If you are assessing against elements of your organization that are managed by a Third Party entity AND this Third Party has previously completed a HITRUST CSF Validated Assessment, the responses to their Requirement Statements can be transferred to your Assessment in a few simple steps.

Step One: Marking the Requirement Statements that need to be Inherited

While Answering a Requirement Statement, there is a checkbox titled Request Inheritance beneath the Enter CAPs? field. By selecting this option, MyCSF will appropriately flag the Statement as one that will need to be assumed from an external Assessment. Continue marking all necessary Requirement Statements incorporated in the Questionnaire as needed.

Marking for Inheritance

Step Two: Creating and Sending an Inheritance Request

Back on the Assessment Homepage is a link labeled Inheritance Request that houses all relevant workflows for completing the Inheritance Process. First press the Inheritance Request URL followed by Add -> Inheritance Request on the subsequent screen.

Create Inheritance Request

Clicking the button will automatically pull you into the proper component to formulate the Request. Two attributes should be made visible to you. The first being the Object from which you would like to inherit from. Complete this field by clicking the magnifying glass icon and selecting your Vendor from the list.

Inheritance Request Fields

Once the first field is addressed, click the button contained within the field labeled Select the HITRUST CSF Requirements to inherit and all of your marked Requirements will populate on the resulting screen. Verify your prior selections by individually clicking the checkbox to the left of each record OR by clicking . Press the option to finish.

Selecting Marked Requirements

To finalize the request, you MUST click the button, which will send a notification to the Point of Contact for your Vendor. From this point, they will need to rule on the proposed Requirement Statements.

Step Three: Completing the Inheritance Request

Once the Third Party has deemed the relevant Requirement Statements for which they manage, including any comments, they will return the Request to you for final approval. You will be notified via an email notification of any such exchange when it occurs. Return to the location specified in the beginning of Step two above, and open the updated Request by either highlighting it and pressing Open OR by double-clicking the row.

Here you can review the Requirements that will be transferred from your Vendor’s Assessment to your own. To initiate the transfer, press the label near the top of the page.

Feedback

Was this helpful?

Yes No
You indicated this topic was not helpful to you ...
Could you please leave a comment telling us why? Thank you!
Thanks for your feedback.

Post your comment on this topic.

Please do not use this for support questions.
Need help? Contact us at HITRUST Support

Post Comment