On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.
Which of the following are true with e1, i1, and r2 assessment types? (Select all that apply)
A pharmacy that accepts Medicare/Medicaid and also takes credit cards should include which regulatory factors in their assessment?
If the seven measurement criteria are not met, the strength rating for the Measured maturity level will be:
A hospital system based in both Texas and Massachusetts processes credit card data within its scoped environment. Management has asked that all relevant regulatory factors be included in the r2 assessment. Which of the following regulatory requirements should be selected? (Select all that apply) [0013]
When partially inheriting a requirement statement score from an external cloud service provider, the weighting applied to the score is determined primarily by the assessed entity and the service provider. [0190]
A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]
When generating a test plan the assessor must only use the Illustrative Procedures provided within the tool. [0054]
For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.
Once an assessment has been submitted to the assessor, can the assessed entity change their responses?
An Interim Assessment must be completed in how many months after r2 certification is achieved? [0023]
What type of deficiency would be identified in the following Requirement Statement scoring scenario?
Policy = 50%
Process = 50%
Implemented = 75%
Measured = 0%
Managed = 0%
On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that score above 25% for Policy and Procedure, and over 0% for Implementation, Measured, and Managed.
How large would the sample size be for a manual control with a population of 56 unique items?
HITRUST offers certifications for the following: (Select all that apply) [0017]
The A1 Security Assessment requirements can only be added to the r2 assessment type.
A three-year HITRUST certification can be achieved by scoring 100% across all 19 Domains. [0095]
Upon submission of an assessment object by the assessor, how many days does HITRUST take to either accept or reject the assessment?
It is possible to test only privacy-related requirements to obtain a HITRUST privacy certification.
To perform a rapid assessment, the assessment and/or insights report must each contain more than 60 requirements.
Measured and Managed Maturity Levels can be scored for some, but not all, requirements in an r2 assessment object.
What is the minimum number of items to sample from a population for a daily control?
Vulnerability testing should never be performed on client systems by an external assessor.
Under which version of the CSF did the framework go industry agnostic and HIPAA became its own regulatory factor?
When an assessor has completed reviewing and agreeing with Requirement Statement scoring, the assessor must save the results. This action will mark the Requirement Statement as "Assessor Review Complete". [0049]
If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".
When scoping an r2 assessment, selecting regulatory factors is required and may generate additional Requirement Statements in the assessment object.
MyCSF analytics can be used to visualize data within an assessment object as well as across all assessment objects within an organization.
All assessment domains are updated with additional requirements when the AI Security factor is selected.
Control Objectives are a statement of the desired result or purpose to be achieved by implementing control procedures into a particular process.
Which version of the CSF supports a traversable requirement statement portfolio? [0107]
Can multiple assessments be performed on your organization simultaneously?
The assessor plans to test a population in a file, and they want to pick every 100th item. Which of the recognized sampling methodologies would best describe the sample that will be pulled?
When creating a new r2 assessment you are required to use the latest version of the HITRUST CSF.
How would you score implemented coverage for one system if two of four evaluative elements were in place?