Healthcare

HITRUST Common Security Framework

A certifiable framework that provides a comprehensive, prescriptive, and scalable security and privacy controls framework. Commonly adopted in healthcare and increasingly in other regulated industries.

12Categories
143Controls
Readiness

Control Categories

Information Protection Program

18 controls

Program governance, risk management, and information protection policies.

Not started

Endpoint Protection

12 controls

Malware protection, mobile device security, and removable media controls.

Not started

Portable Media Security

6 controls

Encryption, tracking, and disposal of portable storage and devices.

Not started

Access Control

22 controls

User registration, privilege management, password policies, and session controls.

Not started

Audit Logging and Monitoring

10 controls

Event logging, monitoring, clock synchronization, and log protection.

Not started

Network Protection

14 controls

Network segmentation, firewall management, and intrusion detection.

Not started

Transmission Protection

8 controls

Encryption of data in transit, secure messaging, and remote access.

Not started

Vulnerability Management

10 controls

Vulnerability scanning, patch management, and penetration testing.

Not started

Configuration Management

9 controls

Baseline configurations, change control, and system hardening.

Not started

Business Continuity

11 controls

BCP/DR planning, backup and recovery, and crisis communication.

Not started

Privacy Practices

15 controls

Notice, consent, data minimization, retention, and individual rights.

Not started

Third-Party Assurance

8 controls

Vendor risk assessment, contracts, and ongoing monitoring.

Not started