# Drata Help Center > Drata Help Center ## Getting Started - [Submitting a Feature Request](https://help.drata.com/en/articles/15184119-submitting-a-feature-request.md) - [Use Markdown formatting in supported text areas](https://help.drata.com/en/articles/15170455-use-markdown-formatting-in-supported-text-areas.md): Markdown helps you add simple formatting to text so your content is easier to read and organize. ## Settings - [Settings Page](https://help.drata.com/en/articles/13563975-settings-page.md): Overview of the Settings page and available configuration options. - [Manage workspace details \(New Experience\)](https://help.drata.com/en/articles/13567122-manage-workspace-details-new-experience.md): Update workspace URLs, frameworks, and managers. - [Find your Account ID](https://help.drata.com/en/articles/13755424-find-your-account-id.md) - [Organization settings: Organization Details \(New Experience\)](https://help.drata.com/en/articles/13565986-organization-settings-organization-details-new-experience.md): Manage your company information, locate your Account ID, and configure audit-facing details - [Organization settings: Key Personnel Information \(New Experience\)](https://help.drata.com/en/articles/13566374-organization-settings-key-personnel-information-new-experience.md): Define leadership and accountability roles used in audits and compliance reporting. - [Organization settings: Security awareness, HIPAA, and AI training](https://help.drata.com/en/articles/13566994-organization-settings-security-awareness-hipaa-and-ai-training.md) - [Organization settings: Human Resources Settings \(New Experience\)](https://help.drata.com/en/articles/13566413-organization-settings-human-resources-settings-new-experience.md): Configure personnel-related controls used for audit evidence and compliance reporting. - [Organization settings: Internal Security](https://help.drata.com/en/articles/13566935-organization-settings-internal-security.md): The Internal Security settings define how employee-related security evidence is sourced and tracked across your organization. - [Organization settings: Notifications rules](https://help.drata.com/en/articles/13566136-organization-settings-notifications-rules.md): Organization notifications rules let you configure automated compliance updates to Slack or Microsoft Teams. - [Personal settings: Notifications \(New Experience\)](https://help.drata.com/en/articles/13566050-personal-settings-notifications-new-experience.md) - [Your Drata Domain](https://help.drata.com/en/articles/10197849-your-drata-domain.md) - [Drata Compliance as Code](https://help.drata.com/en/articles/9930785-drata-compliance-as-code.md) - [Drata MCP — Setup & Usage Guide](https://help.drata.com/en/articles/13379899-drata-mcp-setup-usage-guide.md) - [Microsoft Copilot MCP Integration Guide](https://help.drata.com/en/articles/15369685-microsoft-copilot-mcp-integration-guide.md) ## Connection Support - [Understanding Azure Permissions and How Drata Integrates with Azure \(Concept Guide\)](https://help.drata.com/en/articles/13455183-understanding-azure-permissions-and-how-drata-integrates-with-azure-concept-guide.md): Learn how Azure tenants, subscriptions, Microsoft Graph permissions, and RBAC roles work together in the Drata Azure integration. - [Understanding AWS Permissions and How Drata Integrates with AWS \(Concept Guide\)](https://help.drata.com/en/articles/13455825-understanding-aws-permissions-and-how-drata-integrates-with-aws-concept-guide.md) - [Understanding GCP Permissions and How Drata Integrates with GCP \(Concept Guide\)](https://help.drata.com/en/articles/13456365-understanding-gcp-permissions-and-how-drata-integrates-with-gcp-concept-guide.md) - [Workday Implementation Best Practices](https://help.drata.com/en/articles/14092393-workday-implementation-best-practices.md) ## Policy Guidance - [Essential Policy FAQs: Your Quick Guide](https://help.drata.com/en/articles/10414305-essential-policy-faqs-your-quick-guide.md): This quick guide answers your most common policy questions, helping you stay compliant and find the information you need quickly. - [Policies to Framework Summary](https://help.drata.com/en/articles/7973705-policies-to-framework-summary.md) - [Policy Acknowledge Grouping](https://help.drata.com/en/articles/5849305-policy-acknowledge-grouping.md) - [Policies: should they reflect what is currently in place or the adjustments you'll be making?](https://help.drata.com/en/articles/4752967-policies-should-they-reflect-what-is-currently-in-place-or-the-adjustments-you-ll-be-making.md) - [Policy Coverage for Privacy](https://help.drata.com/en/articles/6422263-policy-coverage-for-privacy.md): This article covers updating policies for privacy frameworks. - [Example Completed Data Classification Table](https://help.drata.com/en/articles/7860581-example-completed-data-classification-table.md) - [Developing a Physical Security Policy for a remote team](https://help.drata.com/en/articles/5036683-developing-a-physical-security-policy-for-a-remote-team.md) - [Control Mapping Updates for Policies - 4/13/2023](https://help.drata.com/en/articles/7250402-control-mapping-updates-for-policies-4-13-2023.md): Updates to policy mappings related to NIST 800-53, NIST CSF and ISO 27001:2022 frameworks - [Business Continuity Plan - Appendix A: Business Impact Analysis](https://help.drata.com/en/articles/5732621-business-continuity-plan-appendix-a-business-impact-analysis.md) - [Roles and Responsibilities Guidance](https://help.drata.com/en/articles/5829670-roles-and-responsibilities-guidance.md) - [Vulnerability Scanning Guidance](https://help.drata.com/en/articles/6136232-vulnerability-scanning-guidance.md) - [Example Business Continuity Plan](https://help.drata.com/en/articles/6232796-example-business-continuity-plan.md) - [Acceptable Use Policy Guidance](https://help.drata.com/en/articles/6568639-acceptable-use-policy-guidance.md) - [Asset Management Policy Guidance](https://help.drata.com/en/articles/6568646-asset-management-policy-guidance.md) - [Backup Policy Guidance](https://help.drata.com/en/articles/6568647-backup-policy-guidance.md) - [Business Continuity Plan Guidance](https://help.drata.com/en/articles/6630838-business-continuity-plan-guidance.md) - [Code of Conduct Guidance](https://help.drata.com/en/articles/6630842-code-of-conduct-guidance.md) - [Example Threat Assessment Plan](https://help.drata.com/en/articles/6915781-example-threat-assessment-plan.md) - [Does Drata Have a Privacy Policy Template?](https://help.drata.com/en/articles/7060948-does-drata-have-a-privacy-policy-template.md) - [Data Classification Policy Guidance](https://help.drata.com/en/articles/7172842-data-classification-policy-guidance.md) - [System Access Control Policy Guidance](https://help.drata.com/en/articles/7211097-system-access-control-policy-guidance.md) - [Password Policy Guidance](https://help.drata.com/en/articles/7257685-password-policy-guidance.md) - [Terms