David, a member of an external assessor org, helped his client remediate a control gap. As part of the validation process David can then review the remediation for appropriateness. [0141]
An i1 Control Reference that scores a 37 would yield what result?
When creating different scenarios for an assessment where the scope has yet to be fully defined, which option allows you to see the difference in Requirement Statement counts without updating the object itself? [0181]
A control that is not documented cannot be measured. [0126]
During a HITRUST Assessment, what percentage of External Assessor hours must be performed by a CCSFP?
If the client and the External Assessor disagree on assessment scope, HITRUST will determine the final scope. [0027]
If an organization has a policy against uploading sensitive data to third parties, what option would facilitate providing evidence to the HITRUST QA team to support maturity level scoring?
When generating a test plan the assessor must only use the Illustrative Procedures provided within the tool. [0054]
Corrective Action Plans (CAPs) can be viewed centrally across multiple assessment objects.
For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.