Mac Devices\)](https://help.drata.com/en/articles/5899473-legacy-microsoft-intune-integration-guide-mac-devices.md): This article covers setting up Intune for macOS devices. - [Legacy: Microsoft Intune Integration Guide \(Windows\)](https://help.drata.com/en/articles/5604949-legacy-microsoft-intune-integration-guide-windows.md): This article walks through the details of configuring Intune to connect to Drata. - [Microsoft Teams Integration Guide](https://help.drata.com/en/articles/6556025-microsoft-teams-integration-guide.md): Drata Microsoft Teams App Support. - [Mixpanel Integration Guide](https://help.drata.com/en/articles/9869007-mixpanel-integration-guide.md) - [Netlify Integration Guide \(User Access Review\)](https://help.drata.com/en/articles/10302115-netlify-integration-guide-user-access-review.md): Follow these steps to connect Netlify to Drata. - [New Relic Integration Guide](https://help.drata.com/en/articles/7830080-new-relic-integration-guide.md): This article describes how to set up a New Relic Connection for the first time within Drata. - [Notion Integration Guide](https://help.drata.com/en/articles/9294590-notion-integration-guide.md) - [Okta Integration Guide \(User Access Review\)](https://help.drata.com/en/articles/8542832-okta-integration-guide-user-access-review.md): Connect Okta as an user access review \(UAR\) connection type - [Oneflow Integration Guide \(UAR\)](https://help.drata.com/en/articles/9774273-oneflow-integration-guide-uar.md) - [OpenAI Integration Guide](https://help.drata.com/en/articles/10302063-openai-integration-guide.md): Follow these steps to connect OpenAI to Drata. - [OpenVPN Integration Guide](https://help.drata.com/en/articles/9972197-openvpn-integration-guide.md): Learn how to connect OpenVPN to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Oracle HCM Integration Guide](https://help.drata.com/en/articles/9300723-oracle-hcm-integration-guide.md) - [Orca Security Integration Guide](https://help.drata.com/en/articles/13131033-orca-security-integration-guide.md): Connection type: Vulnerability - [PagerDuty Integration Guide](https://help.drata.com/en/articles/13171491-pagerduty-integration-guide.md) - [Paycom Integration Guide \(HRIS\)](https://help.drata.com/en/articles/14426678-paycom-integration-guide-hris.md) - [Paylocity Integration Guide](https://help.drata.com/en/articles/5260586-paylocity-integration-guide.md): Making the initial connection to Paylocity - [PeopleFluent Integration Guide](https://help.drata.com/en/articles/12694502-peoplefluent-integration-guide.md) - [Pipedrive Integration Guide](https://help.drata.com/en/articles/9300814-pipedrive-integration-guide.md) - [Pinpoint Integration Guide](https://help.drata.com/en/articles/9300756-pinpoint-integration-guide.md): Learn how to connect Pinpoint to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Qlik Integration Guide](https://help.drata.com/en/articles/9774060-qlik-integration-guide.md) - [Qualys Integration Guide](https://help.drata.com/en/articles/9750514-qualys-integration-guide.md): Learn how to connect Qualys to Drata to automate vulnerability monitoring and compliance evidence collection. - [Rapid7 InsightVM \(On-Prem, Reports-Only\) Integration Guide](https://help.drata.com/en/articles/8180134-rapid7-insightvm-on-prem-reports-only-integration-guide.md): This article walks through the details of configuring Rapid7 InsightVM to connect to Drata. - [Rapid7 InsightVM Integration Guide](https://help.drata.com/en/articles/9750520-rapid7-insightvm-integration-guide.md): This article walks through the details of configuring Rapid7 InsightVM to connect to Drata. - [Recruitee Integration Guide](https://help.drata.com/en/articles/9300816-recruitee-integration-guide.md): In this article, you learn how to integrate Recruitee with Drata to automate user access reviews and monitor access for compliance purposes. - [Render Integration Guide](https://help.drata.com/en/articles/9769676-render-integration-guide.md): Learn how to connect Render to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Retool Integration Guide](https://help.drata.com/en/articles/10595138-retool-integration-guide.md) - [RingCentral Integration Guide](https://help.drata.com/en/articles/9774278-ringcentral-integration-guide.md): Learn how to connect RingCentral to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Rippling Integration Guide \(HRIS, MDM, UAR\)](https://help.drata.com/en/articles/5014534-rippling-integration-guide-hris-mdm-uar.md): Making the initial connection to Rippling - [Rollbar Integration Guide](https://help.drata.com/en/articles/9967708-rollbar-integration-guide.md) - [Salesforce Integration Guide \(User Access Review\)](https://help.drata.com/en/articles/9923104-salesforce-integration-guide-user-access-review.md) - [Salesloft Integration Guide](https://help.drata.com/en/articles/9300819-salesloft-integration-guide.md) - [SAP SuccessFactors Integration Guide](https://help.drata.com/en/articles/12600565-sap-successfactors-integration-guide.md) - [Scaleway Integration Guide](https://help.drata.com/en/articles/9769775-scaleway-integration-guide.md): Learn how to connect Scaleway to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Segment Integration Guide](https://help.drata.com/en/articles/8987892-segment-integration-guide.md): Learn how to connect Segment to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Semgrep Integration Guide](https://help.drata.com/en/articles/9750516-semgrep-integration-guide.md): This article walks through the details of configuring Semgrep to connect to Drata. - [SendGrid Integration Guide](https://help.drata.com/en/articles/9794365-sendgrid-integration-guide.md) - [Sentry Integration Guide](https://help.drata.com/en/articles/8987934-sentry-integration-guide.md): User Access Review connection: Connect Sentry to Drata to review the list of users with access to Sentry in your organization. - [SentinelOne \(EDR\) Integration Guide](https://help.drata.com/en/articles/8348773-sentinelone-edr-integration-guide.md): This article covers how to connect SentinelOne EDR to Drata. - [SentinelOne Singularity Vulnerability Management \(VMS\) Integration Guide](https://help.drata.com/en/articles/9750518-sentinelone-singularity-vulnerability-management-vms-integration-guide.md): This article walks through the details of configuring SentinelOne VMS to connect to Drata. - [Single Sign-On Connection](https://help.drata.com/en/articles/5209416-single-sign-on-connection.md): Making the initial connection to an SSO app - [Slack Integration Guide \(Communication and UAR\)](https://help.drata.com/en/articles/6425963-slack-integration-guide-communication-and-uar.md): This article covers connecting and configuring Slack for company notifications. - [SmartRecruiters Integration Guide](https://help.drata.com/en/articles/9236583-smartrecruiters-integration-guide.md) - [Smartsheet Integration Guide](https://help.drata.com/en/articles/9972027-smartsheet-integration-guide.md): Learn how to connect Smartsheet to Drata. This connection supports the following types: Access Reviews \(UAR\). - [Snowflake Integration Guide](https://help.drata.com/en/articles/8987822-snowflake-integration-guide.md): User Access Review connection: Connect Snowflake to Drata to review the list of users with access to Snowflake in your organization. - [Snyk Integration Guide](https://help.drata.com/en/articles/9750513-snyk-integration-guide.md): This article walks through the details of configuring Snyk to connect to Drata. - [SonarCloud Integration Guide](https://help.drata.com/en/articles/9869023-sonarcloud-integration-guide.md) - [Sophos Integration Guide](https://help.drata.com/en/articles/9972145-sophos-integration-guide.md): Learn how to connect Sophos to Drata to automate User Access Reviews by syncing user data from Sophos. - [Sterling Integration Guide](https://help.drata.com/en/articles/9803828-sterling-integration-guide.md) - [Tableau Integration Guide](https://help.drata.com/en/articles/9774359-tableau-integration-guide.md): Learn how to connect Tableau to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [TalentLMS Integration Guide](https://help.drata.com/en/articles/9774255-talentlms-integration-guide.md): Learn how to connect TalentLMS to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Teamtailor Integration Guide](https://help.drata.com/en/articles/9236588-teamtailor-integration-guide.md) - [TeamViewer \(Remote\) Integration Guide](https://help.drata.com/en/articles/9972130-teamviewer-remote-integration-guide.md): Learn how to connect TeamViewer to Drata to automate User Access Reviews by syncing user data from TeamViewer. - [Tenable Vulnerability Management Integration Guide](https://help.drata.com/en/articles/9750515-tenable-vulnerability-management-integration-guide.md): This article walks through the details of configuring Tenable Vulnerability Management to connect to Drata. - [Terraform Integration Guide](https://help.drata.com/en/articles/9769688-terraform-integration-guide.md) - [Toggl Integration Guide](https://help.drata.com/en/articles/10595224-toggl-integration-guide.md): Learn how to connect Toggl to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [TriNet Integration Guide](https://help.drata.com/en/articles/5455179-trinet-integration-guide.md): Making the initial connection to Trinet - [Twilio Integration Guide](https://help.drata.com/en/articles/10302032-twilio-integration-guide.md): Follow these steps to connect Twilio to Drata. - [Udemy Integration Guide](https://help.drata.com/en/articles/12702488-udemy-integration-guide.md) - [UKG Ready Integration Guide](https://help.drata.com/en/articles/14229348-ukg-ready-integration-guide.md): Learn how to connect UKG Ready to