of Service Guidance: DCF-63 and DCF-66](https://help.drata.com/en/articles/7257698-terms-of-service-guidance-dcf-63-and-dcf-66.md) - [Data Retention Policy Guidance](https://help.drata.com/en/articles/7257853-data-retention-policy-guidance.md) - [Responsible Disclosure Policy Guidance](https://help.drata.com/en/articles/7669169-responsible-disclosure-policy-guidance.md) - [Physical Security Policy Guidance](https://help.drata.com/en/articles/7763364-physical-security-policy-guidance.md) - [Vendor Management Policy Guidance](https://help.drata.com/en/articles/7852188-vendor-management-policy-guidance.md) - [Encryption Policy Guidance](https://help.drata.com/en/articles/7874603-encryption-policy-guidance.md) - [Disaster Recovery Plan Guidance](https://help.drata.com/en/articles/7885003-disaster-recovery-plan-guidance.md) - [Incident Response Plan Guidance](https://help.drata.com/en/articles/7885026-incident-response-plan-guidance.md) - [Information Security Policy Guidance](https://help.drata.com/en/articles/7947579-information-security-policy-guidance.md) - [Vulnerability Management Policy Guidance](https://help.drata.com/en/articles/7987363-vulnerability-management-policy-guidance.md) - [Software Development Lifecycle \(SDLC\) Policy Guidance](https://help.drata.com/en/articles/8002321-software-development-lifecycle-sdlc-policy-guidance.md) - [Risk Assessment Policy Guidance](https://help.drata.com/en/articles/8167887-risk-assessment-policy-guidance.md) - [Data Protection Policy Guidance](https://help.drata.com/en/articles/8260378-data-protection-policy-guidance.md) - [Change Management Policy Guidance](https://help.drata.com/en/articles/8364890-change-management-policy-guidance.md) - [Data Loss Prevention \(DLP\) Guidance](https://help.drata.com/en/articles/9702726-data-loss-prevention-dlp-guidance.md) - [Logging and Monitoring Policy Guidance](https://help.drata.com/en/articles/9829067-logging-and-monitoring-policy-guidance.md) - [Maintenance Management Policy Guidance](https://help.drata.com/en/articles/11140737-maintenance-management-policy-guidance.md) - [System and Information Integrity Policy Guidance](https://help.drata.com/en/articles/11140776-system-and-information-integrity-policy-guidance.md) - [Personal Data Management Policy Guidance](https://help.drata.com/en/articles/11140868-personal-data-management-policy-guidance.md) - [Information Governance Policy Guidance](https://help.drata.com/en/articles/13188487-information-governance-policy-guidance.md): The following article contains guidance explaining portions of the Information Security Policy that we frequently see questions around, explaining what the sections mean. ## Monitoring Test Guidance - [Test: IRP Designates Responsible Team Members](https://help.drata.com/en/articles/4776932-test-irp-designates-responsible-team-members.md): Drata inspects your company Incident Response Plan to determine if it specifies roles for monitoring and responding to incidents. - [Test: IRP Includes Lessons Learned](https://help.drata.com/en/articles/4776933-test-irp-includes-lessons-learned.md): Drata inspects your company Incident Response Plan to ensure it includes a section about documenting “Lessons Learned” after incidents. - [Test: Has Security Policies](https://help.drata.com/en/articles/4776938-test-has-security-policies.md): Drata inspects your company's security policies to determine if they account for securing the company's operations, services, and systems. - [Test: Process for Responsible Disclosure](https://help.drata.com/en/articles/4776891-test-process-for-responsible-disclosure.md): Drata inspects your company security policies to determine if they detail a process for employees to disclose potential security violations. - [Test: Policies for a Security Team](https://help.drata.com/en/articles/4778523-test-policies-for-a-security-team.md): Drata inspects your company records to determine if management has identified the individuals on the security team. - [Test: Backups Checked for Integrity](https://help.drata.com/en/articles/4778883-test-backups-checked-for-integrity.md): Drata inspects your backup restoration testing results to determine if the integrity and completeness of backup information is tested. - [Test: High Vulnerabilities Addressed](https://help.drata.com/en/articles/9859341-test-high-vulnerabilities-addressed.md) - [Test: Policies are Acknowledged](https://help.drata.com/en/articles/4776941-test-policies-are-acknowledged.md): Drata inspects your company security policy records to determine if all employees have acknowledged them. - [Test: Employees Acknowledge the Data Protection Policy](https://help.drata.com/en/articles/4776961-test-employees-acknowledge-the-data-protection-policy.md): Drata inspects your company records to determine if the Data Protection Policy has been been acknowledged by all employees. - [Test: Termination Process and Checklist](https://help.drata.com/en/articles/4797463-test-termination-process-and-checklist.md): Drata inspects your company System Access Control Policy to determine if there is a termination checklist being followed appropriately. - [Test: Critical Vulnerabilities Addressed](https://help.drata.com/en/articles/9859338-test-critical-vulnerabilities-addressed.md) - [October 2024 Release: AWS Drata test](https://help.drata.com/en/articles/10034590-october-2024-release-aws-drata-test.md): New AWS tests in released in October 30, 2024. - [February 2025 Release: AWS and Azure Drata Tests](https://help.drata.com/en/articles/10437783-february-2025-release-aws-and-azure-drata-tests.md): We’re excited to announce the release of new tests in Drata. These AWS and Azure tests were released in February 5, 2025. - [Test 1: Policies Cover Employee Access](https://help.drata.com/en/articles/4776868-test-1-policies-cover-employee-access.md): Drata inspects your company policies to determine if they outline the proper requirements for allowing employees access to customer data. - [Test 2: Policies Cover Employee Confidentiality](https://help.drata.com/en/articles/4776871-test-2-policies-cover-employee-confidentiality.md): Drata inspects your company policies to determine if they require employees to keep customer data completely confidential. - [Test 3: Least Privilege Policy for Customer Data Access](https://help.drata.com/en/articles/4776875-test-3-least-privilege-policy-for-customer-data-access.md): Drata inspects your company security policies to determine if employees are only allowed access to customer data when absolutely necessary. - [Test 4: SSL/TLS on Admin Page of Infrastructure Console](https://help.drata.com/en/articles/4776882-test-4-ssl-tls-on-admin-page-of-infrastructure-console.md): Drata inspects an HTTPS request to your company infrastructure admin console to determine the presence and status of an SSL certificate. - [Test 5: A Version Control System is being