If you are assessing against elements of your organization that are managed by a Third Party entity AND this Third Party has previously completed a HITRUST CSF Validated Assessment, the responses to their Requirement Statements can be transferred to your Assessment in a few simple steps.
Step One: Marking the Requirement Statements that need to be Inherited
While Answering a Requirement Statement, there is a checkbox titled Request Inheritance beneath the Enter CAPs? field. By selecting this option, MyCSF will appropriately flag the Statement as one that will need to be assumed from an external Assessment. Continue marking all necessary Requirement Statements incorporated in the Questionnaire as needed.
Step Two: Creating and Sending an Inheritance Request
Back on the Assessment Homepage is a link labeled Inheritance Request that houses all relevant workflows for completing the Inheritance Process. First press the Inheritance Request URL followed by Add -> Inheritance Request on the subsequent screen.
Clicking the button will automatically pull you into the proper component to formulate the Request. Two attributes should be made visible to you. The first being the Object from which you would like to inherit from. Complete this field by clicking the magnifying glass icon and selecting your Vendor from the list.
Once the first field is addressed, click the button contained within the field labeled Select the HITRUST CSF Requirements to inherit and all of your marked Requirements will populate on the resulting screen. Verify your prior selections by individually clicking the checkbox to the left of each record OR by clicking . Press the option to finish.
To finalize the request, you MUST click the button, which will send a notification to the Point of Contact for your Vendor. From this point, they will need to rule on the proposed Requirement Statements.
Step Three: Completing the Inheritance Request
Once the Third Party has deemed the relevant Requirement Statements for which they manage, including any comments, they will return the Request to you for final approval. You will be notified via an email notification of any such exchange when it occurs. Return to the location specified in the beginning of Step two above, and open the updated Request by either highlighting it and pressing Open OR by double-clicking the row.