What are examples of “significant changes” that might preclude performance of a HITRUST CSF Bridge Assessment?
HITRUST will evaluate changes on a case-by-case basis and is available to engage with assessed entities to discuss specifics. Examples of activities that might be considered significant changes include:
- Moving from an on-premise data center into a public cloud environment,
- Moving the organization’s physical headquarters,
- Decommissioning a data center and moving all assets to a different data center,
- Replacing in-scope platforms (e.g., moving from SAP to Oracle EBS),
- Changing an in-scope system so it uses a NoSQL backend instead of a relational database,
- Moving away from an outsourced IT model by standing up an internal IT function,
- Decommissioning the helpdesk ticketing system, and/or
- New functionality in an in-scope platform enabling it to be accessed from a public location.
Thanks for your feedback.