Help center icons
BlogSecurity
August 7, 2024

Top 5 help center articles for tests

Written by
Shannon DeLange
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Running tests against your security controls and other systems is a critical aspect of protecting your organization from a potential data breach and ensuring that you maintain compliance. Vanta’s platform has automated tests with continuous monitoring that run on an hourly basis against your controls as well as customized tests that you can adapt to your organization's needs. 

In this blog, we’ve highlighted the top five help center articles that can help you run tests more efficiently in Vanta. Whether you’re just getting started with the testing features in the platform or if you’re looking to up-level your existing tests, this blog is for you! 

#1 Getting Started with Tests

If you’re new to the platform and are looking to understand how the testing features work, this article is the perfect place to get started. This article will guide you in setting up and managing critical compliance tests in Vanta to ensure successful security monitoring and a smooth audit process. You’ll learn the basics of linking integrations, enabling specific tests such as multi-factor authentication (MFA) and SSL configurations, and uploading key organizational documents. You’ll also get steps for configuring tests and tips on which areas to focus on for audit readiness.

#2 The Tests Page

This article explains how to utilize Vanta's Tests page to monitor and improve your company's security posture. You’ll learn how to sort and filter tests by urgency, status, or category, assign tests to team members, and access detailed test histories and remediation guidance. Additionally, it covers how to set SLA deadlines for various test categories, using Vanta's recommendations if needed, to ensure timely compliance efforts.

#3 Customizing Automated Tests

If you’re looking to run tests unique to your systems, data, and controls this article is for you! This article explains how to customize Vanta's compliance tests to better align with your organization's security needs. You’ll learn which tests are available for customization and how to adjust parameters such as log retention periods, port restrictions, and review frequencies for various compliance requirements. By following the steps outlined, you’ll be able to modify tests to fit your specific compliance programs.

#4 Creating Custom Tests

This article will help you create and map custom tests to specific controls and frameworks. Learn how to create a custom test by adding necessary details such as the test name, description, remediation instructions, and associated integrations. Additionally, the article explains how to map these custom tests to relevant controls, ensuring they are effectively integrated into the overall compliance strategy.

#5 Test Source Data

This article explains how you can get detailed data on how tests receive information from integrated services to enhance transparency and troubleshooting. You’ll learn how to access the test source data table to review API requests, headers, and responses, as well as fetched data for individual resources. This will help you understand why a test may be passing or failing by comparing the test details and instructions with the actual source data.

Bonus: Collecting Evidence Course

This course provides a comprehensive guide to collecting evidence in Vanta using automated tests, custom tests, and document uploads. You'll gain insight into the significance of meeting service-level agreements and understand what key information auditors seek during the audit period.

For more help getting started or unlocking new parts of the Vanta platform, check out our Vanta Help Center or our Vanta Academy courses

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.