What are HITRUST Assurance Advisories designed to provide? (Select all that apply) [0051]
Select the four general risk factor categories used when scoping r2 assessments.
On an r2 assessment, when considering the CAP vs. gap decision, will CAPs be required if a Control Reference has an aggregate raw score of 72.5 across Requirement Statements with gaps?
Would the certification threshold be met in an e1 assessment if all Requirement Statements had Implemented scored at 50%?
An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?
(Select all that apply)
All i1 Readiness Assessments undergo HITRUST Quality Assurance (QA) reviews.
Halfway through an r2 assessment, management asks to add six implemented systems to the scope of primary components. What would the assessor need to do within MyCSF?
In which assessment(s) are you allowed to "carve out" third-party controls as not applicable? (Select all that apply) [0116]
If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".
The concept of HITRUST CSF risk levels was adapted from what security standard?