Cybersecurity GRC 17 items
HITRUST CSF Readiness Assessment
Assesses readiness for a HITRUST CSF validated assessment, covering scoping, the PRISMA maturity model, control implementation, and corrective action planning.
HITRUST CSFHIPAANIST 800-53
Free PDF · enter your email to download.
Scoping & Preparation
- Is the assessment scope (systems, facilities, data flows) documented? *
- Is the assessment type selected (e1, i1, or r2) based on risk and requirements? *
- Have applicable regulatory factors (HIPAA, state law) been applied to tailor requirements? *
- Is an internal readiness or gap assessment completed before the validated assessment?
Control Maturity (PRISMA)
- Are policies documented for each in-scope control requirement? *
- Are procedures documented that implement each policy? *
- Is each control implemented and operating in practice? *
- Are controls measured for effectiveness?
- Are controls managed with continuous improvement?
Domain Coverage
- Are information protection program and risk management controls in place? *
- Are access control and endpoint protection requirements met? *
- Are third-party assurance and configuration management controls implemented? *
- Are incident management and business continuity controls implemented? *
Evidence & Corrective Action
- Is evidence collected and organized per requirement for the assessor? *
- Are gaps documented with corrective action plans (CAPs) and target dates? *
- Is an owner assigned to remediate each identified gap? *
- Is the MyCSF (or equivalent) workspace maintained and current?
Download the full HITRUST CSF Readiness Assessment checklist
Get it as a clean, printable PDF — free.
