βIn addition to assessing current vendors and getting them to agree to be HITRUST CSF Certified for security and compliance, we needed to evaluate new vendors, Our main focus initially was to make certification a requirement for entry into our vendor environment.β
"We showed the ISO auditor how our HITRUST risk assessment reports attested to our level of control implementations, We also produced a report that matches what the auditor was looking for in a risk register. We leveraged the HITRUST MyCSF as a risk management framework for achieving ISO certification by enabling him to see everything in one place. This shows how MyCSF serves as a tool that lets us easily switch between compliance certifications (such as HIPAA) and audit assessments (such as ISO).β