New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that score above 25% for Policy and Procedure, and over 0% for Implementation, Measured, and Managed.

A.

True

B.

False

What characteristics would allow grouping of multiple like components together?

A.

Systems with the same configurations

B.

Systems with the same patch levels

C.

Facilities with the same access management systems

D.

All of the above

What type of deficiency would be identified in the following Requirement Statement scoring scenario?

    Policy = 50%

    Process = 50%

    Implemented = 75%

    Measured = 0%

    Managed = 0%

A.

No deficiency

B.

Gap

C.

Required CAP

D.

Not enough information to determine

Halfway through an r2 assessment, management asks to add six implemented systems to the scope of primary components. What would the assessor need to do within MyCSF?

A.

Revert all Requirement Statements completed by the assessor so the client can consider control impact

B.

Update the "Scope of the Assessment" tab in the assessment object

C.

Remove all authoritative sources added to the assessment object

D.

Request a Bridge Certificate

An organization can have multiple assessment objects. [0090]

A.

True

B.

False

What are HITRUST Assurance Advisories designed to provide? (Select all that apply) [0051]

A.

Updates related to the HITRUST Assurance Program

B.

List of all new and updated authoritative sources associated with a framework version update

C.

End-of-Life progression for older framework versions

D.

Solicitations for assessor input

E.

All of the above

An r2 certification is good for how many years?

A.

Two years provided an interim assessment is performed, all CAPs have been remediated, and all N/As discharged

B.

Two years provided an interim assessment is performed and interim requirements are met

C.

Two years regardless

D.

Until there has been a significant change in the in-scope environment

When an assessor has completed reviewing and agreeing with Requirement Statement scoring, the assessor must save the results. This action will mark the Requirement Statement as "Assessor Review Complete". [0049]

A.

True

B.

False

Which assessment type tests against requirement statements considered essential to cybersecurity hygiene?

A.

e1 Assessment

B.

r2 Assessment

C.

Targeted Assessment

D.

i1 Assessment

E.

None of the above

Using only the information from the chart and question below, please answer the following question:

Domain

Control Reference

Requirement Statement

Numeric Score

01 Information Program

00.a.ISMP

The organization has...

72

01 Information Program

00.a.ISMP

The organization ensures...

74

01 Information Program

00.a.ISMP

A formal information...

81

02 Endpoint Protection

09.j Controls Against Malicious Code

Antivirus clients have...

62

02 Endpoint Protection

09.ab Monitoring System Use

Antivirus clients are...

79

05 Wireless Protection

09.ab Monitoring System Use

Networks are monitored...

84

19 Data Protection & Privacy

11.c Responsibilities and Procedures

The Privacy Officer...

42

19 Data Protection & Privacy

11.c Responsibilities and Procedures

A formal privacy program...

63

19 Data Protection & Privacy

02.d Management Responsibilities

Senior management...

68

19 Data Protection & Privacy

02.d Management Responsibilities

Requests for covered...

70

Assuming no Implementation score achieved 100% on any requirement statement and assuming all Control References are required for certification, this assessment will contain a required Corrective Action Plan (CAP)? [0193]

A.

True

B.

False