Drata to sync personnel data from your HRIS. This connection supports the following types: HRIS. - [UKG Pro Integration Guide](https://help.drata.com/en/articles/6994418-ukg-pro-integration-guide.md): Making the initial connection to UKG Pro - [Upwind Integration Guide](https://help.drata.com/en/articles/13170986-upwind-integration-guide.md) - [Vercel Integration Guide](https://help.drata.com/en/articles/9923210-vercel-integration-guide.md): Learn how to connect Vercel to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Vetty Integration Guide](https://help.drata.com/en/articles/9655155-vetty-integration-guide.md): Learn how to connect Vetty to Drata for background check workflows and compliance monitoring. - [Webex Integration Guide](https://help.drata.com/en/articles/9300823-webex-integration-guide.md): Learn how to connect Webex to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [Webflow Integration Guide](https://help.drata.com/en/articles/9869055-webflow-integration-guide.md) - [Wiz \(CSPM\) Integration Guide](https://help.drata.com/en/articles/8852067-wiz-cspm-integration-guide.md): Learn how to connect Wiz to Drata and set up risk categories. - [Wiz \(Vulnerability Scanning\) Integration Guide](https://help.drata.com/en/articles/11048924-wiz-vulnerability-scanning-integration-guide.md): Instructions on how to generate credentials for Wiz and the required permissions. This is for the Vulnerability Scanning type connection. - [Wiz Code Integration Guide \(Vulnerability Scanning\)](https://help.drata.com/en/articles/11048914-wiz-code-integration-guide-vulnerability-scanning.md): Instructions on how to generate credentials for Wiz Code and the required permissions. - [Workable Integration Guide](https://help.drata.com/en/articles/9300828-workable-integration-guide.md): Learn how to connect Workable to Drata to automate User Access Reviews by syncing user access data from Workable. - [Workday Integration Guide \(HRIS\)](https://help.drata.com/en/articles/5523237-workday-integration-guide-hris.md): Making the initial connection to Workday. - [Workday Learning Integration Guide](https://help.drata.com/en/articles/12591173-workday-learning-integration-guide.md) - [Workspace ONE MDM Integration Guide](https://help.drata.com/en/articles/7068294-workspace-one-mdm-integration-guide.md) - [Xero Integration Guide \(UAR\)](https://help.drata.com/en/articles/9092027-xero-integration-guide-uar.md): Connecting Xero to Drata allows you to perform access reviews. - [Xyleme Integration Guide](https://help.drata.com/en/articles/12591193-xyleme-integration-guide.md) - [Zelt Integration Guide](https://help.drata.com/en/articles/9300865-zelt-integration-guide.md): Learn how to connect Zelt to Drata. This connection supports the following types: User Access Reviews \(UAR\). - [NinjaOne Integration Guide](https://help.drata.com/en/articles/13554422-ninjaone-integration-guide.md): In this article, you learn how to sync NinjaOne device compliance data with Drata. - [Socket Integration Guide](https://help.drata.com/en/articles/16547778-socket-integration-guide.md) - [DataGrail Integration Guide](https://help.drata.com/en/articles/16602553-datagrail-integration-guide.md) ## Policy Guidance - [Essential Policy FAQs: Your Quick Guide](https://help.drata.com/en/articles/10414305-essential-policy-faqs-your-quick-guide.md): This quick guide answers your most common policy questions, helping you stay compliant and find the information you need quickly. - [Policies to Framework Summary](https://help.drata.com/en/articles/7973705-policies-to-framework-summary.md) - [Policy Acknowledge Grouping](https://help.drata.com/en/articles/5849305-policy-acknowledge-grouping.md) - [Policies: should they reflect what is currently in place or the adjustments you'll be making?](https://help.drata.com/en/articles/4752967-policies-should-they-reflect-what-is-currently-in-place-or-the-adjustments-you-ll-be-making.md) - [Policy Coverage for Privacy](https://help.drata.com/en/articles/6422263-policy-coverage-for-privacy.md): This article covers updating policies for privacy frameworks. - [Example Completed Data Classification Table](https://help.drata.com/en/articles/7860581-example-completed-data-classification-table.md) - [Developing a Physical Security Policy for a remote team](https://help.drata.com/en/articles/5036683-developing-a-physical-security-policy-for-a-remote-team.md) - [Control Mapping Updates for Policies - 4/13/2023](https://help.drata.com/en/articles/7250402-control-mapping-updates-for-policies-4-13-2023.md): Updates to policy mappings related to NIST 800-53, NIST CSF and ISO 27001:2022 frameworks - [Control Mapping Updates for Policies - 10/17/2025](https://help.drata.com/en/articles/12611288-control-mapping-updates-for-policies-10-17-2025.md) - [Business Continuity Plan - Appendix A: Business Impact Analysis](https://help.drata.com/en/articles/5732621-business-continuity-plan-appendix-a-business-impact-analysis.md) - [Roles and Responsibilities Guidance](https://help.drata.com/en/articles/5829670-roles-and-responsibilities-guidance.md) - [Vulnerability Scanning Guidance](https://help.drata.com/en/articles/6136232-vulnerability-scanning-guidance.md) - [Example Business Continuity Plan](https://help.drata.com/en/articles/6232796-example-business-continuity-plan.md) - [Acceptable Use Policy Guidance](https://help.drata.com/en/articles/6568639-acceptable-use-policy-guidance.md) - [Asset Management Policy Guidance](https://help.drata.com/en/articles/6568646-asset-management-policy-guidance.md) - [Backup Policy Guidance](https://help.drata.com/en/articles/6568647-backup-policy-guidance.md) - [Business Continuity Plan Guidance](https://help.drata.com/en/articles/6630838-business-continuity-plan-guidance.md) - [Code of Conduct Guidance](https://help.drata.com/en/articles/6630842-code-of-conduct-guidance.md) - [Example Threat Assessment Plan](https://help.drata.com/en/articles/6915781-example-threat-assessment-plan.md) - [Does Drata Have a Privacy Policy Template?](https://help.drata.com/en/articles/7060948-does-drata-have-a-privacy-policy-template.md) - [Data Classification Policy Guidance](https://help.drata.com/en/articles/7172842-data-classification-policy-guidance.md) - [System Access Control Policy Guidance](https://help.drata.com/en/articles/7211097-system-access-control-policy-guidance.md) - [Password Policy Guidance](https://help.drata.com/en/articles/7257685-password-policy-guidance.md) - [Terms of Service Guidance: DCF-63 and DCF-66](https://help.drata.com/en/articles/7257698-terms-of-service-guidance-dcf-63-and-dcf-66.md) - [Data Retention Policy Guidance](https://help.drata.com/en/articles/7257853-data-retention-policy-guidance.md) - [Responsible Disclosure Policy Guidance](https://help.drata.com/en/articles/7669169-responsible-disclosure-policy-guidance.md) - [Physical Security Policy Guidance](https://help.drata.com/en/articles/7763364-physical-security-policy-guidance.md) - [Vendor Management Policy Guidance](https://help.drata.com/en/articles/7852188-vendor-management-policy-guidance.md) - [Encryption Policy Guidance](https://help.drata.com/en/articles/7874603-encryption-policy-guidance.md) - [Disaster Recovery Plan Guidance](https://help.drata.com/en/articles/7885003-disaster-recovery-plan-guidance.md) - [Incident Response Plan Guidance](https://help.drata.com/en/articles/7885026-incident-response-plan-guidance.md) - [Information Security Policy Guidance](https://help.drata.com/en/articles/7947579-information-security-policy-guidance.md) - [Vulnerability Management Policy Guidance](https://help.drata.com/en/articles/7987363-vulnerability-management-policy-guidance.md) - [Software Development Lifecycle \(SDLC\) Policy Guidance](https://help.drata.com/en/articles/8002321-software-development-lifecycle-sdlc-policy-guidance.md) - [Risk Assessment Policy Guidance](https://help.drata.com/en/articles/8167887-risk-assessment-policy-guidance.md) - [Data Protection Policy Guidance](https://help.drata.com/en/articles/8260378-data-protection-policy-guidance.md) - [Change Management Policy Guidance](https://help.drata.com/en/articles/8364890-change-management-policy-guidance.md) - [Data Loss Prevention \(DLP\) Guidance](https://help.drata.com/en/articles/9702726-data-loss-prevention-dlp-guidance.md) - [Logging and Monitoring Policy Guidance](https://help.drata.com/en/articles/9829067-logging-and-monitoring-policy-guidance.md) - [Maintenance Management Policy Guidance](https://help.drata.com/en/articles/11140737-maintenance-management-policy-guidance.md) - [System and Information Integrity Policy Guidance](https://help.drata.com/en/articles/11140776-system-and-information-integrity-policy-guidance.md) - [Personal Data Management Policy Guidance](https://help.drata.com/en/articles/11140868-personal-data-management-policy-guidance.md) - [Information Governance Policy Guidance](https://help.drata.com/en/articles/13188487-information-governance-policy-guidance.md): The following article contains guidance explaining portions of the Information Security Policy that we frequently see questions around, explaining what the sections mean. ## Personnel Management - [Are Contractors in Scope for my Audit?](https://help.drata.com/en/articles/5947523-are-contractors-in-scope-for-my-audit.md) - [Personnel: who should be accounted for in terms of your audit?](https://help.drata.com/en/articles/4793409-personnel-who-should-be-accounted-for-in-terms-of-your-audit.md) - [Bulk Import Policy Acknowledgments](https://help.drata.com/en/articles/15195769-bulk-import-policy-acknowledgments.md): Upload a CSV of policy acknowledgments using a guided, spreadsheet-style experience. - [Background Check Management](https://help.drata.com/en/articles/5833999-background-check-management.md): How