Learning how to provide compelling HITRUST evidence
Once your organization has collected timely and concise evidence to demonstrate HITRUST compliance, the information must be provided to your HITRUST External Assessor Organization. Create a clear and detailed document that explains how each control is implemented within your organization. This document should align with the specific information request since one information request may support several HITRUST requirement statements. Screenshots illustrate firewall configuration settings, encryption configurations, cloud settings, policy availability, and more. Images are important evidence; however, I prefer to see them embedded in a PDF with text describing the images, especially when there are a series of images. Ensure that the evidence is accompanied by any necessary explanations, clarifications, or context to help the assessor understand the significance and relevance of the evidence presented. Often two screenshot images from a landscape monitor, each with a description, will not fit on a portrait page. Still, a landscape page may maximize the image, improving clarity for the external assessor. In addition to the image descriptions, the text of the information request could be placed in a searchable format at the top of the image. Ask yourself, would I be happy to assess this evidence? Would someone outside my department understand what is being expressed? A population of current users may be used in the Information Protection Program, Endpoint Protection, Password Management, Access Control, Education, Training and Awareness, Physical & Environmental Security domains, and others. If the evidence request, or information request list item, has a unique identifier, that is a great piece of information to use at the beginning of the file name. This makes the files line up in order in a directory and makes it easy to link the file multiple times once uploaded to the HITRUST MyCSF interactive portal. As an External Assessor, if the evidence request item is #301 I would rather see a file named “r301 current users.csv” than “list.csv". Policy and procedures documents should be provided to the External Assessor in a searchable format. These documents should serve as a detailed guide for understanding the implemented security measures and the approach to risk management. The External Assessor will likely need to search an entire document for the evaluative elements described in the requirement statement. If the element covered by the document uses different verbiage or would be difficult to search quickly, a separate document describing the location of the section addressing the requirement statement, possibly with a screenshot of the paragraph, is extremely helpful to the External Assessor. Open-source or non-proprietary file extensions are usually preferred:- PNG for large org charts, flow charts, and network diagrams
- PDF for documents and collections of screenshots
- CSV for exported lists
Gary Holverson
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)