339 results found
- 
Fine-Grain Assessment Object ReversionI suggest implementing fine-grain assessment object reversion when subscriber changes (e.g., to requirement scores, NA statements, CAPs, and external inheritance requests) are needed post-submission. Under the current system, it seems that such changes require reversion of the entire object, which then calls for revalidating all requirements (rather than just the updated ones). Fine-grain reversion would support greater assessment efficiency, less rework, and less frustration for subscribers. Also, MyCSF would more accurately reflect workflow status, without resetting the status of previously completed phases/tasks. 1 vote
- 
Requirement Sorting Within MyCSFdomains, this sort order (whether ascending or descending) makes it easier to quickly find specific requirements. This is especially true when working between MyCSF and an assessment test plan (typically during scoring, commenting, and evidence mapping), because test plans tend to feature this sort order also. 2 votes
- 
Quarterly MyCSF Release NotesI suggest that HITRUST publishes a quarterly release note digest to summarize changes for users. Under the Release Notes section of MyCSF Help, no new notes have been published since June 2021; yet, MyCSF has changed dramatically (especially regarding workflow and status management) since this time. The digests can be published under the Release Notes section, or (even better) emailed to registered MyCSF users. 1 vote
- 
change sort order of presets to align with assurance levelschange the left to right sort order of assessment presets to align with assurance provided....r2 should be left, i1 center, e1 right. 1 vote
- 
Fix Exports so that formatting, particularly numbering, are included in the exportIn V11, when exporting controls the language removes all formatting and numbering, making it difficult to trace back actions to the sub-requirements. Given the importance of the list breakdown this should be included ASAP. If the formatting is a challenge due to Excel/CSV, the numbering should still be included. 1 vote
- 
Bulk export and archive of an objectAt times our organization has reached our object capacity. We would like to export all of our entire object and reports, but it is currently a manually intensive process. For peace of mind, we want to export everything from a previous object, then archive or delete it. Current the process is manual with reports having to be downloaded one at a time. A bulk download and export feature would be so nice. 3 votes
- 
Evaluative Elements ReportCreate a report that shows a list of the Evaluative Elements for each requirement statement similar to the Illustrative Procedures report - this will help both assessors and assessed entities with ensuring that they are meeting the EEs when working in offline testing workbooks without clicking into each requirement statement within MyCSF. 15 votes
- 
Deminar screenshots visibilityThe screenshots in deminar are not visible 0 votes
- 
New Environment testAzure test 1 vote
- 
Include dates when files are uploadedIt would be nice to see if we could have dates of when files are uploaded. It can be very confusing when evidence is similar and there is no reference date of when it got uploaded. 1 vote
- 
Map CSF to COSO PrinciplesMap CSF controls to COSO Principles in the HITRUST CSF Authoritative Sources Cross Reference 1 vote
- 
Have Salesforce publish an SRMIt appears that Salesforce does not have an SRM available. As a widely used product it may benefit many subscribers if they published an SRM for use. 2 votes
- 
HITRUST Assessment Markup LanguageThis would allow an assessed entity or assessor to highlight and mark test in documents and automatically create a link to the control requirement statement from which it was accessed and allow them to select the maturity domain that the highlighted text supports. This could also be granular enough to allow it to tie to requirement criteria as defined in illustrative procedures and listed in MyCSF. 1 vote
- 
collaborationVery confusing whether multiple people can work in an assessment at one time or not. Sometimes save works, sometimes it doesn't and reverts to previous states. Make it clear how it works with clear UX like in google docs. 2 votes
- 
Include the HITRUST requirement ID in the ReportsPlease re-configure the Reports under Analytics to ensure that Requirement ID is part of the data pull. We manage this work at a requirement level and currently, every report that we run we have to do a cross-reference to pull in the requirement ID. 26 votes
- 
Update "Change / Cancellation Policy" section on the Reservation tabCan you update the "Change / Cancellation Policy" section on the Reservation tab to include the requirement that your submission date cannot be less than 2 weeks before the QA block selected. This requirement is not written out anywhere online but is enforced. 2 votes
- 
Make it easier to recall or reverse and assessmentIt is difficult to reverse an assessment if a domain has been submitted. I am proposing making it easier for a submitter to reverse an assessment if it was submitted in error. Or add functionality so that organizational information can be updated even if a domain has been submitted for an external assessor review. 1 vote
- 
Allow submission of assessments prior to renewal date without changing annual renewal dateCurrently, if we want to maintain our annual reassessment date, we need to submit our assessment on that specific date (i.e., we cannot submit an assessment earlier if it is ready). We should be able to submit at any point and mark the date of the submission, or simply keep the annual assessment date unless a different date is requested. 10 votes
- 
Allow select-all for Facilities in Platforms/Systems tableWhen selecting the facilities where a platform/system is running, have the option to select all facilities rather than needing to go one-by-one. 2 votes
- 
Applications & Databases are mandatory fields in the Platforms/Systems table, mark them as such when the table is being filled out.When completing the Platforms/Systems table, some fields are marked mandatory. The Applications & Databases fields are not. However, HITRUST QA requires something to be included here. Please mark these fields as mandatory up front to minimize these QA tasks/findings. 2 votes
- Don't see your idea?
