New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

If the client and the External Assessor disagree on assessment scope, HITRUST will determine the final scope. [0027]

A.

True

B.

False

A pharmacy that accepts Medicare/Medicaid and also takes credit cards should include which regulatory factors in their assessment?

A.

FISMA

B.

FTC Red Flags Rule

C.

PCI-DSS

D.

FedRAMP

E.

CMS (Centers for Medicare and Medicaid Services) Minimum Security Requirements (High)

Which of the following does HITRUST certify?

A.

Products

B.

People

C.

Implemented Systems

D.

Facilities

E.

All of the above

On an r2 Validated Assessment any domain that scores less than a 61 will result in what type of report? [0142]

A.

Validated Report with Certification

B.

Readiness Assessment Report

C.

Validated Report without Certification

D.

Accepted Report

Which assessment type allows users to select any HITRUST authoritative source?

A.

Readiness Assessment

B.

Validated Assessment

C.

r2 Assessment

D.

e1 Assessment

E.

None of the above

HITRUST offers certifications for the following: (Select all that apply) [0017]

A.

NIST 800-53

B.

ISO 27001

C.

HITRUST CSF

D.

PCI-DSS

E.

NIST Cybersecurity Framework

If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".

A.

True

B.

False

Is additional work required by the assessor to generate the NIST Cybersecurity Framework Report?

A.

Yes

B.

No

Can certification be achieved when scoring 100% on the following maturity levels within an r2 Assessment Object?

    Policy: 100%

    Procedure: 100%

    Implementation: 100%

    Measured: 0%

    Managed: 0%

A.

Yes

B.

No

It is possible to test only privacy-related requirements to obtain a HITRUST privacy certification.

A.

True

B.

False