Which of the following are appropriate types of inheritance within MyCSF? (Select all that apply) [0061]
Is the HITRUST CSF a replacement standard for HIPAA or NIST 800-53?
In which assessment(s) are you allowed to "carve out" third-party controls as not applicable? (Select all that apply) [0116]
A control that is not documented cannot be measured. [0126]
Requirement Statement scores are averaged to determine Control Reference and Domain scores.
What is the minimum number of days an organization must wait before a remediated requirement statement's Implemented maturity level can be reconsidered for i1 testing?
When considering third-party reports for reliance, what must be included in the report? (Select all that apply)
The HITRUST QA reservation must be made by the External Assessor at least six months in advance of the submission date.
The scoring of Requirement Statements is used to calculate the overall Domain score.
Which of the following does HITRUST certify?
Should a company always select the most current version of the CSF framework? [0163]
Halfway through an r2 assessment, management asks to add six implemented systems to the scope of primary components. What would the assessor need to do within MyCSF?
For an r2 assessment, what is the minimum number of days an organization should wait before a new or updated Policy and/or Procedure can be reconsidered for testing?
An Interim Assessment must be completed in how many months after r2 certification is achieved? [0023]
On an r2 Validated Assessment any domain that scores less than a 61 will result in what type of report? [0142]
For the maturity levels "Measured" and "Managed," any score above 50% requires the following supporting documentation. (Select all that apply)
Where can you go to view a reporting dashboard for your organization?
A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]
Which assessment type allows users to select any HITRUST authoritative source?
When will the MyCSF tool automatically create a subscriber’s interim assessment object for a previously certified assessment?
The HITRUST CSF applies to covered information across all transmission and storage methods.
The Certified CSF Practitioner (CCSFP) designation is good for how many years?
The A1 Security Assessment requirements can only be added to the r2 assessment type.
Would the certification threshold be met in an e1 assessment if all Requirement Statements had Implemented scored at 50%?
In an i1 assessment a Control Reference score of 62 would yield which result?
A pharmacy that accepts Medicare/Medicaid and also takes credit cards should include which regulatory factors in their assessment?
The HITRUST CSF is built upon the following model: [0134]
Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to an assessment object?
Select the four general risk factor categories used when scoping r2 assessments.
If the seven measurement criteria are not met, the strength rating for the Measured maturity level will be:
When conducting a Validated Assessment, the entity must score the Measured and Managed maturity levels.
What sample size should be pulled for a manual control that operates at a defined frequency of weekly?
Which assessment type is the most tailorable to an organization's risk profile?
If a requirement statement beginning with "The Privacy Officer..." scored a 50 instead of 42, would the overall assessment achieve certification?

An i1 Control Reference that scores a 37 would yield what result?
What characteristics would allow grouping of multiple like components together?
What information is required to complete the documentation of a Corrective Action Plan (CAP)? (Select all that apply) [0064]
An r2 Requirement Statement that scores at a 37 would yield which result?
How would you score implemented coverage for one system if two of four evaluative elements were in place?
David, a member of an external assessor organization, helped his client remediate a control gap. As part of the validation process, David can then review the remediation for appropriateness.
All i1 Readiness Assessments undergo HITRUST Quality Assurance (QA) reviews.
An r2 certification is good for how many years?