simpl.
Cybersecurity GRC 17 items

HITRUST CSF Readiness Assessment

Assesses readiness for a HITRUST CSF validated assessment, covering scoping, the PRISMA maturity model, control implementation, and corrective action planning.

HITRUST CSFHIPAANIST 800-53

Free PDF · enter your email to download.

Scoping & Preparation

  • Is the assessment scope (systems, facilities, data flows) documented? *
  • Is the assessment type selected (e1, i1, or r2) based on risk and requirements? *
  • Have applicable regulatory factors (HIPAA, state law) been applied to tailor requirements? *
  • Is an internal readiness or gap assessment completed before the validated assessment?

Control Maturity (PRISMA)

  • Are policies documented for each in-scope control requirement? *
  • Are procedures documented that implement each policy? *
  • Is each control implemented and operating in practice? *
  • Are controls measured for effectiveness?
  • Are controls managed with continuous improvement?

Domain Coverage

  • Are information protection program and risk management controls in place? *
  • Are access control and endpoint protection requirements met? *
  • Are third-party assurance and configuration management controls implemented? *
  • Are incident management and business continuity controls implemented? *

Evidence & Corrective Action

  • Is evidence collected and organized per requirement for the assessor? *
  • Are gaps documented with corrective action plans (CAPs) and target dates? *
  • Is an owner assigned to remediate each identified gap? *
  • Is the MyCSF (or equivalent) workspace maintained and current?

Download the full HITRUST CSF Readiness Assessment checklist

Get it as a clean, printable PDF — free.