Used](https://help.drata.com/en/articles/4776883-test-5-a-version-control-system-is-being-used.md): Drata inspects your company version control system to determine if it is in fact being used. - [Test 6: Only Authorized Employees Access Version Control](https://help.drata.com/en/articles/4778488-test-6-only-authorized-employees-access-version-control.md): Drata uses OAuth to access your company's Identity Provider and version control system ensuring access is permitted correctly. - [Test 7: Only Authorized Employees Change Code](https://help.drata.com/en/articles/4778497-test-7-only-authorized-employees-change-code.md): Drata uses OAuth to access your company's Identity Provider \(IdP\) and version control system to ensure only authorized users change code. - [Test 8: Formal Code Review Process](https://help.drata.com/en/articles/4776886-test-8-formal-code-review-process.md): Drata reads branch configurations for all in-scope repos in your version control system to ensure reviews are required before merging code . - [Test 9: Production Code Changes Restricted](https://help.drata.com/en/articles/4777024-test-9-production-code-changes-restricted.md): Drata pulls a list of all of the authorized users with access to merge code to the default branch of a code repository in version control. - [Test 11: Contact Information Available to Customers](https://help.drata.com/en/articles/4776889-test-11-contact-information-available-to-customers.md): Drata inspects your company records to determine if a URL to customer-accessible support documentation has been provided. - [Test 13: System Access Control Policy](https://help.drata.com/en/articles/4776894-test-13-system-access-control-policy.md): Drata inspects your company records to determine if a System Access Control Policy is in place and is currently valid. - [Test 16: Information Security Policy](https://help.drata.com/en/articles/4776895-test-16-information-security-policy.md): Drata inspects your company records to determine if an Information Security Policy is in place and is currently valid. - [Test 17: Maintains Organization Chart](https://help.drata.com/en/articles/4776896-test-17-maintains-organization-chart.md): Drata inspects your company records to determine if an Organizational Chart has been uploaded within the last 12 months - [Test 18: Risk Assessment Policy](https://help.drata.com/en/articles/4776899-test-18-risk-assessment-policy.md): Drata inspects your company records to determine if a Risk Assessment Policy is in place and is currently valid. - [Test 21: Vulnerability Scanning](https://help.drata.com/en/articles/4776909-test-21-vulnerability-scanning.md): Drata requests verification that there is an active connection to a vulnerability scanning system in Drata. - [Test 26: Security Issues are Prioritized](https://help.drata.com/en/articles/4776916-test-26-security-issues-are-prioritized.md): Drata inspects your company task tracking system to determine if security issues are being tagged and prioritized accordingly. - [Test 27: SLA for Security Bugs](https://help.drata.com/en/articles/4776919-test-27-sla-for-security-bugs.md): Drata inspects your company records to determine if a Vulnerability Management Policy, that includes an SLA for P0 security bugs, is active. - [Test 28: Disaster Recovery Plan](https://help.drata.com/en/articles/4776923-test-28-disaster-recovery-plan.md): Drata inspects your company records to determine if a Disaster Recovery Plan is in place and is currently active. - [Test 30: Availability Zones Used](https://help.drata.com/en/articles/4776928-test-30-availability-zones-used.md): Drata inspects your company infrastructure configurations to determine if multiple availability zones \(AZs\) are utilized. - [Test 32: Policies for Tracking Security Items](https://help.drata.com/en/articles/4776929-test-32-policies-for-tracking-security-items.md): Drata inspects your company Incident Response Plan to determine if it includes a section about tracking follow-ups after an incident. - [Test 33: Incident Response Plan \(IRP\)](https://help.drata.com/en/articles/4776931-test-33-incident-response-plan-irp.md): Drata inspects your company records to determine if an Incident Response Plan is in place and is before the policy renewal date. - [Test 36: Has a SDLC Policy](https://help.drata.com/en/articles/4776936-test-36-has-a-sdlc-policy.md): Drata inspects your company records to determine if a Software Development Life Cycle Policy is in place and is currently active. - [Test 39: Security Policies are Reviewed](https://help.drata.com/en/articles/4776944-test-39-security-policies-are-reviewed.md): Drata inspects your company records to determine if Management reviewed and approved its security policies before the renewal date. - [Test 42: Policies for Security Awareness Training](https://help.drata.com/en/articles/4778541-test-42-policies-for-security-awareness-training.md): Drata inspects your company Information Security Policy to ensure the security team is responsible for training all employees on security. - [Test 43: Security Awareness Training Completed](https://help.drata.com/en/articles/4778548-test-43-security-awareness-training-completed.md): Drata inspects your company security awareness training certificates to determine if all employees have completed their training. - [Test 44: Acceptable Use Policy](https://help.drata.com/en/articles/4776945-test-44-acceptable-use-policy.md): Drata inspects your company records to determine if an Acceptable Use Policy is in place and is before the renewal date. - [Test 45: Employees Acknowledge the Acceptable Use Policy](https://help.drata.com/en/articles/4776946-test-45-employees-acknowledge-the-acceptable-use-policy.md): Drata inspects your company records to determine if the Acceptable Use Policy has been acknowledged by all employees. - [Test 46: Performance Evaluation Process](https://help.drata.com/en/articles/4778550-test-46-performance-evaluation-process.md): Drata inspects your company records to determine if there is a formal process to evaluate employee performance. - [Test 47: Employee Background Checks](https://help.drata.com/en/articles/4778551-test-47-employee-background-checks.md): Drata inspects your company records to determine if all new employees have completed background checks upon hire. - [Test 48: Contractors Acknowledge the Code of Conduct](https://help.drata.com/en/articles/4776948-test-48-contractors-acknowledge-the-code-of-conduct.md): Drata inspects your company records to determine if the Code of Conduct has been acknowledged by all contractors. - [Test 49: Contractors Acknowledge the Acceptable Use Policy](https://help.drata.com/en/articles/4776953-test-49-contractors-acknowledge-the-acceptable-use-policy.md): Drata inspects your company records to determine if the Acceptable Use Policy has been acknowledged by all contractors. - [Test 50: Contractor Background