Do HITRUST e1 and i1 Assessments Require Policy Documents
Unraveling the intricacies of HITRUST assessments is crucial for organizations striving to achieve and maintain information security compliance. Understanding the role of policy documentation in the HITRUST framework is paramount to ensuring a robust and effective compliance strategy. Join us as we explore the requirements, considerations, and best practices surrounding policy documents in HITRUST E1 and I1 assessments. Gain valuable insights to navigate the compliance landscape with confidence. The new e1-validated HITRUST assessment offers a baseline level of assurance focused on implementing essential cybersecurity hygiene. The new i1-validated assessment provides a moderate level of assurance focused on implementing leading information security practices. The r2, a risk-based two-year validated assessment, scores the thoroughness of policies, procedures, and implementation regarding a particular requirement statement. The new e1 (Jan. 2023) and i1 (Jan. 2022) only score implementation, so does this mean policy or standards documents are not required? The e1 and i1 measure the implementation of several controls against the requirements stated in the entity’s formal policy or standards documentation. For instance, an evaluative element for a requirement statement may instruct the External Assessor to obtain and inspect the organization's specific security control policy or standard. We will also compare it to the technical enforcement of the control implementation within its systems. So, what if the organization has implemented the security control according to best practices but has no policy or standard practice requiring the level of security control? The requirement statement can’t be scored 100%. The security team may be doing the right thing, but since they are doing it without a mandate from leadership, the controls could be discarded, and the budget diverted quickly. While many call policy without implementation a work of fiction, I call the implementation of a security control without a requirement in a policy or standard vigilantism. Requirement statements and evaluative elements may not specifically call out testing a policy or standard, but when the user is required to follow a control, I would look to a policy document. Eight of the 19 domains in the e1 require policies to receive a full score, while 17 of the 19 domains in the i1 require policies for scoring. Would you like to learn more about tailoring your policies and procerus documents to meet compliance and justify your security controls? We can help your organization to craft policies. We will not only apply to the e1 or i1 HITRUST assessment but also prepare your organization for a r2 and improved governance of information security. Please contact risk3sixty for help.
Gary Holverson
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)