Vulnerability testing should never be performed on client systems by an external assessor.
Documents placed in the document repository can be accessed across multiple assessment objects. [0113]
After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.
How large would the sample size be for a manual control with a population of 56 unique items?
An assessed entity is required to comply with six regulatory factors. Must the entity include all six regulatory factors in the scope of their assessment? [0088]
When an implementation gap is remediated, what is the minimum number of days the control must operate before retesting? [0130]
For an r2 assessment, what is the minimum number of days an organization should wait before a new or updated Policy and/or Procedure can be reconsidered for testing?
Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to an assessment object?
A readiness assessment report provides the highest level of assurance. [0019]
Requirement Statement scores are averaged to determine Control Reference and Domain scores.
When generating a test plan the assessor must only use the Illustrative Procedures provided within the tool. [0054]
Control Objectives are a statement of the desired result or purpose to be achieved by implementing control procedures into a particular process.
How would you score implemented coverage for one system if two of four evaluative elements were in place?
A validated assessment is only available to organizations after performing a readiness assessment. [0020]
Should a company always select the most current version of the CSF framework? [0163]
Which of the following are appropriate types of inheritance within MyCSF? (Select all that apply) [0061]
If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".
Which assessment type allows users to select any HITRUST authoritative source?
Using only the information from the chart and question below, please answer:
This assessment will be able to achieve certification. [0192]
In which assessment(s) are you allowed to "carve out" third-party controls as not applicable? (Select all that apply) [0116]
On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that score above 25% for Policy and Procedure, and over 0% for Implementation, Measured, and Managed.
If an organization requires an assessment with the highest level of assurance, which assessment type should they choose?
When creating different scenarios for an assessment where the scope has yet to be fully defined, which option allows you to see the difference in Requirement Statement counts without updating the object itself? [0181]
When considering third-party reports for reliance, what must be included in the report? (Select all that apply)
An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor.
An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?
(Select all that apply)
Under which version of the CSF did the framework go industry agnostic and HIPAA became its own regulatory factor?
When creating a new r2 assessment you are required to use the latest version of the HITRUST CSF.
A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]