Checks](https://help.drata.com/en/articles/4778553-test-50-contractor-background-checks.md): Drata inspects your company records to determine if all new contractors have completed background checks upon hire. - [Test 51: Independent Board of Directors](https://help.drata.com/en/articles/4776954-test-51-independent-board-of-directors.md): Drata inspects your company records to determine if all of its Board of Directors' biographies were saved. - [Test 54: Formal Code of Conduct](https://help.drata.com/en/articles/4776955-test-54-formal-code-of-conduct.md): Drata inspects your company records to determine if a Code of Conduct is in place and has is before the policy renewal date. - [Test 55: Employees Acknowledge the Code of Conduct](https://help.drata.com/en/articles/4776957-test-55-employees-acknowledge-the-code-of-conduct.md): Drata inspects your company records to determine if the Code of Conduct has been been acknowledged by all employees. - [Test 56: Data Protection Policy](https://help.drata.com/en/articles/4776958-test-56-data-protection-policy.md): Drata checks your company records to verify that a Data Protection Policy is in place and that it has not passed its renewal date. - [Test 58: New Hire Contracts](https://help.drata.com/en/articles/4778696-test-58-new-hire-contracts.md): Drata inspects your company records to determine if there is a sample new hire contract. - [Test 59: Job Descriptions](https://help.drata.com/en/articles/4778705-test-59-job-descriptions.md): Drata inspects your company records to determine if a URL to its external jobs/careers website has been provided. - [Test 60: Engineering Job Description](https://help.drata.com/en/articles/4778708-test-60-engineering-job-description.md): Drata inspects your company records to determine if there is a sample engineering job description. - [Test 61: Screensaver Lock Required on Employee Computers](https://help.drata.com/en/articles/4778709-test-61-screensaver-lock-required-on-employee-computers.md): Drata inspects if employee computers have a required password 60 seconds or less after the machine has been idle for at least 15 minutes. - [Test 62: Password Manager Required](https://help.drata.com/en/articles/4777028-test-62-password-manager-required.md): Drata inspected your companies' security policies to determine if employees are required to use a password manager for cloud services. - [Test 63: Password Manager Records on Employee Computers](https://help.drata.com/en/articles/4775951-test-63-password-manager-records-on-employee-computers.md): Drata inspects your company computers to determine if each is running a password manager. - [Test 64: Malware Detection Software Installed](https://help.drata.com/en/articles/4776962-test-64-malware-detection-software-installed.md): Drata inspects your company computers to determine if each is running an antivirus software. - [Test 65: Security Patches Auto-Applied](https://help.drata.com/en/articles/4776966-test-65-security-patches-auto-applied.md): Drata inspects your company computers to determine if each automatically applies operating system security patches. - [Test 66: Hard-Disk Encryption Enabled on Employee Computers](https://help.drata.com/en/articles/4778714-test-66-hard-disk-encryption-enabled-on-employee-computers.md): Drata inspects your company computers to determine if each hard-disks is encrypted. - [Test 67: Cryptography Policy](https://help.drata.com/en/articles/4776969-test-67-cryptography-policy.md): Drata inspects your company records to determine if an Encryption Policy is in place and is before the policy renewal date. - [Test 68: Customer Data is Encrypted at Rest](https://help.drata.com/en/articles/4776970-test-68-customer-data-is-encrypted-at-rest.md): Drata inspects your company configuration of the database\(s\) storing customer data to determine if the data is encrypted at rest. - [Test 69: Customer Data in Cloud Storage is Encrypted at Rest](https://help.drata.com/en/articles/4776971-test-69-customer-data-in-cloud-storage-is-encrypted-at-rest.md): Drata inspects your company cloud storage configuration to ensure customer data is encrypted at rest when stored. - [Test 70: SSL/TLS Enforced on Company Website](https://help.drata.com/en/articles/4776181-test-70-ssl-tls-enforced-on-company-website.md): Drata makes a request to your company website to see if it's reachable exclusively over HTTPS. - [Test 71: SSL/TLS Configuration has No Known Issues](https://help.drata.com/en/articles/4776834-test-71-ssl-tls-configuration-has-no-known-issues.md): Drata makes a request to your company website to inspect its SSL/TLS configurations and determine if there are any known issues - [Test 72: SSL/TLS Certificate has Not Expired](https://help.drata.com/en/articles/4776839-test-72-ssl-tls-certificate-has-not-expired.md): Drata makes a request to your company website to inspect its SSL/TLS configurations and determine if the SSL certificate is expired. - [Test 83: MSAs Offered to Customers](https://help.drata.com/en/articles/4778733-test-83-msas-offered-to-customers.md): Drata inspects your company records to determine if there is a sample Master Service Agreement \(MSA\) in place. - [Test 84: Privacy Policy Publicly Available](https://help.drata.com/en/articles/4778740-test-84-privacy-policy-publicly-available.md): Drata inspects your company records to determine if a URL to its public Privacy Policy has been provided. - [Test 85: Terms of Use Publicly Available](https://help.drata.com/en/articles/4778743-test-85-terms-of-use-publicly-available.md): Drata inspects your company records to determine if a URL to its public Terms of Service has been provided. - [Test 86: MFA on Identity Provider](https://help.drata.com/en/articles/4776841-test-86-mfa-on-identity-provider.md): Drata uses its synchronized account delegation with your Identity Provider to request a list of all users and determine if MFA is enabled. - [Test 87: MFA on Version Control System](https://help.drata.com/en/articles/4776860-test-87-mfa-on-version-control-system.md): Drata connects to your companies' Version Control System and pulls all user accounts to determine if each has MFA enabled. - [Test 88: MFA on Infrastructure Console](https://help.drata.com/en/articles/4777035-test-88-mfa-on-infrastructure-console.md): Drata connects to the company's infrastructure and pulls a list of IAM accounts' auth configurations to determine if MFA is required. - [Test 89: Internal Password Policy for Employees](https://help.drata.com/en/articles/4776975-test-89-internal-password-policy-for-employees.md): Drata inspects your company records to determine if a Password Policy is in place and is before the policy renewal date. - [Test 94: Version Control Accounts Removed Properly](https://help.drata.com/en/articles/4777036-test-94-version-control-accounts-removed-properly.md): Drata inspects your company records to determine if terminated employee accounts are removed from version