Join the discussion
Question 38/52
In an i1 assessment a Control Reference score of 62 would yield which result?
Correct Answer: B
In an i1 assessment, scoring follows a pass/fail logic tied to CAP requirements. If a Control Reference scores below the defined threshold (typically 83 for i1 assessments), any gaps within its requirement statements must be addressed with a required Corrective Action Plan (CAP). A score of 62 is below the threshold, meaning it cannot be accepted without remediation. This ensures organizations remediate key cybersecurity hygiene gaps, even in a moderate assurance assessment. Optional CAPs are not used in i1 assessments, as the assurance program emphasizes mandatory remediation for below-threshold controls. Certification cannot be granted with unresolved required CAPs. Therefore, the correct outcome for a score of 62 in an i1 Control Reference is a required CAP.
HITRUST CSF Assurance Program - "i1 Assessment Scoring Rules"; CCSFP Practitioner Guide - "CAP Requirements in i1 Assessments."
HITRUST CSF Assurance Program - "i1 Assessment Scoring Rules"; CCSFP Practitioner Guide - "CAP Requirements in i1 Assessments."
Add Comments
- Other Question (52q)
- Q1. On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at...
- Q2. Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to a...
- Q3. When partially inheriting a requirement statement score from an external cloud service pro...
- Q4. Which AI models can be evaluated using the A1 Security Assessment?...
- Q5. David, a member of an external assessor organization, helped his client remediate a contro...
- Q6. An organization has identified a number of components needed for an assessment. These comp...
- Q7. During HITRUST's QA phase of a Validated Assessment, HITRUST picks a sample of Control Obj...
- Q8. On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that sc...
- Q9. Which of the following is NOT one of the Technical risk factors?...
- Q10. What information is required to complete the documentation of a Corrective Action Plan (CA...
- Q11. Which of the following are appropriate types of inheritance within MyCSF? (Select all that...
- Q12. For an r2 assessment, what is the minimum number of days an organization should wait befor...
- Q13. When performing r2 assessments, any added compliance factors should be considered before m...
- Q14. What characteristics would allow grouping of multiple like components together?...
- Q15. HITRUST offers certifications for the following: (Select all that apply) [0017]...
- Q16. If a requirement statement beginning with "The Privacy Officer..." scored a 50 instead of ...
- Q17. Management has asked you to scope out an assessment including your entire network. What ar...
- Q18. An assessed entity is required to comply with six regulatory factors. Must the entity incl...
- Q19. When are HITRUST Assurance Advisories (HAA) posted? [0167]...
- Q20. When creating different scenarios for an assessment where the scope has yet to be fully de...
- Q21. During a HITRUST Assessment, what percentage of External Assessor hours must be performed ...
- Q22. A hospital system based in both Texas and Massachusetts processes credit card data within ...
- Q23. The HITRUST CSF is built upon the following model: [0134]...
- Q24. Should a company always select the most current version of the CSF framework? [0163]...
- Q25. Which of the following are true with e1, i1, and r2 assessment types? (Select all that app...
- Q26. Which assessment type allows users to select any HITRUST authoritative source?...
- Q27. Which version of the CSF supports a traversable requirement statement portfolio? [0107]...
- Q28. On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that sc...
- Q29. Organizations that process sensitive data face multiple challenges relating to information...
- Q30. Control Objectives are a statement of the desired result or purpose to be achieved by impl...
- Q31. The concept of HITRUST CSF risk levels was adapted from what security standard?...
- Q32. It is possible to test only privacy-related requirements to obtain a HITRUST privacy certi...
- Q33. What type of deficiency would be identified in the following Requirement Statement scoring...
- Q34. What type of scoping boundary includes the relevant IT platforms and supporting infrastruc...
- Q35. The HITRUST CSF is updated on an annual basis....
- Q36. Select the four general risk factor categories used when scoping r2 assessments....
- Q37. Where can you go to view a reporting dashboard for your organization?...
- Q38. In an i1 assessment a Control Reference score of 62 would yield which result?...
- Q39. The HITRUST CSF applies to covered information in all forms (words, numbers, pictures, sou...
- Q40. What can the Illustrative Procedures be used for? (Select all that apply)...
- Q41. An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor....
- Q42. When considering third-party reports for reliance, what must be included in the report? (S...
- Q43. The scoring of Requirement Statements is used to calculate the overall Domain score....
- Q44. On an r2 Validated Assessment any domain that scores less than a 61 will result in what ty...
- Q45. How many domains are there in an assessment?
- Q46. Upon submission of an assessment object by the assessor, how many days does HITRUST take t...
- Q47. Which of the following does HITRUST certify?
- Q48. Gaps with required CAPs must be remediated within six months....
- Q49. Why would an organization want to have multiple assessment objects? [0175]...
- Q50. Is the Payment Card Industry - Data Security Standard (PCI-DSS) a Risk Management Framewor...
- Q51. If the seven measurement criteria are not met, the strength rating for the Measured maturi...
- Q52. Which AI models can be evaluated using the A1 Security Assessment?...
