Join the discussion
Question 1/52
On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.
Correct Answer: B
CAP decisions are made at theControl Reference level, not both Requirement Statement and Control Reference levels. Individual requirement statements roll up into a control reference, and the control reference score determines whether a CAP is required. For instance, a low-scoring requirement may be present, but if the aggregated control reference score remains above the threshold, a CAP may not be required. Conversely, if the control reference score falls below the defined threshold, then a CAP is mandatory. This approach ensures consistency by focusing on control objectives as a whole rather than single requirements. Therefore, CAP decisions are not made independently at the requirement statement level, making the statementFalse.
References:HITRUST CSF Scoring Rubric - "Control Reference Scoring and CAP Triggers"; CCSFP Practitioner Guide - "CAPs at the Control Reference Level."
References:HITRUST CSF Scoring Rubric - "Control Reference Scoring and CAP Triggers"; CCSFP Practitioner Guide - "CAPs at the Control Reference Level."
Add Comments
- Other Question (52q)
- Q1. On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at...
- Q2. Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to a...
- Q3. When partially inheriting a requirement statement score from an external cloud service pro...
- Q4. Which AI models can be evaluated using the A1 Security Assessment?...
- Q5. David, a member of an external assessor organization, helped his client remediate a contro...
- Q6. An organization has identified a number of components needed for an assessment. These comp...
- Q7. During HITRUST's QA phase of a Validated Assessment, HITRUST picks a sample of Control Obj...
- Q8. On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that sc...
- Q9. Which of the following is NOT one of the Technical risk factors?...
- Q10. What information is required to complete the documentation of a Corrective Action Plan (CA...
- Q11. Which of the following are appropriate types of inheritance within MyCSF? (Select all that...
- Q12. For an r2 assessment, what is the minimum number of days an organization should wait befor...
- Q13. When performing r2 assessments, any added compliance factors should be considered before m...
- Q14. What characteristics would allow grouping of multiple like components together?...
- Q15. HITRUST offers certifications for the following: (Select all that apply) [0017]...
- Q16. If a requirement statement beginning with "The Privacy Officer..." scored a 50 instead of ...
- Q17. Management has asked you to scope out an assessment including your entire network. What ar...
- Q18. An assessed entity is required to comply with six regulatory factors. Must the entity incl...
- Q19. When are HITRUST Assurance Advisories (HAA) posted? [0167]...
- Q20. When creating different scenarios for an assessment where the scope has yet to be fully de...
- Q21. During a HITRUST Assessment, what percentage of External Assessor hours must be performed ...
- Q22. A hospital system based in both Texas and Massachusetts processes credit card data within ...
- Q23. The HITRUST CSF is built upon the following model: [0134]...
- Q24. Should a company always select the most current version of the CSF framework? [0163]...
- Q25. Which of the following are true with e1, i1, and r2 assessment types? (Select all that app...
- Q26. Which assessment type allows users to select any HITRUST authoritative source?...
- Q27. Which version of the CSF supports a traversable requirement statement portfolio? [0107]...
- Q28. On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that sc...
- Q29. Organizations that process sensitive data face multiple challenges relating to information...
- Q30. Control Objectives are a statement of the desired result or purpose to be achieved by impl...
- Q31. The concept of HITRUST CSF risk levels was adapted from what security standard?...
- Q32. It is possible to test only privacy-related requirements to obtain a HITRUST privacy certi...
- Q33. What type of deficiency would be identified in the following Requirement Statement scoring...
- Q34. What type of scoping boundary includes the relevant IT platforms and supporting infrastruc...
- Q35. The HITRUST CSF is updated on an annual basis....
- Q36. Select the four general risk factor categories used when scoping r2 assessments....
- Q37. Where can you go to view a reporting dashboard for your organization?...
- Q38. In an i1 assessment a Control Reference score of 62 would yield which result?...
- Q39. The HITRUST CSF applies to covered information in all forms (words, numbers, pictures, sou...
- Q40. What can the Illustrative Procedures be used for? (Select all that apply)...
- Q41. An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor....
- Q42. When considering third-party reports for reliance, what must be included in the report? (S...
- Q43. The scoring of Requirement Statements is used to calculate the overall Domain score....
- Q44. On an r2 Validated Assessment any domain that scores less than a 61 will result in what ty...
- Q45. How many domains are there in an assessment?
- Q46. Upon submission of an assessment object by the assessor, how many days does HITRUST take t...
- Q47. Which of the following does HITRUST certify?
- Q48. Gaps with required CAPs must be remediated within six months....
- Q49. Why would an organization want to have multiple assessment objects? [0175]...
- Q50. Is the Payment Card Industry - Data Security Standard (PCI-DSS) a Risk Management Framewor...
- Q51. If the seven measurement criteria are not met, the strength rating for the Measured maturi...
- Q52. Which AI models can be evaluated using the A1 Security Assessment?...