to use Drata's Background Check Management table to link users to their personal background checks performed before hiring - [Certn Background Check Packages](https://help.drata.com/en/articles/5695892-certn-background-check-packages.md): Additional information to help choose the right background check package for your employees - [Future Hire Personnel](https://help.drata.com/en/articles/13612293-future-hire-personnel.md): Track future employees in Drata without impacting compliance by using Future Hire status based on start dates. - [Manually map proof of a background check](https://help.drata.com/en/articles/13613216-manually-map-proof-of-a-background-check.md): Manually map or upload background check evidence for employees in Drata when using a non-integrated provider. - [Review and Acknowledge Company Policies](https://help.drata.com/en/articles/4674033-review-and-acknowledge-company-policies.md): Acknowledge policies as an employee or contractor - [Showing completion of Security Awareness Training](https://help.drata.com/en/articles/4753640-showing-completion-of-security-awareness-training.md): Here's how to show you have completed Security Awareness Training within Drata - [Personnel Offboarding Evidence](https://help.drata.com/en/articles/6653817-personnel-offboarding-evidence.md): The goal of offboarding evidence is to provide proof that access and responsibilities were removed for former employees. - [Offboarding Checklist Guidance](https://help.drata.com/en/articles/6077161-offboarding-checklist-guidance.md): This article provides a checklist for an effective offboarding process. - [How to Handle Device Compliance for Chromebooks](https://help.drata.com/en/articles/6297654-how-to-handle-device-compliance-for-chromebooks.md) - [How do Bring Your Own Device \(BYOD\) Devices Affect my Audit?](https://help.drata.com/en/articles/6297649-how-do-bring-your-own-device-byod-devices-affect-my-audit.md) - [Manual evidence uploads for personnel compliance checks](https://help.drata.com/en/articles/4972218-manual-evidence-uploads-for-personnel-compliance-checks.md): Employees have the option to load manual evidence if not using the Drata Agent - [Installing and Using a Password Manager](https://help.drata.com/en/articles/4675829-installing-and-using-a-password-manager.md): Password managers like 1Password, LastPass, and others should be used. - [Configuring Automatic Updates on your Computer](https://help.drata.com/en/articles/4675832-configuring-automatic-updates-on-your-computer.md): Auto-updates on your computer - [Encrypting your Computer's Hard Drive](https://help.drata.com/en/articles/4675833-encrypting-your-computer-s-hard-drive.md): How to ensure your hard disk is encrypted - [Configure your computer for installing Anti-Virus Software](https://help.drata.com/en/articles/4675835-configure-your-computer-for-installing-anti-virus-software.md): Protect your system from malware \(Test: Malware Detection Software Installed – Test 64\) - [Auto-Lock your Workstation with Screensaver](https://help.drata.com/en/articles/4675838-auto-lock-your-workstation-with-screensaver.md): Configuring your workstation to auto-lock \(and require a password\) when the screensaver activates - [Multiple MDM Support \(Classic Experience\)](https://help.drata.com/en/articles/5990364-multiple-mdm-support-classic-experience.md): This article explains how Drata handles multiple MDMs - [How does the Drata agent work?](https://help.drata.com/en/articles/4742932-how-does-the-drata-agent-work.md): Once installed, how does the Drata agent work on your computer? - [Drata Agent not reporting system updates](https://help.drata.com/en/articles/4785054-drata-agent-not-reporting-system-updates.md): If you or your employee has made changes to their system \(to meet requirements\) and aren't seeing them report back to Drata - [Computer Configuration via Windows OS](https://help.drata.com/en/articles/5002070-computer-configuration-via-windows-os.md) - [Computer Configuration via Ubuntu Linux](https://help.drata.com/en/articles/5014509-computer-configuration-via-ubuntu-linux.md) - [Drata Agent Installation Link](https://help.drata.com/en/articles/6110773-drata-agent-installation-link.md): This article covers how to access Drata Agent directly when the Agent option is disabled. - [Install the Drata Agent](https://help.drata.com/en/articles/13612377-install-the-drata-agent.md): Learn how to install and verify the Drata Agent to report device security settings during employee onboarding. - [Multi-Device Support](https://help.drata.com/en/articles/13613390-multi-device-support.md): Learn how Drata supports multiple devices per user, how devices are tracked, and how compliance responsibility is managed. - [Capture Agent Device Logs \(macOS\)](https://help.drata.com/en/articles/14328618-capture-agent-device-logs-macos.md) ## Monitoring Test Guidance - [Test: IRP Designates Responsible Team Members](https://help.drata.com/en/articles/4776932-test-irp-designates-responsible-team-members.md): Drata inspects your company Incident Response Plan to determine if it specifies roles for monitoring and responding to incidents. - [Test: IRP Includes Lessons Learned](https://help.drata.com/en/articles/4776933-test-irp-includes-lessons-learned.md): Drata inspects your company Incident Response Plan to ensure it includes a section about documenting “Lessons Learned” after incidents. - [Test: Has Security Policies](https://help.drata.com/en/articles/4776938-test-has-security-policies.md): Drata inspects your company's security policies to determine if they account for securing the company's operations, services, and systems. - [Test: Process for Responsible Disclosure](https://help.drata.com/en/articles/4776891-test-process-for-responsible-disclosure.md): Drata inspects your company security policies to determine if they detail a process for employees to disclose potential security violations. - [Test: Policies for a Security Team](https://help.drata.com/en/articles/4778523-test-policies-for-a-security-team.md): Drata inspects your company records to determine if management has identified the individuals on the security team. - [Test: Backups Checked for Integrity](https://help.drata.com/en/articles/4778883-test-backups-checked-for-integrity.md): Drata inspects your backup restoration testing results to determine if the integrity and completeness of backup information is tested. - [Test: High Vulnerabilities Addressed](https://help.drata.com/en/articles/9859341-test-high-vulnerabilities-addressed.md) - [Test: Policies are Acknowledged](https://help.drata.com/en/articles/4776941-test-policies-are-acknowledged.md): Drata inspects your company security policy records to determine if all employees have acknowledged them. - [Test: Employees Acknowledge the Data Protection Policy](https://help.drata.com/en/articles/4776961-test-employees-acknowledge-the-data-protection-policy.md): Drata inspects your company records to determine if the Data Protection Policy has been been acknowledged by all employees. - [Test: Termination Process and Checklist](https://help.drata.com/en/articles/4797463-test-termination-process-and-checklist.md): Drata inspects your company System Access Control Policy to determine if there is a termination checklist being followed appropriately. - [Test: Critical Vulnerabilities Addressed](https://help.drata.com/en/articles/9859338-test-critical-vulnerabilities-addressed.md) - [October 2024 Release: AWS Drata test](https://help.drata.com/en/articles/10034590-october-2024-release-aws-drata-test.md): New AWS tests in released in October 30, 2024. - [February 2025 Release: AWS and Azure Drata Tests](https://help.drata.com/en/articles/10437783-february-2025-release-aws-and-azure-drata-tests.md): We’re excited to announce the release of new tests in Drata. These AWS and Azure tests were released in February 5, 2025. - [Test 1: Policies Cover Employee Access](https://help.drata.com/en/articles/4776868-test-1-policies-cover-employee-access.md): Drata inspects your company policies to determine if they outline the proper requirements for allowing employees access to customer data. - [Test 2: Policies Cover Employee Confidentiality](https://help.drata.com/en/articles/4776871-test-2-policies-cover-employee-confidentiality.md): Drata inspects your company policies to determine if they require employees to keep customer data completely confidential. - [Test 3: Least Privilege Policy for Customer Data Access](https://help.drata.com/en/articles/4776875-test-3-least-privilege-policy-for-customer-data-access.md): Drata inspects your company security policies to determine if employees are only allowed access to customer data when absolutely necessary. - [Test 4: SSL/TLS on Admin Page of Infrastructure Console](https://help.drata.com/en/articles/4776882-test-4-ssl-tls-on-admin-page-of-infrastructure-console.md): Drata inspects an HTTPS request to your company infrastructure admin console to determine the presence and status of an SSL certificate. - [Test 5: A Version Control System is being Used](https://help.drata.com/en/articles/4776883-test-5-a-version-control-system-is-being-used.md): Drata inspects your company version control system to determine if it is in fact being used. - [Test 6: Only Authorized Employees Access Version Control](https://help.drata.com/en/articles/4778488-test-6-only-authorized-employees-access-version-control.md): Drata uses OAuth to access your company's Identity Provider and version control system ensuring access is permitted correctly. - [Test 7: Only Authorized Employees Change Code](https://help.drata.com/en/articles/4778497-test-7-only-authorized-employees-change-code.md): Drata uses