control within the specified SLA. - [Test 95: Infrastructure Accounts Properly Removed](https://help.drata.com/en/articles/4777040-test-95-infrastructure-accounts-properly-removed.md): Drata inspects your company records to determine if terminated employee accounts are removed from the infrastructure provider. - [Test 96: Employees have Unique Email Accounts](https://help.drata.com/en/articles/4776863-test-96-employees-have-unique-email-accounts.md): Drata uses its synchronized account delegation with your Identity Provider to verify ownership and authenticity of listed accounts. - [Test 97: Employees have Unique Version Control Accounts](https://help.drata.com/en/articles/4777042-test-97-employees-have-unique-version-control-accounts.md): Drata accesses your company version control system to determine if each account matches to an identity from the company's IdP. - [Test 98: Employees have Unique Infrastructure Accounts](https://help.drata.com/en/articles/4777045-test-98-employees-have-unique-infrastructure-accounts.md): Drata accesses your company infrastructure provider to determine if each account matches to an identity from the company's IdP. - [Test 102: Public SSH Denied](https://help.drata.com/en/articles/4776976-test-102-public-ssh-denied.md): Drata inspects all virtual assets to determine if security groups allow SSH access to public \(0.0.0.0/0\) - [Test 104: Cloud Storage Public Access Disabled](https://help.drata.com/en/articles/4777046-test-104-cloud-storage-public-access-disabled.md): Drata inspects the cloud data storage access configuration\(s\) to determine if read/write access is configured to restrict public access. - [Test 105: Threat Detection in Place](https://help.drata.com/en/articles/4778757-test-105-threat-detection-in-place.md): Drata inspects your company AWS configuration to determine if AWS GuardDuty is in place to detect unauthorized file additions. - [Test 106: Has a Backup Policy](https://help.drata.com/en/articles/4776867-test-106-has-a-backup-policy.md): Drata inspects your company records to determine if a Backup Policy is in place and is before the policy renewal date. - [Test 107: Daily Database Backups](https://help.drata.com/en/articles/4777050-test-107-daily-database-backups.md): Drata inspects your company backup configuration from its infrastructure provider to determine if the backup schedule is set to daily. - [Test 108: Storage Data Versioned or Retained](https://help.drata.com/en/articles/4778759-test-108-storage-data-versioned-or-retained.md): Drata inspects all data stores to determine if the data versioning configuration is enabled. - [Test 109: Logs are Centrally Stored](https://help.drata.com/en/articles/4778760-test-109-logs-are-centrally-stored.md): Drata inspects your company system configuration for collecting and storing logs to ensure logs are deposited in a central location. - [Test 110: Only Authorized Users can Access Log Sinks](https://help.drata.com/en/articles/4778762-test-110-only-authorized-users-can-access-log-sinks.md): Drata inspects the access policy for the infrastructure logging system to determine if only authorized users can access log sinks. - [Test 111: Logs are Retained for 365 Days](https://help.drata.com/en/articles/4778770-test-111-logs-are-retained-for-365-days.md): Drata inspects the retention policy for the infrastructure logging system to determine if the logs are being archived in long-term storage. - [Test 112: Database CPU Monitored](https://help.drata.com/en/articles/4776977-test-112-database-cpu-monitored.md): Drata inspects your company alerting and monitoring configuration to determine if server CPUs are monitored, with appropriate alerts. - [Test 113: Database Free Storage Space Monitored](https://help.drata.com/en/articles/4776980-test-113-database-free-storage-space-monitored.md): Drata inspects your company database monitoring configuration to determine if free storage space is monitored, with appropriate alerts. - [Test 114: Database Read I/O Monitored](https://help.drata.com/en/articles/4776984-test-114-database-read-i-o-monitored.md): Drata inspects your company database monitoring configuration to determine if I/O is monitored, with appropriate alerts. - [Test 115: Messaging Queue Message Age Monitored](https://help.drata.com/en/articles/4776986-test-115-messaging-queue-message-age-monitored.md): Drata inspects your company messaging queue monitoring configuration to determine if message age is monitored, with appropriate alerts. - [Test 116: NoSQL Cluster CPU Load Monitored](https://help.drata.com/en/articles/10029043-test-116-nosql-cluster-cpu-load-monitored.md): Inspects NoSQL cluster monitor and alert configurations to determine if CPU load is monitored and alerts when defined thresholds are crossed - [Test 117: NoSQL Cluster Storage Utilization Monitored](https://help.drata.com/en/articles/4776995-test-117-nosql-cluster-storage-utilization-monitored.md): Drata inspects your company NoSQL cluster configuration to determine if storage utilization is monitored, with appropriate alerts. - [Test 118: Infrastructure Instance CPU Monitored](https://help.drata.com/en/articles/4776997-test-118-infrastructure-instance-cpu-monitored.md): Drata inspects your company server monitoring configuration to determine if server CPU use is monitored, with appropriate alerts. - [Test 119: Firewall Default Disallows Traffic](https://help.drata.com/en/articles/4777002-test-119-firewall-default-disallows-traffic.md): Drata inspects your company firewall configuration files to determine if they are configured to deny all traffic not explicitly allowed. - [Test 121: Logs Monitored for Suspicious Activity](https://help.drata.com/en/articles/4797516-test-121-logs-monitored-for-suspicious-activity.md): Drata inspects the company infrastructure logs to determine that it is configured to monitor web traffic and suspicious activity. - [Test 122: Web Application Firewall in Place](https://help.drata.com/en/articles/4777003-test-122-web-application-firewall-in-place.md): Drata inspects the WAF configurations to determine if WAF is appropriately deployed and configured to appropriately block malicious traffic. - [Test 123: Cloud Infrastructure Linked to Drata](https://help.drata.com/en/articles/4778777-test-123-cloud-infrastructure-linked-to-drata.md): Drata inspects your company cloud infrastructure to ensure it is successfully linked to Drata. - [Test 124: Root Infrastructure Account Unused](https://help.drata.com/en/articles/4777051-test-124-root-infrastructure-account-unused.md): Drata inspects your company infrastructure provider configurations to determine if the Root account is unused. - [Test 127: Security Policies Cover Encryption](https://help.drata.com/en/articles/4778866-test-127-security-policies-cover-encryption.md): Drata inspects your company security policies to determine if they explain the procedures for encrypting sensitive data. - [Test 