TION NO: 133 [Assessment Types and Process]
What type of scoping boundary includes the relevant IT platforms and supporting infrastructure used by one or more business units? [0155]
During HITRUST's QA phase of a Validated Assessment, HITRUST picks a sample of Control Objectives to review the assessor's validation and testing procedures.
Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to an assessment object?
Management has asked you to scope out an assessment including your entire network. What are some examples you may see listed as a primary scoping component?
Gaps with required CAPs must be remediated within six months.
The Subscribers Comments field should be populated with the rationale for any requirement statement marked not-applicable (N/A).
MyCSF analytics can be used to visualize data within an assessment object as well as across all assessment objects within an organization.
A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]
How is the sample of Requirement Statements within an interim assessment selected for testing?
How large would the sample size be for a manual control with a population of 56 unique items?