Hitrust Participation Agreement

• To get a sub­scrip­tion to MyCSF, fill out the form under hitrustalliance.net/mycsf/ or call HITRUST at 855–448-7878 The project coor­di­na­tor is an inter­nal per­son appoint­ed by the orga­ni­za­tion who fol­lows a HITRUST assess­ment. The role of the project coor­di­na­tor is to guide the work team in achiev­ing the objec­tives and expec­ta­tions set for the […]

• To get a sub­scrip­tion to MyCSF, fill out the form under hitrustalliance.net/mycsf/ or call HITRUST at 855–448-7878 The project coor­di­na­tor is an inter­nal per­son appoint­ed by the orga­ni­za­tion who fol­lows a HITRUST assess­ment. The role of the project coor­di­na­tor is to guide the work team in achiev­ing the objec­tives and expec­ta­tions set for the eval­u­a­tion. He or she is respon­si­ble for col­lect­ing doc­u­ments, orga­niz­ing inter­views and ver­i­fy­ing par­tic­i­pa­tion. 2. Learn more about the HITRUST process and details of using MyCSF, check out the videos avail­able on the HITRUST web­site (see hitrustalliance.net/mycsf/training-videos/ and hitrustalliance.net/mycsfvideos/) and/or view videos and doc­u­ments relat­ed to the MyCSF tool. “The com­plete set of mea­sures and pro­ce­dures used by the orga­ni­za­tion to ensure that the ser­vices pro­vid­ed con­tin­ue to meet the customer‘s expec­ta­tions, as out­lined in the rel­e­vant agree­ments.” • To learn more about the MyCSF tool, see the 18-minute video under hitrustalliance.net/mycsf/. This video is returned in the steps below. “The pro­grams and sys­tems used for the use of the HITRUST CSF and CSF tools, asso­ci­at­ed with data pro­tec­tion assess­ments accord­ing to the stan­dards estab­lished by HITRUST.” The HITRUST CSF takes into account 46 con­trol objec­tives. Each is a state­ment of the objec­tive or objec­tive to be achieved with regard to the checks car­ried out with­in a CSF HITRUST con­trol cat­e­go­ry. There are three lev­els of HITRUST imple­men­ta­tion that describe the risk asso­ci­at­ed with each con­trol element.

The high­er the risk, the greater the resis­tance to con­trol used. Orga­ni­za­tions wish­ing to obtain HITRUST cer­ti­fi­ca­tion must com­plete at least the first step. Among the imple­men­ta­tion steps are: Note: The min­i­mum sub­scrip­tion to acquire is the Pro­fes­sion­al license. “The secu­ri­ty or counter-mea­sure required for an orga­ni­za­tion and/or infor­ma­tion sys­tem to pro­tect the con­fi­den­tial­i­ty, integri­ty and avail­abil­i­ty of infor­ma­tion.” At first, the com­pli­ance process can be over­whelm­ing. How­ev­er, the HITRUST Com­mon Secu­ri­ty Frame­work (CSF) has been specif­i­cal­ly designed to opti­mise com­pli­ance with com­pa­ny leg­is­la­tion. The hitrust CSF matu­ri­ty mod­el, which rep­re­sents an evo­lu­tion of the PRISMA mod­el, is used to eval­u­ate prepa­ra­tion assess­ments and val­i­dat­ed assess­ments. The score is deter­mined accord­ing to the five basic lev­els: pol­i­cy, process/process, imple­ment­ed, mea­sured and man­aged. A risk-based approach, based on orga­ni­za­tion­al, reg­u­la­to­ry and sys­tem pro­file infor­ma­tion, is used to deter­mine the cus­tomized set of require­ment instruc­tions applic­a­ble to the orga­ni­za­tion to be assessed. In total, there are 845 proofs of require­ment. In part, the process of iden­ti­fy­ing the require­ments applic­a­ble to the orga­ni­za­tion seek­ing cer­ti­fi­ca­tion helps deter­mine the extent of HITRUST‘s com­mit­ment to the FSB. By par­tic­i­pat­ing in this pro­gram, com­pa­nies will have access to com­pli­ance assess­ments and report­ing tools for HIPAA, HITECH, fed­er­al, state, and indus­try requirements.

In par­tic­u­lar, HITRUST sup­ports CSF organ­i­sa­tions and their busi­ness part­ners with a con­sis­tent approach to man­ag­ing secu­ri­ty assess­ments. The CSF HITRUST insur­ance pro­gram includes risk man­age­ment over­sight and assess­ment pro­to­col, tai­lored to indi­vid­ual reg­u­la­to­ry and busi­ness require­ments of dif­fer­ent indus­tries. “The infor­ma­tion pro­tec­tion risk man­age­ment pro­gram and process­es for the orga­ni­za­tion (includ­ing mis­sion, func­tions, image and rep­u­ta­tion), include orga­ni­za­tion­al assets, indi­vid­u­als and oth­er orga­ni­za­tions: at the end of the HITRUST assess­ment, the orga­ni­za­tion receives a report on the results of the eval­u­a­tion dur­ing the qual­i­ty assur­ance phase. The report also con­tains cor­rec­tive actions that should be fol­lowed in cor­rec­tive action plans (CAP). Hitrust cer­ti­fi­ca­tion con­firms that the com­pa­ny has passed the com­pre­hen­sive secu­ri­ty assess­ment and main­tains com­pli­ance with the rel­e­vant rules on data loss pre­ven­tion and infor­ma­tion risk management..… 

INGEN KOMMENTARER

Kommentarfeltet til denne artikkelen er nå stengt. Ta kontakt med redaksjonen dersom du har synspunkter på artikkelen.

til toppen