128: Physical Security Policy](https://help.drata.com/en/articles/4777004-test-128-physical-security-policy.md): Drata inspects your company records to determine if a Physical Security Policy is in place and currently valid. - [Test 129: Capacity and Usage Monitoring](https://help.drata.com/en/articles/4778868-test-129-capacity-and-usage-monitoring.md): Drata inspects your companies' processing capacity and usage reports to determine if processing capacity and usage is monitored. - [Test 130: Load Balancer Used](https://help.drata.com/en/articles/4777006-test-130-load-balancer-used.md): Drata inspects your company infrastructure to determine if Load Balancers are configured to balance between multiple availability zones. - [Test 131: Autoscale Server Instances](https://help.drata.com/en/articles/10029045-test-131-autoscale-server-instances.md): Determine if autoscaling was in place to provision new compute resources when predefined capacity thresholds are met. - [Test 132: Daily backup job status monitored](https://help.drata.com/en/articles/9999495-test-132-daily-backup-job-status-monitored.md): Drata inspected company's database snapshot history and determined a successful snapshot is available for the previous day. - [Test 133: Failed Backup Alerts Being Sent](https://help.drata.com/en/articles/4778878-test-133-failed-backup-alerts-being-sent.md): Infrastructure configurations and confirmed that alerts are configured to be sent to personnel when the backup process fails. - [Test 134: Failed Backups Addressed in Timely Manner](https://help.drata.com/en/articles/4778882-test-134-failed-backups-addressed-in-timely-manner.md): Drata inspected infrastructure configuration and confirmed that failed backups were resolved in a timely manner. - [Test 136: Data Retention Policy](https://help.drata.com/en/articles/4778884-test-136-data-retention-policy.md): Drata inspects your records to determine if a valid, approved Data Deletion Policy is in place with a data retention period specified. - [Test 137: Data Classification Policy](https://help.drata.com/en/articles/4777011-test-137-data-classification-policy.md): Drata inspects your company records to determine if a Data Classification Policy is in place and currently valid. - [Test 138: Deleting Customer Data Upon Terminated Contract](https://help.drata.com/en/articles/4778892-test-138-deleting-customer-data-upon-terminated-contract.md): Drata inspects your company records to determine if a valid, approved Data Deletion Policy is in place that specifies data deletion periods. - [Test 141: Clean Desk Policy](https://help.drata.com/en/articles/4778895-test-141-clean-desk-policy.md): Drata inspects your company records to determine if a Information Security Policy is in place and approved within the last 12 months. - [Test 143: Sensitive Data Disposal Policy](https://help.drata.com/en/articles/4778896-test-143-sensitive-data-disposal-policy.md): Drata inspects your company records to determine if an Information Security Policy is in place and is before the policy renewal date. - [Test 205: CloudTrail log file integrity validation enabled](https://help.drata.com/en/articles/10029049-test-205-cloudtrail-log-file-integrity-validation-enabled.md): Drata validates that AWS CloudTrail log validation is enabled on all trails. - [Test 206: SQL Freeable Memory Monitored](https://help.drata.com/en/articles/10029047-test-206-sql-freeable-memory-monitored.md): Determine if freeable memory is monitored and alerts to personnel are sent when defined thresholds are crossed. - [Test 208: Excessive Privileges Assigned](https://help.drata.com/en/articles/8946448-test-208-excessive-privileges-assigned.md) - [Test 209: External Exposure of Cloud Resources](https://help.drata.com/en/articles/8946449-test-209-external-exposure-of-cloud-resources.md) - [Test 210: Encryption in Transit](https://help.drata.com/en/articles/8946445-test-210-encryption-in-transit.md) - [Test 214: MFA for AWS Root Account](https://help.drata.com/en/articles/9828711-test-214-mfa-for-aws-root-account.md): Drata validates that multi-factor authentication \(MFA\) is enabled for the root user account in AWS. - [Test 215: AWS IAM Password Minimum Length](https://help.drata.com/en/articles/9828716-test-215-aws-iam-password-minimum-length.md): Drata validates that the AWS IAM password policy requires a minimum length of 14 characters or greater. - [Test 216: AWS IAM Password Reuse](https://help.drata.com/en/articles/9828717-test-216-aws-iam-password-reuse.md): Drata validates that AWS IAM password policy is configured to prevent reuse of any of the last 24 passwords. - [Test 217: AWS IAM Group-Based Access Control](https://help.drata.com/en/articles/9828704-test-217-aws-iam-group-based-access-control.md): Drata validates that IAM users are granted permissions only through groups and no users with inline policy or direct policy attachments. - [Test 218: AWS EBS Volume Encryption](https://help.drata.com/en/articles/9828784-test-218-aws-ebs-volume-encryption.md): Validates that default encryption for elastic block store \(EBS\) volume creation is enabled for every region where EC2 instances are detected - [Test 219: AWS RDS Auto Minor Version Upgrade](https://help.drata.com/en/articles/9828785-test-219-aws-rds-auto-minor-version-upgrade.md): Drata validates that the automatic minor version upgrade feature is enabled for AWS RDS instances. - [Test 220: AWS RDS Public Access Restricted](https://help.drata.com/en/articles/9828787-test-220-aws-rds-public-access-restricted.md): Drata validates that AWS RDS database instances do not allow unrestricted public access \(0.0.0.0/0\). - [Test 221: AWS S3 Bucket Access Logging](https://help.drata.com/en/articles/9828721-test-221-aws-s3-bucket-access-logging.md): Drata validates that AWS S3 bucket access logging is enabled on the AWS CloudTrail S3 bucket. - [Test 222: AWS CloudTrail Logs Encrypted](https://help.drata.com/en/articles/9828725-test-222-aws-cloudtrail-logs-encrypted.md): Drata validates that AWS CloudTrail logs are encrypted at rest using AWS KMS customer created master keys \(CMKs\). - [Test 223: AWS CMK Rotation](https://help.drata.com/en/articles/9828731-test-223-aws-cmk-rotation.md): Drata validates that key rotation is enabled for customer-created symmetric customer master keys \(CMKs\) in AWS Key Management Service \(KMS\). - [Test 224: AWS VPC Flow Logging](https://help.drata.com/en/articles/9828733-test-224-aws-vpc-flow-logging.md): Drata validates that VPC flow logging is enabled in all AWS VPCs. - [Test 225: Hardware MFA for AWS Root Account](https://help.drata.com/en/articles/9828713-test-225-hardware-mfa-for-aws-root-account.md): Drata validates that hardware MFA is enabled for the root user account in AWS. - [Test 226: AWS S3 Object-Level Logging for Read & Write Events](https://help.drata.com/en/articles/9828791-test-226-aws-s3-object-level-logging-for-read-write-events.md): Drata