Which of the following does HITRUST certify?
It is possible to test only privacy-related requirements to obtain a HITRUST privacy certification.
The concept of HITRUST CSF risk levels was adapted from what security standard?
To place reliance on a point-in-time assessment report, the issue date must be within two years from the assessment fieldwork start date. [0078]
Which of the following must be confirmed before inheriting requirement scores?
After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.
A hospital system based in both Texas and Massachusetts processes credit card data within its scoped environment. Management has asked that all relevant regulatory factors be included in the r2 assessment. Which of the following regulatory requirements should be selected? (Select all that apply) [0013]
A validated assessment is only available to organizations after performing a readiness assessment. [0020]
When partially inheriting a requirement statement score from an external cloud service provider, the weighting applied to the score is determined primarily by the assessed entity and the service provider. [0190]
When an implementation gap is remediated, what is the minimum number of days the control must operate before retesting? [0130]