OAuth to access your company's Identity Provider \(IdP\) and version control system to ensure only authorized users change code. - [Test 8: Formal Code Review Process](https://help.drata.com/en/articles/4776886-test-8-formal-code-review-process.md): Drata reads branch configurations for all in-scope repos in your version control system to ensure reviews are required before merging code . - [Test 9: Production Code Changes Restricted](https://help.drata.com/en/articles/4777024-test-9-production-code-changes-restricted.md): Drata pulls a list of all of the authorized users with access to merge code to the default branch of a code repository in version control. - [Test 11: Contact Information Available to Customers](https://help.drata.com/en/articles/4776889-test-11-contact-information-available-to-customers.md): Drata inspects your company records to determine if a URL to customer-accessible support documentation has been provided. - [Test 13: System Access Control Policy](https://help.drata.com/en/articles/4776894-test-13-system-access-control-policy.md): Drata inspects your company records to determine if a System Access Control Policy is in place and is currently valid. - [Test 16: Information Security Policy](https://help.drata.com/en/articles/4776895-test-16-information-security-policy.md): Drata inspects your company records to determine if an Information Security Policy is in place and is currently valid. - [Test 17: Maintains Organization Chart](https://help.drata.com/en/articles/4776896-test-17-maintains-organization-chart.md): Drata inspects your company records to determine if an Organizational Chart has been uploaded within the last 12 months - [Test 18: Risk Assessment Policy](https://help.drata.com/en/articles/4776899-test-18-risk-assessment-policy.md): Drata inspects your company records to determine if a Risk Assessment Policy is in place and is currently valid. - [Test 21: Vulnerability Scanning](https://help.drata.com/en/articles/4776909-test-21-vulnerability-scanning.md): Drata requests verification that there is an active connection to a vulnerability scanning system in Drata. - [Test 26: Security Issues are Prioritized](https://help.drata.com/en/articles/4776916-test-26-security-issues-are-prioritized.md): Drata inspects your company task tracking system to determine if security issues are being tagged and prioritized accordingly. - [Test 27: SLA for Security Bugs](https://help.drata.com/en/articles/4776919-test-27-sla-for-security-bugs.md): Drata inspects your company records to determine if a Vulnerability Management Policy, that includes an SLA for P0 security bugs, is active. - [Test 28: Disaster Recovery Plan](https://help.drata.com/en/articles/4776923-test-28-disaster-recovery-plan.md): Drata inspects your company records to determine if a Disaster Recovery Plan is in place and is currently active. - [Test 30: Availability Zones Used](https://help.drata.com/en/articles/4776928-test-30-availability-zones-used.md): Drata inspects your company infrastructure configurations to determine if multiple availability zones \(AZs\) are utilized. - [Test 32: Policies for Tracking Security Items](https://help.drata.com/en/articles/4776929-test-32-policies-for-tracking-security-items.md): Drata inspects your company Incident Response Plan to determine if it includes a section about tracking follow-ups after an incident. - [Test 33: Incident Response Plan \(IRP\)](https://help.drata.com/en/articles/4776931-test-33-incident-response-plan-irp.md): Drata inspects your company records to determine if an Incident Response Plan is in place and is before the policy renewal date. - [Test 36: Has a SDLC Policy](https://help.drata.com/en/articles/4776936-test-36-has-a-sdlc-policy.md): Drata inspects your company records to determine if a Software Development Life Cycle Policy is in place and is currently active. - [Test 39: Security Policies are Reviewed](https://help.drata.com/en/articles/4776944-test-39-security-policies-are-reviewed.md): Drata inspects your company records to determine if Management reviewed and approved its security policies before the renewal date. - [Test 42: Policies for Security Awareness Training](https://help.drata.com/en/articles/4778541-test-42-policies-for-security-awareness-training.md): Drata inspects your company Information Security Policy to ensure the security team is responsible for training all employees on security. - [Test 43: Security Awareness Training Completed](https://help.drata.com/en/articles/4778548-test-43-security-awareness-training-completed.md): Drata inspects your company security awareness training certificates to determine if all employees have completed their training. - [Test 44: Acceptable Use Policy](https://help.drata.com/en/articles/4776945-test-44-acceptable-use-policy.md): Drata inspects your company records to determine if an Acceptable Use Policy is in place and is before the renewal date. - [Test 45: Employees Acknowledge the Acceptable Use Policy](https://help.drata.com/en/articles/4776946-test-45-employees-acknowledge-the-acceptable-use-policy.md): Drata inspects your company records to determine if the Acceptable Use Policy has been acknowledged by all employees. - [Test 46: Performance Evaluation Process](https://help.drata.com/en/articles/4778550-test-46-performance-evaluation-process.md): Drata inspects your company records to determine if there is a formal process to evaluate employee performance. - [Test 47: Employee Background Checks](https://help.drata.com/en/articles/4778551-test-47-employee-background-checks.md): Drata inspects your company records to determine if all new employees have completed background checks upon hire. - [Test 48: Contractors Acknowledge the Code of Conduct](https://help.drata.com/en/articles/4776948-test-48-contractors-acknowledge-the-code-of-conduct.md): Drata inspects your company records to determine if the Code of Conduct has been acknowledged by all contractors. - [Test 49: Contractors Acknowledge the Acceptable Use Policy](https://help.drata.com/en/articles/4776953-test-49-contractors-acknowledge-the-acceptable-use-policy.md): Drata inspects your company records to determine if the Acceptable Use Policy has been acknowledged by all contractors. - [Test 50: Contractor Background Checks](https://help.drata.com/en/articles/4778553-test-50-contractor-background-checks.md): Drata inspects your company records to determine if all new contractors have completed background checks upon hire. - [Test 51: Independent Board of Directors](https://help.drata.com/en/articles/4776954-test-51-independent-board-of-directors.md): Drata inspects your company records to determine if all of its Board of Directors' biographies were saved. - [Test 54: Formal Code of Conduct](https://help.drata.com/en/articles/4776955-test-54-formal-code-of-conduct.md): Drata inspects your company records to determine if a Code of Conduct is in place and has is before the policy renewal date. - [Test 55: Employees Acknowledge the Code of Conduct](https://help.drata.com/en/articles/4776957-test-55-employees-acknowledge-the-code-of-conduct.md): Drata inspects your company records to determine if the Code of Conduct has been been acknowledged by all employees. - [Test 56: Data Protection Policy](https://help.drata.com/en/articles/4776958-test-56-data-protection-policy.md): Drata checks your company records to verify that a Data Protection Policy is in place and that it has not passed its renewal date. - [Test 58: New Hire Contracts](https://help.drata.com/en/articles/4778696-test-58-new-hire-contracts.md): Drata inspects your company records to determine if there is a sample new hire contract. - [Test 59: Job Descriptions](https://help.drata.com/en/articles/4778705-test-59-job-descriptions.md): Drata inspects your company records to determine if a URL to its external jobs/careers website has been provided. - [Test 60: Engineering Job Description](https://help.drata.com/en/articles/4778708-test-60-engineering-job-description.md): Drata inspects your company records to determine if there is a sample engineering job description. - [Test 61: Screensaver Lock Required on Employee Computers](https://help.drata.com/en/articles/4778709-test-61-screensaver-lock-required-on-employee-computers.md): Drata inspects if employee computers have a required password 60 seconds or less after the machine has been idle for at least 15 minutes. - [Test 62: Password Manager Required](https://help.drata.com/en/articles/4777028-test-62-password-manager-required.md): Drata inspected your companies' security policies to determine if employees are required to use a password manager for cloud services. - [Test 63: Password Manager Records on Employee Computers](https://help.drata.com/en/articles/4775951-test-63-password-manager-records-on-employee-computers.md): Drata inspects your company computers to determine if each is running a password manager. - [Test 64: Malware Detection Software Installed](https://help.drata.com/en/articles/4776962-test-64-malware-detection-software-installed.md): Drata inspects your company computers to determine if each is running an antivirus software. - [Test 65: Security Patches Auto-Applied](https://help.drata.com/en/articles/4776966-test-65-security-patches-auto-applied.md): Drata inspects your company computers to determine if each automatically applies operating system security patches. - [Test 66: Hard-Disk Encryption Enabled on Employee Computers](https://help.drata.com/en/articles/4778714-test-66-hard-disk-encryption-enabled-on-employee-computers.md): Drata inspects your company computers to determine if each hard-disks is encrypted. - [Test 67: Cryptography Policy](https://help.drata.com/en/articles/4776969-test-67-cryptography-policy.md): Drata