validates that object-level logging for read and write events is enabled for AWS S3 buckets. - [Test 227: AWS Network ACLs Public Remote Server Administration Access Restricted](https://help.drata.com/en/articles/9828735-test-227-aws-network-acls-public-remote-server-administration-access-restricted.md) - [Test 228: AWS Security Groups Restrict Public RDP Access](https://help.drata.com/en/articles/9828740-test-228-aws-security-groups-restrict-public-rdp-access.md) - [Test 229: AWS IAM Unused Credentials](https://help.drata.com/en/articles/9828680-test-229-aws-iam-unused-credentials.md): Drata validated that all credentials \(e.g., passwords, access keys\) for IAM users have been used within the last 45 days. - [Test 230: AWS IAM Principle of Least Privilege](https://help.drata.com/en/articles/9828707-test-230-aws-iam-principle-of-least-privilege.md): Drata validates that AWS IAM policies that allow broad access patterns or wild-card permissions \(e.g., '\*'\) are not used. - [Test 231: AWS EFS Encrypted at Rest](https://help.drata.com/en/articles/9828789-test-231-aws-efs-encrypted-at-rest.md): Drata validates that AWS Elastic File System \(EFS\) data is encrypted at rest using AWS KMS for all regions. - [Test 232: AWS IAM Access Key Rotation](https://help.drata.com/en/articles/9828694-test-232-aws-iam-access-key-rotation.md): Drata validated that all AWS IAM access keys have a key age of less than 90 days. - [Test 233: AWS VPC Default Security Groups Restrict All Traffic](https://help.drata.com/en/articles/9828741-test-233-aws-vpc-default-security-groups-restrict-all-traffic.md): Drata validates that all AWS VPC default security groups are configured to restrict all traffic. - [Test 234: AWS S3 HTTP Requests Denied](https://help.drata.com/en/articles/9828783-test-234-aws-s3-http-requests-denied.md): Drata validates that access policies for AWS S3 buckets are set to deny unencrypted, HTTP requests. - [Test 243: Azure Log Alert for Create Policy Assignment](https://help.drata.com/en/articles/9828827-test-243-azure-log-alert-for-create-policy-assignment.md): Drata validates that an activity log alert for the 'Create Policy Assignment' event exists in Azure. - [Test 244: Azure Log Alert for Delete Public IP Address](https://help.drata.com/en/articles/9828829-test-244-azure-log-alert-for-delete-public-ip-address.md): Drata validates that an activity log alert for the 'Delete Public IP Address' event exists in Azure. - [Test 245: Azure Log Alert for Delete Policy Assignment](https://help.drata.com/en/articles/9828840-test-245-azure-log-alert-for-delete-policy-assignment.md): Drata validates that an activity log alert for the 'Delete Policy Assignment' event exists in Azure. - [Test 246: Azure Log Alert for Create or Update Network Security Group](https://help.drata.com/en/articles/9828841-test-246-azure-log-alert-for-create-or-update-network-security-group.md): Drata validates that an activity log alert for the 'Create or Update Network Security Group' event exists in Azure. - [Test 247: Azure Log Alert for Delete Network Security Group](https://help.drata.com/en/articles/9828842-test-247-azure-log-alert-for-delete-network-security-group.md): Drata validates that an activity log alert for the 'Delete Network Security Group' event exists in Azure. - [Test 248: Azure Log Alert for Create or Update Security Solution](https://help.drata.com/en/articles/9828843-test-248-azure-log-alert-for-create-or-update-security-solution.md): Drata validates that an activity log alert for the 'Create or Update Security Solution' event exists in Azure. - [Test 249: Azure Log Alert for Delete Security Solution](https://help.drata.com/en/articles/9828845-test-249-azure-log-alert-for-delete-security-solution.md): Drata validates that an activity log alert for the 'Delete Security Solution' event exists in Azure. - [Test 250: Azure Log Alert for Create or Update SQL Server Firewall Rule](https://help.drata.com/en/articles/9828846-test-250-azure-log-alert-for-create-or-update-sql-server-firewall-rule.md): Drata validates that an activity log alert for the 'Create or Update SQL Server Firewall Rule' event exists in Azure. - [Test 251: Azure Log Alert for Delete SQL Server Firewall Rule](https://help.drata.com/en/articles/9828848-test-251-azure-log-alert-for-delete-sql-server-firewall-rule.md): Drata validates that an activity log alert for the 'Delete SQL Server Firewall Rule' event exists in Azure. - [Test 252: Azure Log Alert for Create or Update Public IP Address rule](https://help.drata.com/en/articles/9828850-test-252-azure-log-alert-for-create-or-update-public-ip-address-rule.md): Drata validates that an activity log alert for the 'Create or Update Public IP Address rule' event exists in Azure. - [Test 253: Azure Storage Accounts Accessed Via Private Endpoints](https://help.drata.com/en/articles/9828851-test-253-azure-storage-accounts-accessed-via-private-endpoints.md): Drata validates that private endpoints are used to access Azure Storage Accounts. - [Test 254: Azure Key Vaults Key Expiration](https://help.drata.com/en/articles/12369439-test-254-azure-key-vaults-key-expiration.md): Drata validates that an expiration date is set for all enabled keys in Azure key vaults. - [Test 256: Azure SQL Servers Auditing](https://help.drata.com/en/articles/9999539-test-256-azure-sql-servers-auditing.md): Drata validates that Azure SQL servers auditing is enabled for SQL servers. - [Test 257: Azure PostgreSQL Database Server Log Checkpoints](https://help.drata.com/en/articles/10375748-test-257-azure-postgresql-database-server-log-checkpoints.md): Drata validates that 'log\_checkpoints' is enabled for all Azure PostgreSQL database servers. - [Test 263: Azure Storage Accounts Secure TLS Configuration](https://help.drata.com/en/articles/9828854-test-263-azure-storage-accounts-secure-tls-configuration.md): Drata validates that the 'Minimum TLS version' for Azure storage accounts is set to TLS version 1.2. - [Test 268: Azure Network Security Group SSH Public Access Restricted](https://help.drata.com/en/articles/9828856-test-268-azure-network-security-group-ssh-public-access-restricted.md): Drata validates that no network security groups in Azure have inbound rules that allow unrestricted access to SSH port \(22\). - [Test 269: Azure App Service Web App Redirects HTTP Traffic to HTTPS](https://help.drata.com/en/articles/9828857-test-269-azure-app-service-web-app-redirects-http-traffic-to-https.md): Drata validates that Web Apps in Azure App Service redirect non-secure HTTP traffic to HTTPS. - [Test 270: Azure SQL Data Encryption](https://help.drata.com/en/articles/9828859-test-270-azure-sql-data-encryption.md): Drata validates that data encryption is enabled on all Azure SQL server databases. - [Test 290: AWS Database Writes I/O Monitored](https://help.drata.com/en/articles/9828793-test-290-aws-database-writes-i-o-monitored.md): Drata validates that AWS database