How large would the sample size be for a manual control with a population of 56 unique items?
An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?
(Select all that apply)
On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.
An Interim Assessment must be completed in how many months after r2 certification is achieved? [0023]
Which assessment type is the most tailorable to an organization's risk profile?
When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".
Which type of assessments must be performed to be eligible for certification? [0158]
If the client and the External Assessor disagree on assessment scope, HITRUST will determine the final scope. [0027]
Pre-populated default maturity level scores cannot be changed across an assessment object.
For the External Assessor QA process, the individual who acts as the Quality Assurance Reviewer for an assessor organization can also be the Engagement Executive.