inspects your company records to determine if an Encryption Policy is in place and is before the policy renewal date. - [Test 68: Customer Data is Encrypted at Rest](https://help.drata.com/en/articles/4776970-test-68-customer-data-is-encrypted-at-rest.md): Drata inspects your company configuration of the database\(s\) storing customer data to determine if the data is encrypted at rest. - [Test 69: Customer Data in Cloud Storage is Encrypted at Rest](https://help.drata.com/en/articles/4776971-test-69-customer-data-in-cloud-storage-is-encrypted-at-rest.md): Drata inspects your company cloud storage configuration to ensure customer data is encrypted at rest when stored. - [Test 70: SSL/TLS Enforced on Company Website](https://help.drata.com/en/articles/4776181-test-70-ssl-tls-enforced-on-company-website.md): Drata makes a request to your company website to see if it's reachable exclusively over HTTPS. - [Test 71: SSL/TLS Configuration has No Known Issues](https://help.drata.com/en/articles/4776834-test-71-ssl-tls-configuration-has-no-known-issues.md): Drata makes a request to your company website to inspect its SSL/TLS configurations and determine if there are any known issues - [Test 72: SSL/TLS Certificate has Not Expired](https://help.drata.com/en/articles/4776839-test-72-ssl-tls-certificate-has-not-expired.md): Drata makes a request to your company website to inspect its SSL/TLS configurations and determine if the SSL certificate is expired. - [Test 83: MSAs Offered to Customers](https://help.drata.com/en/articles/4778733-test-83-msas-offered-to-customers.md): Drata inspects your company records to determine if there is a sample Master Service Agreement \(MSA\) in place. - [Test 84: Privacy Policy Publicly Available](https://help.drata.com/en/articles/4778740-test-84-privacy-policy-publicly-available.md): Drata inspects your company records to determine if a URL to its public Privacy Policy has been provided. - [Test 85: Terms of Use Publicly Available](https://help.drata.com/en/articles/4778743-test-85-terms-of-use-publicly-available.md): Drata inspects your company records to determine if a URL to its public Terms of Service has been provided. - [Test 86: MFA on Identity Provider](https://help.drata.com/en/articles/4776841-test-86-mfa-on-identity-provider.md): Drata uses its synchronized account delegation with your Identity Provider to request a list of all users and determine if MFA is enabled. - [Test 87: MFA on Version Control System](https://help.drata.com/en/articles/4776860-test-87-mfa-on-version-control-system.md): Drata connects to your companies' Version Control System and pulls all user accounts to determine if each has MFA enabled. - [Test 88: MFA on Infrastructure Console](https://help.drata.com/en/articles/4777035-test-88-mfa-on-infrastructure-console.md): Drata connects to the company's infrastructure and pulls a list of IAM accounts' auth configurations to determine if MFA is required. - [Test 89: Internal Password Policy for Employees](https://help.drata.com/en/articles/4776975-test-89-internal-password-policy-for-employees.md): Drata inspects your company records to determine if a Password Policy is in place and is before the policy renewal date. - [Test 94: Version Control Accounts Removed Properly](https://help.drata.com/en/articles/4777036-test-94-version-control-accounts-removed-properly.md): Drata inspects your company records to determine if terminated employee accounts are removed from version control within the specified SLA. - [Test 95: Infrastructure Accounts Properly Removed](https://help.drata.com/en/articles/4777040-test-95-infrastructure-accounts-properly-removed.md): Drata inspects your company records to determine if terminated employee accounts are removed from the infrastructure provider. - [Test 96: Employees have Unique Email Accounts](https://help.drata.com/en/articles/4776863-test-96-employees-have-unique-email-accounts.md): Drata uses its synchronized account delegation with your Identity Provider to verify ownership and authenticity of listed accounts. - [Test 97: Employees have Unique Version Control Accounts](https://help.drata.com/en/articles/4777042-test-97-employees-have-unique-version-control-accounts.md): Drata accesses your company version control system to determine if each account matches to an identity from the company's IdP. - [Test 98: Employees have Unique Infrastructure Accounts](https://help.drata.com/en/articles/4777045-test-98-employees-have-unique-infrastructure-accounts.md): Drata accesses your company infrastructure provider to determine if each account matches to an identity from the company's IdP. - [Test 102: Public SSH Denied](https://help.drata.com/en/articles/4776976-test-102-public-ssh-denied.md): Drata inspects all virtual assets to determine if security groups allow SSH access to public \(0.0.0.0/0\) - [Test 104: Cloud Storage Public Access Disabled](https://help.drata.com/en/articles/4777046-test-104-cloud-storage-public-access-disabled.md): Drata inspects the cloud data storage access configuration\(s\) to determine if read/write access is configured to restrict public access. - [Test 105: Threat Detection in Place](https://help.drata.com/en/articles/4778757-test-105-threat-detection-in-place.md): Drata inspects your company AWS configuration to determine if AWS GuardDuty is in place to detect unauthorized file additions. - [Test 106: Has a Backup Policy](https://help.drata.com/en/articles/4776867-test-106-has-a-backup-policy.md): Drata inspects your company records to determine if a Backup Policy is in place and is before the policy renewal date. - [Test 107: Daily Database Backups](https://help.drata.com/en/articles/4777050-test-107-daily-database-backups.md): Drata inspects your company backup configuration from its infrastructure provider to determine if the backup schedule is set to daily. - [Test 108: Storage Data Versioned or Retained](https://help.drata.com/en/articles/4778759-test-108-storage-data-versioned-or-retained.md): Drata inspects all data stores to determine if the data versioning configuration is enabled. - [Test 109: Logs are Centrally Stored](https://help.drata.com/en/articles/4778760-test-109-logs-are-centrally-stored.md): Drata inspects your company system configuration for collecting and storing logs to ensure logs are deposited in a central location. - [Test 110: Only Authorized Users can Access Log Sinks](https://help.drata.com/en/articles/4778762-test-110-only-authorized-users-can-access-log-sinks.md): Drata inspects the access policy for the infrastructure logging system to determine if only authorized users can access log sinks. - [Test 111: Logs are Retained for 365 Days](https://help.drata.com/en/articles/4778770-test-111-logs-are-retained-for-365-days.md): Drata inspects the retention policy for the infrastructure logging system to determine if the logs are being archived in long-term storage. - [Test 112: Database CPU Monitored](https://help.drata.com/en/articles/4776977-test-112-database-cpu-monitored.md): Drata inspects your company alerting and monitoring configuration to determine if server CPUs are monitored, with appropriate alerts. - [Test 113: Database Free Storage Space Monitored](https://help.drata.com/en/articles/4776980-test-113-database-free-storage-space-monitored.md): Drata inspects your company database monitoring configuration to determine if free storage space is monitored, with appropriate alerts. - [Test 114: Database Read I/O Monitored](https://help.drata.com/en/articles/4776984-test-114-database-read-i-o-monitored.md): Drata inspects your company database monitoring configuration to determine if I/O is monitored, with appropriate alerts. - [Test 115: Messaging Queue Message Age Monitored](https://help.drata.com/en/articles/4776986-test-115-messaging-queue-message-age-monitored.md): Drata inspects your company messaging queue monitoring configuration to determine if message age is monitored, with appropriate alerts. - [Test 116: NoSQL Cluster CPU Load Monitored](https://help.drata.com/en/articles/10029043-test-116-nosql-cluster-cpu-load-monitored.md): Inspects NoSQL cluster monitor and alert configurations to determine if CPU load is monitored and alerts when defined thresholds are crossed - [Test 117: NoSQL Cluster Storage Utilization Monitored](https://help.drata.com/en/articles/4776995-test-117-nosql-cluster-storage-utilization-monitored.md): Drata inspects your company NoSQL cluster configuration to determine if storage utilization is monitored, with appropriate alerts. - [Test 118: Infrastructure Instance CPU Monitored](https://help.drata.com/en/articles/4776997-test-118-infrastructure-instance-cpu-monitored.md): Drata inspects your company server monitoring configuration to determine if server CPU use is monitored, with appropriate alerts. - [Test 119: Firewall Default Disallows Traffic](https://help.drata.com/en/articles/4777002-test-119-firewall-default-disallows-traffic.md): Drata inspects your company firewall configuration files to determine if they are configured to deny all traffic not explicitly allowed. - [Test 121: Logs Monitored for Suspicious Activity](https://help.drata.com/en/articles/4797516-test-121-logs-monitored-for-suspicious-activity.md): Drata inspects the company infrastructure logs to determine that it is configured to monitor web traffic and suspicious activity. - [Test 122: Web Application Firewall in Place](https://help.drata.com/en/articles/4777003-test-122-web-application-firewall-in-place.md): Drata inspects the WAF configurations to determine if WAF is appropriately deployed and configured to appropriately block malicious traffic. - [Test 123: Cloud Infrastructure Linked to