<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HITRUST in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19585#M919</link>
    <description>&lt;P&gt;While HITRUST is copyrighted, anyone can download the CSF.&amp;nbsp; There are just certain restrictions on its use.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2019 21:45:24 GMT</pubDate>
    <dc:creator>emb021</dc:creator>
    <dc:date>2019-02-28T21:45:24Z</dc:date>
    <item>
      <title>HITRUST</title>
      <link>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19530#M915</link>
      <description>&lt;P&gt;What do people know about HITRUST.&amp;nbsp; I am interested as I have been selected out of a cast of one to do the work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After a complete list requirements, domains, controls, checks, and evidence requirements if anyone can help????&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:07:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19530#M915</guid>
      <dc:creator>skyflier21</dc:creator>
      <dc:date>2023-10-09T09:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: HITRUST</title>
      <link>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19534#M916</link>
      <description>&lt;P&gt;Its kind of a "kitchen sink" mode of IT Controls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its aim is at the healthcare industry, as a means to meet HIPAA compliance.&amp;nbsp; They basically started off with ISO/IEC 27002 controls (pretty clear if you compare the two control sets), and then started to dump on top of that almost every other possible control set.&amp;nbsp; In fact, if you take a look at the change list in the HITRUST document, you'll see all the standards and regulations they've dumped into it (PCI, GDPR, NY-DFS, etc etc).&amp;nbsp; You almost have to wonder if they're training to create the "one ring" of IT control sets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a bit daunting, as depending on the size of the organization, more controls are expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I also find a little confusing is they have their MyCSF tool that isn't quite the same as the HITRUST CSF.&amp;nbsp; Don't understand why.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point, my experience is that most of the companies that are pursing HITRUST certification are those that are forced to by their clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I won't claim to be a HITRUST expert, but I've helped several clients get prepared for HITRUST certification, but can't do the certification work.&amp;nbsp; That can only be don't by people certified by HITRUST (similar to PCI assessments).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 20:31:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19534#M916</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-02-27T20:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: HITRUST</title>
      <link>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19558#M918</link>
      <description>&lt;P&gt;I have implemented and used the framework and used to be a certified in&amp;nbsp;HITRUST.&amp;nbsp; (I let it lapse as the certification only holds value if you are at a company that does HITRUST audits.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HITRUST is a proprietary framework that is copyrighted.&amp;nbsp; However, you can get a list of the controls as they map to AICPA's SOC framework from the AICPA website.&amp;nbsp; That might be a good place to start if you are looking for something that is no cost.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 14:34:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19558#M918</guid>
      <dc:creator>TankerT</dc:creator>
      <dc:date>2019-02-28T14:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: HITRUST</title>
      <link>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19585#M919</link>
      <description>&lt;P&gt;While HITRUST is copyrighted, anyone can download the CSF.&amp;nbsp; There are just certain restrictions on its use.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 21:45:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/HITRUST/m-p/19585#M919</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-02-28T21:45:24Z</dc:date>
    </item>
  </channel>
</rss>