clusters and database instances have a CloudWatch metric alarm for writes I/O for each cluster or instance - [Test 291: AWS Security Groups HTTP Access Restricted](https://help.drata.com/en/articles/9828797-test-291-aws-security-groups-http-access-restricted.md): Drata validates that AWS Security Groups restrict inbound HTTP access \(Port 80\) to specific IP or IP ranges only. - [Test 292: AWS EC2 Instances IMDSv1 Disabled](https://help.drata.com/en/articles/9828799-test-292-aws-ec2-instances-imdsv1-disabled.md): Drata validates that active AWS EC2 instances have Instance MetaData Service Version 1 \(IMDSv1\) disabled. - [Test 293: AWS Classic Load Balancer Latency Monitored](https://help.drata.com/en/articles/9828801-test-293-aws-classic-load-balancer-latency-monitored.md): Validates that all AWS Classic Load Balancers have a CloudWatch metric alarm for latency and that the alarm is subscribed to an SNS topic. - [Test 294: AWS Application Load Balancer Target Response Time Monitored](https://help.drata.com/en/articles/9828803-test-294-aws-application-load-balancer-target-response-time-monitored.md): Validates AWS Application Load Balancers have CloudWatch metric alarm for target response time and each alarm is subscribed to an SNS topic. - [Test 295: AWS Classic Load Balancer Server Errors Monitored](https://help.drata.com/en/articles/9828804-test-295-aws-classic-load-balancer-server-errors-monitored.md): Validates that all AWS Classic Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for server errors. - [Test 296: AWS Application Load Balancer Server Errors Monitored](https://help.drata.com/en/articles/9828806-test-296-aws-application-load-balancer-server-errors-monitored.md): Drata validates that all AWS Application Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for server errors. - [Test 297: AWS Classic Load Balancer Unhealthy Hosts Monitored](https://help.drata.com/en/articles/9828820-test-297-aws-classic-load-balancer-unhealthy-hosts-monitored.md): Drata validates that all AWS Classic Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for unhealthy hosts count. - [Test 298: AWS Application Load Balancer Unhealthy Hosts Monitored](https://help.drata.com/en/articles/9828822-test-298-aws-application-load-balancer-unhealthy-hosts-monitored.md): Validates that all AWS Application Load Balancers have a CloudWatch metric alarm \(subscribed to an SNS topic\) for unhealthy hosts count. - [Test 299: AWS Application Load Balancer Redirects HTTP to HTTPS](https://help.drata.com/en/articles/9828823-test-299-aws-application-load-balancer-redirects-http-to-https.md): Drata validates that for all AWS Application Load Balancer listeners, there is has a rule that redirects unencrypted HTTP traffic to HTTPS. - [Test 300: AWS Lambda Error Rate Monitored](https://help.drata.com/en/articles/9828825-test-300-aws-lambda-error-rate-monitored.md): Drata validates that all AWS Lambda functions have a CloudWatch metric alarm for error rate. - [Test 301: AWS DynamoDB Point-in-Time Recovery Enabled](https://help.drata.com/en/articles/9999538-test-301-aws-dynamodb-point-in-time-recovery-enabled.md): Drata validates that each DynamoDB table has point-in-time recovery status set to enabled. - [Test 310: Audit Logs Enabled for EKS Clusters](https://help.drata.com/en/articles/10375560-test-310-audit-logs-enabled-for-eks-clusters.md) - [Example Evidence Gitlab On-Prem](https://help.drata.com/en/articles/8709228-example-evidence-gitlab-on-prem.md) ## Assessing Your Readiness - [Scope Determination Checklist for Compliance Audits](https://help.drata.com/en/articles/11759499-scope-determination-checklist-for-compliance-audits.md): A practical guide to scoping the right systems, people, data, and processes for compliance frameworks - [Are Your Controls Ready? Understanding the Relationship Between Policies, Evidence, and Controls](https://help.drata.com/en/articles/10723594-are-your-controls-ready-understanding-the-relationship-between-policies-evidence-and-controls.md): Mapping Policies, Evidence, and Controls for Compliance ## The Auditor Experience - [Understanding the Drata + Fieldguide Integration](https://help.drata.com/en/articles/11504009-understanding-the-drata-fieldguide-integration.md) - [Set up the Drata + Fieldguide integration in Audit Hub](https://help.drata.com/en/articles/15436000-set-up-the-drata-fieldguide-integration-in-audit-hub.md) - [Work in a Fieldguide-connected audit in Audit Hub](https://help.drata.com/en/articles/15436045-work-in-a-fieldguide-connected-audit-in-audit-hub.md) - [What auditors need to do for the Drata + Fieldguide integration](https://help.drata.com/en/articles/15436084-what-auditors-need-to-do-for-the-drata-fieldguide-integration.md) - [Using the Drata Audit Portal \(New Experience\)](https://help.drata.com/en/articles/13773092-using-the-drata-audit-portal-new-experience.md): A guide for external auditors - [Auditor API Key Self Service](https://help.drata.com/en/articles/11614342-auditor-api-key-self-service.md) - [Using the Drata Evidence Package and Manifest File](https://help.drata.com/en/articles/12739202-using-the-drata-evidence-package-and-manifest-file.md) - [Audits page overview \(New Experience\)](https://help.drata.com/en/articles/13774474-audits-page-overview-new-experience.md): Use the Audits page to see all of your active and completed audits in one place, track progress against auditor requests, and manage evidence and communication without leaving Drata. - [Internal audits in Drata \(New Experience\)](https://help.drata.com/en/articles/13893566-internal-audits-in-drata-new-experience.md) - [View and Open Evidence from the Audits page \(New Experience\)](https://help.drata.com/en/articles/13893605-view-and-open-evidence-from-the-audits-page-new-experience.md) - [Pre-audit evidence packages in Drata \(New Experience\)](https://help.drata.com/en/articles/14324952-pre-audit-evidence-packages-in-drata-new-experience.md) - [What auditors can see in Audit Portal](https://help.drata.com/en/articles/15266741-what-auditors-can-see-in-audit-portal.md): A comparison guide showing what auditors can see in Audit Portal compared to what customers can see in Drata. - [Mark messages as read or unread in your audits \(New Experience\)](https://help.drata.com/en/articles/13557358-mark-messages-as-read-or-unread-in-your-audits-new-experience.md) - [Create and add auditors to an audit](https://help.drata.com/en/articles/13605649-create-and-add-auditors-to-an-audit.md): Use this article to create an audit, add auditors, and resolve common reasons an auditor may not have access in Drata. - [How audit date ranges and evidence sampling affect auditor access](https://help.drata.com/en/articles/13606011-how-audit-date-ranges-and-evidence-sampling-affect-auditor-access.md): This article explains why auditors may not see certain evidence and how audit date ranges and evidence sampling determine what’s included in an audit.