Drata](https://help.drata.com/en/articles/4778777-test-123-cloud-infrastructure-linked-to-drata.md): Drata inspects your company cloud infrastructure to ensure it is successfully linked to Drata. - [Test 124: Root Infrastructure Account Unused](https://help.drata.com/en/articles/4777051-test-124-root-infrastructure-account-unused.md): Drata inspects your company infrastructure provider configurations to determine if the Root account is unused. - [Test 127: Security Policies Cover Encryption](https://help.drata.com/en/articles/4778866-test-127-security-policies-cover-encryption.md): Drata inspects your company security policies to determine if they explain the procedures for encrypting sensitive data. - [Test 128: Physical Security Policy](https://help.drata.com/en/articles/4777004-test-128-physical-security-policy.md): Drata inspects your company records to determine if a Physical Security Policy is in place and currently valid. - [Test 129: Capacity and Usage Monitoring](https://help.drata.com/en/articles/4778868-test-129-capacity-and-usage-monitoring.md): Drata inspects your companies' processing capacity and usage reports to determine if processing capacity and usage is monitored. - [Test 130: Load Balancer Used](https://help.drata.com/en/articles/4777006-test-130-load-balancer-used.md): Drata inspects your company infrastructure to determine if Load Balancers are configured to balance between multiple availability zones. - [Test 131: Autoscale Server Instances](https://help.drata.com/en/articles/10029045-test-131-autoscale-server-instances.md): Determine if autoscaling was in place to provision new compute resources when predefined capacity thresholds are met. - [Test 132: Daily backup job status monitored](https://help.drata.com/en/articles/9999495-test-132-daily-backup-job-status-monitored.md): Drata inspected company's database snapshot history and determined a successful snapshot is available for the previous day. - [Test 133: Failed Backup Alerts Being Sent](https://help.drata.com/en/articles/4778878-test-133-failed-backup-alerts-being-sent.md): Infrastructure configurations and confirmed that alerts are configured to be sent to personnel when the backup process fails. - [Test 134: Failed Backups Addressed in Timely Manner](https://help.drata.com/en/articles/4778882-test-134-failed-backups-addressed-in-timely-manner.md): Drata inspected infrastructure configuration and confirmed that failed backups were resolved in a timely manner. - [Test 136: Data Retention Policy](https://help.drata.com/en/articles/4778884-test-136-data-retention-policy.md): Drata inspects your records to determine if a valid, approved Data Deletion Policy is in place with a data retention period specified. - [Test 137: Data Classification Policy](https://help.drata.com/en/articles/4777011-test-137-data-classification-policy.md): Drata inspects your company records to determine if a Data Classification Policy is in place and currently valid. - [Test 138: Deleting Customer Data Upon Terminated Contract](https://help.drata.com/en/articles/4778892-test-138-deleting-customer-data-upon-terminated-contract.md): Drata inspects your company records to determine if a valid, approved Data Deletion Policy is in place that specifies data deletion periods. - [Test 141: Clean Desk Policy](https://help.drata.com/en/articles/4778895-test-141-clean-desk-policy.md): Drata inspects your company records to determine if a Information Security Policy is in place and approved within the last 12 months. - [Test 143: Sensitive Data Disposal Policy](https://help.drata.com/en/articles/4778896-test-143-sensitive-data-disposal-policy.md): Drata inspects your company records to determine if an Information Security Policy is in place and is before the policy renewal date. - [Test 205: CloudTrail log file integrity validation enabled](https://help.drata.com/en/articles/10029049-test-205-cloudtrail-log-file-integrity-validation-enabled.md): Drata validates that AWS CloudTrail log validation is enabled on all trails. - [Test 206: SQL Freeable Memory Monitored](https://help.drata.com/en/articles/10029047-test-206-sql-freeable-memory-monitored.md): Determine if freeable memory is monitored and alerts to personnel are sent when defined thresholds are crossed. - [Test 208: Excessive Privileges Assigned](https://help.drata.com/en/articles/8946448-test-208-excessive-privileges-assigned.md) - [Test 209: External Exposure of Cloud Resources](https://help.drata.com/en/articles/8946449-test-209-external-exposure-of-cloud-resources.md) - [Test 210: Encryption in Transit](https://help.drata.com/en/articles/8946445-test-210-encryption-in-transit.md) - [Test 214: MFA for AWS Root Account](https://help.drata.com/en/articles/9828711-test-214-mfa-for-aws-root-account.md): Drata validates that multi-factor authentication \(MFA\) is enabled for the root user account in AWS. - [Test 215: AWS IAM Password Minimum Length](https://help.drata.com/en/articles/9828716-test-215-aws-iam-password-minimum-length.md): Drata validates that the AWS IAM password policy requires a minimum length of 14 characters or greater. - [Test 216: AWS IAM Password Reuse](https://help.drata.com/en/articles/9828717-test-216-aws-iam-password-reuse.md): Drata validates that AWS IAM password policy is configured to prevent reuse of any of the last 24 passwords. - [Test 217: AWS IAM Group-Based Access Control](https://help.drata.com/en/articles/9828704-test-217-aws-iam-group-based-access-control.md): Drata validates that IAM users are granted permissions only through groups and no users with inline policy or direct policy attachments. - [Test 218: AWS EBS Volume Encryption](https://help.drata.com/en/articles/9828784-test-218-aws-ebs-volume-encryption.md): Validates that default encryption for elastic block store \(EBS\) volume creation is enabled for every region where EC2 instances are detected - [Test 219: AWS RDS Auto Minor Version Upgrade](https://help.drata.com/en/articles/9828785-test-219-aws-rds-auto-minor-version-upgrade.md): Drata validates that the automatic minor version upgrade feature is enabled for AWS RDS instances. - [Test 220: AWS RDS Public Access Restricted](https://help.drata.com/en/articles/9828787-test-220-aws-rds-public-access-restricted.md): Drata validates that AWS RDS database instances do not allow unrestricted public access \(0.0.0.0/0\). - [Test 221: AWS S3 Bucket Access Logging](https://help.drata.com/en/articles/9828721-test-221-aws-s3-bucket-access-logging.md): Drata validates that AWS S3 bucket access logging is enabled on the AWS CloudTrail S3 bucket. - [Test 222: AWS CloudTrail Logs Encrypted](https://help.drata.com/en/articles/9828725-test-222-aws-cloudtrail-logs-encrypted.md): Drata validates that AWS CloudTrail logs are encrypted at rest using AWS KMS customer created master keys \(CMKs\). - [Test 223: AWS CMK Rotation](https://help.drata.com/en/articles/9828731-test-223-aws-cmk-rotation.md): Drata validates that key rotation is enabled for customer-created symmetric customer master keys \(CMKs\) in AWS Key Management Service \(KMS\). - [Test 224: AWS VPC Flow Logging](https://help.drata.com/en/articles/9828733-test-224-aws-vpc-flow-logging.md): Drata validates that VPC flow logging is enabled in all AWS VPCs. - [Test 225: Hardware MFA for AWS Root Account](https://help.drata.com/en/articles/9828713-test-225-hardware-mfa-for-aws-root-account.md): Drata validates that hardware MFA is enabled for the root user account in AWS. - [Test 226: AWS S3 Object-Level Logging for Read & Write Events](https://help.drata.com/en/articles/9828791-test-226-aws-s3-object-level-logging-for-read-write-events.md): Drata validates that object-level logging for read and write events is enabled for AWS S3 buckets. - [Test 227: AWS Network ACLs Public Remote Server Administration Access Restricted](https://help.drata.com/en/articles/9828735-test-227-aws-network-acls-public-remote-server-administration-access-restricted.md) - [Test 228: AWS Security Groups Restrict Public RDP Access](https://help.drata.com/en/articles/9828740-test-228-aws-security-groups-restrict-public-rdp-access.md) - [Test 229: AWS IAM Unused Credentials](https://help.drata.com/en/articles/9828680-test-229-aws-iam-unused-credentials.md): Drata validated that all credentials \(e.g., passwords, access keys\) for IAM users have been used within the last 45 days. - [Test 230: AWS IAM Principle of Least Privilege](https://help.drata.com/en/articles/9828707-test-230-aws-iam-principle-of-least-privilege.md): In this article, you learn how Drata validates that AWS IAM policies follow the principle of least privilege and how to remediate policies that allow broad access. - [Test 231: AWS EFS Encrypted at Rest](https://help.drata.com/en/articles/9828789-test-231-aws-efs-encrypted-at-rest.md): Drata validates that AWS Elastic File System \(EFS\) data is encrypted at rest using AWS KMS for all regions. - [Test 232: AWS IAM Access Key Rotation](https://help.drata.com/en/articles/9828694-test-232-aws-iam-access-key-rotation.md): Drata validated that all AWS IAM access keys have a key age of less than 90 days. - [Test 233: AWS VPC Default Security Groups Restrict All Traffic](https://help.drata.com/en/articles/9828741-test-233-aws-vpc-default-security-groups-restrict-all-traffic.md): Drata validates that all AWS VPC default security groups are configured to restrict all traffic. - [Test 234: AWS S3 HTTP Requests Denied](https://help.drata.com/en/articles/9828783-test-234-aws-s3-http-requests-denied.md): Drata validates that access policies for AWS S3 buckets are set to deny unencrypted, HTTP requests. - [Test 243: Azure Log Alert for Create Policy Assignment](https://help.drata.com/en/articles/9828827-test-243-azure-log-alert-for-create-policy-assignment.md): Drata