HITRUST CCSFP - Certified CSF Practitioner 2025 Exam
For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.
Who defines the scope of an assessment?
When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".
On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.
Firewalls with identical configurations can be grouped for testing as one component.
When scoping an r2 assessment, selecting regulatory factors is required and may generate additional Requirement Statements in the assessment object.
For an r2 assessment, to obtain a Validated Report with Certification, each domain must score at least a 71 or higher.
After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.
When testing, can you sample across a population of ungrouped primary components within an assessment's scope?
Which AI models can be evaluated using the A1 Security Assessment?
