HITRUST CSF readiness (assessment domains)
Version: CSF v11, 19 assessment domains (readiness, domain level)
A domain-level readiness view of the HITRUST CSF, the certifiable security and privacy framework widely required by healthcare organizations and their vendors. Tracks preparedness across the 19 assessment domains used in HITRUST assessments; it does not reproduce the licensed CSF requirement statements.
Where we stand
Controls
50%
Evidence
6%
Policies
18%
16 of 19 clauses mapped to adopted controls
As of (just now)
Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.
Clause-by-clause readiness
| Clause | Title | Controls | Evidence | Policies | Last tested |
|---|---|---|---|---|---|
| 01 | Information protection program Controls: BIZ-12, BIZ-14, BIZ-15 | Passing | Not current | Not approved | Not yet |
| 02 | Endpoint protection | Unmapped | Unmapped | Unmapped | Not yet |
| 03 | Portable media security | Unmapped | Unmapped | Unmapped | Not yet |
| 04 | Mobile device security Controls: IT-02 | Not passing | Not current | Approved | Not yet |
| 05 | Wireless security | Unmapped | Unmapped | Unmapped | Not yet |
| 06 | Configuration management Controls: CLOUD-02, IT-04, IT-05 | Passing | Not current | Not approved | (29 d ago) |
| 07 | Vulnerability management Controls: CLOUD-05, IT-03, MON-04, MON-05, MON-06 | Not passing | Not current | Not approved | (8 h ago) |
| 08 | Network protection Controls: CLOUD-03 | Passing | Not current | Approved | Not yet |
| 09 | Transmission protection Controls: CLOUD-01, DATA-03, DATA-06 | Not passing | Not current | Not approved | (8 h ago) |
| 10 | Password management Controls: IAM-02, IAM-03, IAM-08 | Not passing | Not current | Not approved | (8 h ago) |
| 11 | Access control Controls: IAM-04, IAM-05, IAM-06, IAM-07, IAM-09 | Not passing | Not current | Not approved | (29 d ago) |
| 12 | Audit logging and monitoring Controls: MON-01, MON-02, MON-03 | Not passing | Not current | Not approved | (3 mo ago) |
| 13 | Education, training, and awareness Controls: PEOPLE-06 | Not passing | Current | Approved | (8 h ago) |
| 14 | Third-party assurance Controls: VEND-01, VEND-02, VEND-03, VEND-04 | Not passing | Not current | Not approved | (8 h ago) |
| 15 | Incident management Controls: BIZ-02, BIZ-03, BIZ-21 | Passing | Not current | Not approved | (8 h ago) |
| 16 | Business continuity and disaster recovery Controls: BIZ-01, BIZ-20, DATA-12, DATA-15 | Passing | Not current | Not approved | (29 d ago) |
| 17 | Risk management Controls: BIZ-04, BIZ-05, BIZ-09 | Passing | Not current | Not approved | (4 mo ago) |
| 18 | Physical and environmental security Controls: PHYS-01 | Passing | Not current | Not approved | Not yet |
| 19 | Data protection and privacy Controls: DATA-01, DATA-02, DATA-04, DATA-05, LEGAL-01 | Passing | Not current | Not approved | Not yet |
