Hopefully, your organization did not need to discipline any users for security policy violations, experience a security incident, disclose covered information to law enforcement, or store covered information unencrypted this past year. If so, what type of evidence should you present to your HITRUST External Assessor Organization? For a zero population of events related to a requirement statement, I request an email from the security officer, compliance director, or manager leading the validated assessment for the assessed entity confirming that a particular event did not occur during the assessment period. This provides management assertion that the control did not operate with a time and date stamp from the email. But then what? It’s not enough to say that things didn’t happen during the assessment period, and assessed entities should provide the training and standard operating procedures that instruct users on how to handle the situation. Your External Assessor wants to see how the organization instructs the users to act if the control does operate. The External Assessor would like to see the training material describing the procedure for the event. Training material demonstrates the assessed entity’s commitment to educating staff about incident identification and reporting to reduce confusion and improve outcomes for rare situations. The External Assessor would also like to see the process and procedural documentation describing the actions the user should take in the situation described in the requirement statement. Additionally, if training or procedural documents need to be clarified, meeting minutes and/or quarterly reports noting that the control was unnecessary to add credibility to the claim of a zero population of events. Remember to ensure that all evidence provided is accurate, up-to-date, and relevant to the time frame of the validated assessment. Would you like to know more about preparing training materials and standard operating procedures for rare events scored in HITRUST-validated assessments? Please get in touch with risk3sixty for help.
Gary Holverson
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)