FintastIQTrust Center
LoginBook a Consultation
Framework

HITRUST CSF readiness (assessment domains)

Version: CSF v11, 19 assessment domains (readiness, domain level)

A domain-level readiness view of the HITRUST CSF, the certifiable security and privacy framework widely required by healthcare organizations and their vendors. Tracks preparedness across the 19 assessment domains used in HITRUST assessments; it does not reproduce the licensed CSF requirement statements.

Official source

Summary

Where we stand

Controls
50%
Evidence
6%
Policies
18%

16 of 19 clauses mapped to adopted controls

As of (just now)

Percentages are over clauses mapped to at least one adopted control. Unmapped clauses are listed below and never count as passing. A known gap is a clause that applies to us and that no control covers yet.

Clauses

Clause-by-clause readiness

ClauseTitleControlsEvidencePoliciesLast tested
01Information protection program
Controls: BIZ-12, BIZ-14, BIZ-15
PassingNot currentNot approvedNot yet
02Endpoint protectionUnmappedUnmappedUnmappedNot yet
03Portable media securityUnmappedUnmappedUnmappedNot yet
04Mobile device security
Controls: IT-02
Not passingNot currentApprovedNot yet
05Wireless securityUnmappedUnmappedUnmappedNot yet
06Configuration management
Controls: CLOUD-02, IT-04, IT-05
PassingNot currentNot approved(29 d ago)
07Vulnerability management
Controls: CLOUD-05, IT-03, MON-04, MON-05, MON-06
Not passingNot currentNot approved(8 h ago)
08Network protection
Controls: CLOUD-03
PassingNot currentApprovedNot yet
09Transmission protection
Controls: CLOUD-01, DATA-03, DATA-06
Not passingNot currentNot approved(8 h ago)
10Password management
Controls: IAM-02, IAM-03, IAM-08
Not passingNot currentNot approved(8 h ago)
11Access control
Controls: IAM-04, IAM-05, IAM-06, IAM-07, IAM-09
Not passingNot currentNot approved(29 d ago)
12Audit logging and monitoring
Controls: MON-01, MON-02, MON-03
Not passingNot currentNot approved(3 mo ago)
13Education, training, and awareness
Controls: PEOPLE-06
Not passingCurrentApproved(8 h ago)
14Third-party assurance
Controls: VEND-01, VEND-02, VEND-03, VEND-04
Not passingNot currentNot approved(8 h ago)
15Incident management
Controls: BIZ-02, BIZ-03, BIZ-21
PassingNot currentNot approved(8 h ago)
16Business continuity and disaster recovery
Controls: BIZ-01, BIZ-20, DATA-12, DATA-15
PassingNot currentNot approved(29 d ago)
17Risk management
Controls: BIZ-04, BIZ-05, BIZ-09
PassingNot currentNot approved(4 mo ago)
18Physical and environmental security
Controls: PHYS-01
PassingNot currentNot approvedNot yet
19Data protection and privacy
Controls: DATA-01, DATA-02, DATA-04, DATA-05, LEGAL-01
PassingNot currentNot approvedNot yet