3 Months Free Update
3 Months Free Update
3 Months Free Update
An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor.
After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.
The concept of HITRUST CSF risk levels was adapted from what security standard?
The HITRUST CSF applies to covered information across all transmission and storage methods.
The HITRUST CSF applies to covered information in all forms (words, numbers, pictures, sounds).
Measured and Managed Maturity Levels can be scored for some, but not all, requirements in an r2 assessment object.
Is additional work required by the assessor to generate the NIST Cybersecurity Framework Report?
It is possible to test only privacy-related requirements to obtain a HITRUST privacy certification.
An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?
(Select all that apply)
Enter the value assigned to each of the following scoring levels on the HITRUST Scoring Rubric.
Vulnerability testing should never be performed on client systems by an external assessor.
Upon submission of an assessment object by the assessor, how many days does HITRUST take to either accept or reject the assessment?
Which of the following must be confirmed before inheriting requirement scores?
The Subscribers Comments field should be populated with the rationale for any requirement statement marked not-applicable (N/A).
Select the four general risk factor categories used when scoping r2 assessments.
What sample size should be pulled for a manual control that operates at a defined frequency of weekly?
For an r2 assessment, what is the minimum number of days an organization should wait before a new or updated Policy and/or Procedure can be reconsidered for testing?
If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".
What is the minimum number of items to sample from a population for a daily control?
What is the minimum number of days an organization must wait before a remediated requirement statement's Implemented maturity level can be reconsidered for i1 testing?