Skip to content

Settings and activity

1 result found

  1. 14 votes

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)

    We’ll send you updates on this idea

    Planned  ·  4 comments  ·  The HITRUST CSF » Clarity  ·  Admin →
    How important is this to you?

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    An error occurred while saving the comment
    Keith Marceau commented  · 

    I think the numerals beside each element makes more sense because it is difficult to pick out what the elements are especially in Illustrative procedures like the one below. Putting a number out front still requires us to determine which {3} or which {6} that Hitrust considers to be elements.

    Examine policies and/or standards related to user roles and responsibilities and determine if the organization has developed, disseminated, and annually reviewed/updated a formal, documented personnel security policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance. Further, document procedures to facilitate the implementation of the personnel security policy and associated personnel security controls. Validate the existence of a written policy or standard.