validates that an activity log alert for the 'Create Policy Assignment' event exists in Azure. - [Test 244: Azure Log Alert for Delete Public IP Address](https://help.drata.com/en/articles/9828829-test-244-azure-log-alert-for-delete-public-ip-address.md): Drata validates that an activity log alert for the 'Delete Public IP Address' event exists in Azure. - [Test 245: Azure Log Alert for Delete Policy Assignment](https://help.drata.com/en/articles/9828840-test-245-azure-log-alert-for-delete-policy-assignment.md): Drata validates that an activity log alert for the 'Delete Policy Assignment' event exists in Azure. - [Test 246: Azure Log Alert for Create or Update Network Security Group](https://help.drata.com/en/articles/9828841-test-246-azure-log-alert-for-create-or-update-network-security-group.md): Drata validates that an activity log alert for the 'Create or Update Network Security Group' event exists in Azure. - [Test 247: Azure Log Alert for Delete Network Security Group](https://help.drata.com/en/articles/9828842-test-247-azure-log-alert-for-delete-network-security-group.md): Drata validates that an activity log alert for the 'Delete Network Security Group' event exists in Azure. - [Test 248: Azure Log Alert for Create or Update Security Solution](https://help.drata.com/en/articles/9828843-test-248-azure-log-alert-for-create-or-update-security-solution.md): Drata validates that an activity log alert for the 'Create or Update Security Solution' event exists in Azure. - [Test 249: Azure Log Alert for Delete Security Solution](https://help.drata.com/en/articles/9828845-test-249-azure-log-alert-for-delete-security-solution.md): Drata validates that an activity log alert for the 'Delete Security Solution' event exists in Azure. - [Test 250: Azure Log Alert for Create or Update SQL Server Firewall Rule](https://help.drata.com/en/articles/9828846-test-250-azure-log-alert-for-create-or-update-sql-server-firewall-rule.md): Drata validates that an activity log alert for the 'Create or Update SQL Server Firewall Rule' event exists in Azure. - [Test 251: Azure Log Alert for Delete SQL Server Firewall Rule](https://help.drata.com/en/articles/9828848-test-251-azure-log-alert-for-delete-sql-server-firewall-rule.md): Drata validates that an activity log alert for the 'Delete SQL Server Firewall Rule' event exists in Azure. - [Test 252: Azure Log Alert for Create or Update Public IP Address rule](https://help.drata.com/en/articles/9828850-test-252-azure-log-alert-for-create-or-update-public-ip-address-rule.md): Drata validates that an activity log alert for the 'Create or Update Public IP Address rule' event exists in Azure. - [Test 253: Azure Storage Accounts Accessed Via Private Endpoints](https://help.drata.com/en/articles/9828851-test-253-azure-storage-accounts-accessed-via-private-endpoints.md): Drata validates that private endpoints are used to access Azure Storage Accounts. - [Test 254: Azure Key Vaults Key Expiration](https://help.drata.com/en/articles/12369439-test-254-azure-key-vaults-key-expiration.md): Drata validates that an expiration date is set for all enabled keys in Azure key vaults. - [Test 256: Azure SQL Servers Auditing](https://help.drata.com/en/articles/9999539-test-256-azure-sql-servers-auditing.md): Drata validates that Azure SQL servers auditing is enabled for SQL servers. - [Test 257: Azure PostgreSQL Database Server Log Checkpoints](https://help.drata.com/en/articles/10375748-test-257-azure-postgresql-database-server-log-checkpoints.md): Drata validates that 'log\_checkpoints' is enabled for all Azure PostgreSQL database servers. - [Test 263: Azure Storage Accounts Secure TLS Configuration](https://help.drata.com/en/articles/9828854-test-263-azure-storage-accounts-secure-tls-configuration.md): Drata validates that the 'Minimum TLS version' for Azure storage accounts is set to TLS version 1.2. - [Test 268: Azure Network Security Group SSH Public Access Restricted](https://help.drata.com/en/articles/9828856-test-268-azure-network-security-group-ssh-public-access-restricted.md): Drata validates that no network security groups in Azure have inbound rules that allow unrestricted access to SSH port \(22\). - [Test 269: Azure App Service Web App Redirects HTTP Traffic to HTTPS](https://help.drata.com/en/articles/9828857-test-269-azure-app-service-web-app-redirects-http-traffic-to-https.md): Drata validates that Web Apps in Azure App Service redirect non-secure HTTP traffic to HTTPS. - [Test 270: Azure SQL Data Encryption](https://help.drata.com/en/articles/9828859-test-270-azure-sql-data-encryption.md): Drata validates that data encryption is enabled on all Azure SQL server databases. - [Test 290: AWS Database Writes I/O Monitored](https://help.drata.com/en/articles/9828793-test-290-aws-database-writes-i-o-monitored.md): Drata validates that AWS database clusters and database instances have a CloudWatch metric alarm for writes I/O for each cluster or instance - [Test 291: AWS Security Groups HTTP Access Restricted](https://help.drata.com/en/articles/9828797-test-291-aws-security-groups-http-access-restricted.md): Drata validates that AWS Security Groups restrict inbound HTTP access \(Port 80\) to specific IP or IP ranges only. - [Test 292: AWS EC2 Instances IMDSv1 Disabled](https://help.drata.com/en/articles/9828799-test-292-aws-ec2-instances-imdsv1-disabled.md): Drata validates that active AWS EC2 instances have Instance MetaData Service Version 1 \(IMDSv1\) disabled. - [Test 293: AWS Classic Load Balancer Latency Monitored](https://help.drata.com/en/articles/9828801-test-293-aws-classic-load-balancer-latency-monitored.md): Validates that all AWS Classic Load Balancers have a CloudWatch metric alarm for latency and that the alarm is subscribed to an SNS topic. - [Test 294: AWS Application Load Balancer Target Response Time Monitored](https://help.drata.com/en/articles/9828803-test-294-aws-application-load-balancer-target-response-time-monitored.md): Validates AWS Application Load Balancers have CloudWatch metric alarm for target response time and each alarm is subscribed to an SNS topic. - [Test 295: AWS Classic Load Balancer Server Errors Monitored](https://help.drata.com/en/articles/9828804-test-295-aws-classic-load-balancer-server-errors-monitored.md): Validates that all AWS Classic Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for server errors. - [Test 296: AWS Application Load Balancer Server Errors Monitored](https://help.drata.com/en/articles/9828806-test-296-aws-application-load-balancer-server-errors-monitored.md): Drata validates that all AWS Application Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for server errors. - [Test 297: AWS Classic Load Balancer Unhealthy Hosts Monitored](https://help.drata.com/en/articles/9828820-test-297-aws-classic-load-balancer-unhealthy-hosts-monitored.md): Drata validates that all AWS Classic Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for unhealthy hosts count. - [Test 298: AWS Application Load Balancer Unhealthy Hosts Monitored](https://help.drata.com/en/articles/9828822-test-298-aws-application-load-balancer-unhealthy-hosts-monitored.md): Validates that all AWS Application Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for unhealthy hosts count. - [Test 299: AWS Application Load Balancer Redirects HTTP to HTTPS](https://help.drata.com/en/articles/9828823-test-299-aws-application-load-balancer-redirects-http-to-https.md): Drata validates that for all AWS Application Load Balancer listeners, there is has a rule that redirects unencrypted HTTP traffic to HTTPS. - [Test 300: AWS Lambda Error Rate Monitored](https://help.drata.com/en/articles/9828825-test-300-aws-lambda-error-rate-monitored.md): Drata validates that all AWS Lambda functions have a CloudWatch metric alarm for error rate. - [Test 301: AWS DynamoDB Point-in-Time Recovery Enabled](https://help.drata.com/en/articles/9999538-test-301-aws-dynamodb-point-in-time-recovery-enabled.md): Drata validates that each DynamoDB table has point-in-time recovery status set to enabled. - [Test 310: Audit Logs Enabled for EKS Clusters](https://help.drata.com/en/articles/10375560-test-310-audit-logs-enabled-for-eks-clusters.md) - [Example Evidence Gitlab On-Prem](https://help.drata.com/en/articles/8709228-example-evidence-gitlab-on-prem.md) ## Enhancing your workflow - [Custom Fields Overview](https://help.drata.com/en/articles/13687561-custom-fields-overview.md): By creating custom fields, you can tailor data collection to your organization's specific needs for risks, controls, vendors, and personnel. - [Custom fields and formulas to represent the FAIR model](https://help.drata.com/en/articles/11593525-custom-fields-and-formulas-to-represent-the-fair-model.md): Using Drata’s custom fields and formulas to represent the FAIR model in Risk Management - [Automate Actions with Drata’s Workflows](https://help.drata.com/en/articles/11751113-automate-actions-with-drata-s-workflows.md): Automate tasks, notifications, and webhooks in Drata with workflows triggered by control, evidence, risk or personnel events. - [View and Manage Workflows](https://help.drata.com/en/articles/11752727-view-and-manage-workflows.md): Learn how to view, filter, and manage workflows in Drata, including published versions, run logs, and workflow actions. - [Create Workflow for Control](https://help.drata.com/en/articles/12876602-create-workflow-for-control.md): Learn how to build automated control workflows in Drata to improve compliance efficiency, trigger actions, and integrate with external tools. - [Create Workflow for Personnel](https://help.drata.com/en/articles/12876875-create-workflow-for-personnel.md): Create automated personnel workflows in Drata to track compliance status changes, send