Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Control Reference scores are averaged to determine Domain scores.

A.

True

B.

False

David, a member of an external assessor org, helped his client remediate a control gap. As part of the validation process David can then review the remediation for appropriateness. [0141]

A.

True

B.

False

How large would the sample size be for a manual control with a population of 56 unique items?

A.

5

B.

8

C.

6

D.

25

E.

56

A control that is not documented cannot be measured. [0126]

A.

True

B.

False

The HITRUST CSF is built upon the following model: [0134]

A.

Control Objectives, Control References, COBIT Controls

B.

Functions, Categories, Sub-Categories

C.

Control Categories, COBIT controls, Implementation levels

D.

Control Categories, Control Objectives, Control References

The Subscribers Comments field should be populated with the rationale for any requirement statement marked not-applicable (N/A).

A.

True

B.

False

David, a member of an external assessor organization, helped his client remediate a control gap. As part of the validation process, David can then review the remediation for appropriateness.

A.

True

B.

False

Where can you go to view a reporting dashboard for your organization?

A.

Within the Illustrative Procedure

B.

Within the administration tab on the MyCSF portal's home page

C.

Dashboards are only provided within the certified CSF report

D.

Within the analytics tab on the MyCSF portal's home page

E.

Within the library tab on the MyCSF portal's home page

The Offline Assessment function allows assessors which capability?

A.

Download the entire CSF into an Excel spreadsheet

B.

Download an assessment's Requirement Statements into an Excel spreadsheet

C.

Upload the results from an assessor-developed spreadsheet directly into the MyCSF tool

D.

Submit their client's assessment to HITRUST QA outside of the MyCSF tool

An assessed entity is required to comply with six regulatory factors. Must the entity include all six regulatory factors in the scope of their assessment? [0088]

A.

Yes

B.

No