notifications, and more! - [Create Workflow for Evidence](https://help.drata.com/en/articles/12876880-create-workflow-for-evidence.md): Learn how to build evidence workflows in Drata to manage renewals and notify stakeholders. - [Create Workflow for Risk](https://help.drata.com/en/articles/12876894-create-workflow-for-risk.md): Learn how to build automated risk workflows in Drata to monitor inherent and residual score changes, trigger alerts, and more! - [Manage tasks in Drata](https://help.drata.com/en/articles/13688199-manage-tasks-in-drata.md): Learn how to track, create, complete, and manage automated and custom tasks in Drata to support continuous compliance operations. - [Task notifications](https://help.drata.com/en/articles/12141398-task-notifications.md): Learn how to manage task email notifications including upcoming task reminders and past due tasks. - [Tasks and Workspaces](https://help.drata.com/en/articles/12143145-tasks-and-workspaces.md): Learn how Drata tasks work across workspaces, including workspace-specific, company-wide, and role-based visibility. - [Manage Risk Tasks in Drata \(New Experience\)](https://help.drata.com/en/articles/14435209-manage-risk-tasks-in-drata-new-experience.md) - [Bulk Import Custom Tasks](https://help.drata.com/en/articles/14744132-bulk-import-custom-tasks.md): In this article, you learn how to create many custom tasks at once using bulk import. - [Jira security tickets: Label vs JQL](https://help.drata.com/en/articles/4806017-jira-security-tickets-label-vs-jql.md) - [Create and Manage Tickets in Drata \(New Experience\)](https://help.drata.com/en/articles/13688350-create-and-manage-tickets-in-drata-new-experience.md) - [Ticket Automation \(Jira-only\) \(Classic Experience\)](https://help.drata.com/en/articles/6953569-ticket-automation-jira-only-classic-experience.md): Configure rules to automatically create Jira tickets based on control and test events. - [Create and map Jira Tickets in Drata](https://help.drata.com/en/articles/6474482-create-and-map-jira-tickets-in-drata.md): Create and view Jira tickets for Controls, Tests and Risk Management directly through Drata - [Create Tickets for ServiceNow](https://help.drata.com/en/articles/7885041-create-tickets-for-servicenow.md): This article covers how to create manual tickets in ServiceNow via Drata. - [Create Tickets for Asana](https://help.drata.com/en/articles/7968908-create-tickets-for-asana.md): Create an Asana ticket through Drata associated with risk, control, or test. - [Create Tickets for Basecamp](https://help.drata.com/en/articles/8206940-create-tickets-for-basecamp.md): Create Basecamp tickets through Drata associated with risk, control, or test. - [Create Tickets for Bitbucket](https://help.drata.com/en/articles/8206968-create-tickets-for-bitbucket.md): Create a Bitbucket ticket through Drata associated with risk, control, or test. - [Create Tickets for Freshdesk](https://help.drata.com/en/articles/8206987-create-tickets-for-freshdesk.md): Create a Freshdesk ticket through Drata associated with risk, control, or test. - [Create Tickets for Freshservice](https://help.drata.com/en/articles/8207011-create-tickets-for-freshservice.md): Create Freshservice tickets through Drata associated with risk, control, or test. - [Create Tickets for Height](https://help.drata.com/en/articles/8207022-create-tickets-for-height.md): Create Height tickets through Drata associated with risk, control, or test. - [Create Tickets for Hive](https://help.drata.com/en/articles/8207038-create-tickets-for-hive.md): Create Hive tickets through Drata associated with risk, control, or test. - [Create Tickets for Teamwork](https://help.drata.com/en/articles/8207048-create-tickets-for-teamwork.md): Create Teamwork tickets through Drata associated with risk, control, or test. - [Create Tickets for Wrike](https://help.drata.com/en/articles/8207066-create-tickets-for-wrike.md): Create Wrike tickets through Drata associated with risk, control, or test. - [Create Tickets for Zendesk](https://help.drata.com/en/articles/8209157-create-tickets-for-zendesk.md): Create Zendesk tickets through Drata associated with risk, control, or test. - [Create Tickets for Aha!](https://help.drata.com/en/articles/8209168-create-tickets-for-aha.md): Create an Aha ticket through Drata associated with risk, control, or test. - [Create Tickets for GitLab Issues](https://help.drata.com/en/articles/8342213-create-tickets-for-gitlab-issues.md): Create a GitLab ticket through Drata associated with risk, control, or test. ## Assessing Your Readiness - [Scope Determination Checklist for Compliance Audits](https://help.drata.com/en/articles/11759499-scope-determination-checklist-for-compliance-audits.md): A practical guide to scoping the right systems, people, data, and processes for compliance frameworks - [Are Your Controls Ready? Understanding the Relationship Between Policies, Evidence, and Controls](https://help.drata.com/en/articles/10723594-are-your-controls-ready-understanding-the-relationship-between-policies-evidence-and-controls.md): Mapping Policies, Evidence, and Controls for Compliance - [Pre-Audit Checklist: How to Prepare for Your Audit with Drata](https://help.drata.com/en/articles/12020733-pre-audit-checklist-how-to-prepare-for-your-audit-with-drata.md) ## The Auditor Experience - [Understanding the Drata + Fieldguide Integration](https://help.drata.com/en/articles/11504009-understanding-the-drata-fieldguide-integration.md) - [Set up the Drata + Fieldguide integration in Audit Hub](https://help.drata.com/en/articles/15436000-set-up-the-drata-fieldguide-integration-in-audit-hub.md) - [Work in a Fieldguide-connected audit in Audit Hub](https://help.drata.com/en/articles/15436045-work-in-a-fieldguide-connected-audit-in-audit-hub.md) - [What auditors need to do for the Drata + Fieldguide integration](https://help.drata.com/en/articles/15436084-what-auditors-need-to-do-for-the-drata-fieldguide-integration.md) - [Using the Drata Audit Portal \(New Experience\)](https://help.drata.com/en/articles/13773092-using-the-drata-audit-portal-new-experience.md): A guide for external auditors - [Auditor API Key Self Service](https://help.drata.com/en/articles/11614342-auditor-api-key-self-service.md) - [Using the Drata Evidence Package and Manifest File](https://help.drata.com/en/articles/12739202-using-the-drata-evidence-package-and-manifest-file.md) - [Audits page overview \(New Experience\)](https://help.drata.com/en/articles/13774474-audits-page-overview-new-experience.md): Use the Audits page to see all of your active and completed audits in one place, track progress against auditor requests, and manage evidence and communication without leaving Drata. - [Internal audits in Drata \(New Experience\)](https://help.drata.com/en/articles/13893566-internal-audits-in-drata-new-experience.md) - [View and Open Evidence from the Audits page \(New Experience\)](https://help.drata.com/en/articles/13893605-view-and-open-evidence-from-the-audits-page-new-experience.md) - [Pre-audit evidence packages in Drata \(New Experience\)](https://help.drata.com/en/articles/14324952-pre-audit-evidence-packages-in-drata-new-experience.md) - [What auditors can see in Audit Portal](https://help.drata.com/en/articles/15266741-what-auditors-can-see-in-audit-portal.md): A comparison guide showing what auditors can see in Audit Portal compared to what customers can see in Drata. - [Mark messages as read or unread in your audits \(New Experience\)](https://help.drata.com/en/articles/13557358-mark-messages-as-read-or-unread-in-your-audits-new-experience.md) - [Create and add auditors to an audit](https://help.drata.com/en/articles/13605649-create-and-add-auditors-to-an-audit.md): Use this article to create an audit, add auditors, and resolve common reasons an auditor may not have access in Drata. - [How audit date ranges and evidence sampling affect auditor access](https://help.drata.com/en/articles/13606011-how-audit-date-ranges-and-evidence-sampling-affect-auditor-access.md): This article explains why auditors may not see certain evidence and how audit date ranges and evidence sampling determine what’s included in an audit. - [Map audit requests to DCF controls with AI](https://help.drata.com/en/articles/16144674-map-audit-requests-to-dcf-controls-with-ai.md) ## GRC Best Practices - [Do cloud-hosted systems need Contingency Plans?](https://help.drata.com/en/articles/5956581-do-cloud-hosted-systems-need-contingency-plans.md) - [Are we required to have an independent Board of Directors?](https://help.drata.com/en/articles/5633581-are-we-required-to-have-an-independent-board-of-directors.md): Board of Directors Guidance - [How to Adjust Controls When You Don’t Have a Board of Directors](https://help.drata.com/en/articles/6501316-how-to-adjust-controls-when-you-don-t-have-a-board-of-directors.md) - [How to Determine Key Vendors to include in Drata?](https://help.drata.com/en/articles/6008277-how-to-determine-key-vendors-to-include-in-drata.md): Determine key vendor or vendors to include in Drata - [What Is a Subprocessor?](https://help.drata.com/en/articles/9792194-what-is-a-subprocessor.md): An overview of how compliance frameworks use the term "subprocessor." - [Annual Compliance Review](https://help.drata.com/en/articles/5696227-annual-compliance-review.md): Ensure your security posture is maintained year to year - [Disaster Recovery Checklist: Simple Steps for Business Resilience](https://help.drata.com/en/articles/12141266-disaster-recovery-checklist-simple-steps-for-business-resilience.md) - [The backup policy and version control](https://help.drata.com/en/articles/5168457-the-backup-policy-and-version-control.md): How should backups be done for your version control system