Search
Related topics are listed below.
Pre-Assessment
Pre-Assessment
Topics in Pre-Assessment include: Creating a New Assessment and Scoping an Assessment. Organization Information Subtopics Creating a New Assessment Scoping an Assessment
Assessment Name
Pre-Assessment » Creating a New Assessment » Name & Security » Assessment Name
On the Name & Security page, there is a text input reserved for the name of the Assessment. The name will help you identify it easily from any other assessment you may have. For example: “2019 ABC Company Validated Assessment”, “2019 ABC Company…
Assessment Questionnaire
Assessment Questionnaire
After completing the Scope of your Assessment, you can begin answering the questions that have been generated based on your scope. Topics range from: Completing an Assessment, Marking Not-Applicable, Assigning a User, CAP Management, Authoritative Sources, Assessment…
Assessment Options
Pre-Assessment » Scoping an Assessment » Assessment Options
Answer the dropdowns provided to determine what kind of assessment will be generated by MyCSF. This includes Targeted, CSF Security, CSF Security & Privacy, CSF Comprehensive Security, and CSF Comprehensive Security & Privacy Assessments. The level of validation will…
Assessment Report
Analytics » Reports » External Reports » Assessment Report
Contains the responses of the HITRUST CSF Assessment categorizes by the nineteen domains. This is separate from the purchasable Self-Assessment report. Assessment Report After authenticating through the ‘MyCSF Portal’, click on ‘Analytics’ in the…
Scoping an Assessment
Pre-Assessment » Scoping an Assessment
The scope of the Assessment is the information about your organization that will be used to narrow down the most precise assessment for your compliance and security needs. Fields marked with red asterisks are mandatory. After authenticating through the HITRUST…
Deleting an Assessment
Pre-Assessment » Creating a New Assessment » Name & Security » Deleting an Assessment
Deleting an Assessment will be permanently removed from MyCSF. Only Account Admins and Assessment Leads have the privilege to delete an Assessment. The status of the Assessment must be ‘Not Started’ or ‘Answering Assessment’, as well as not submitted to the…
Completing an Assessment
Assessment Questionnaire » Completing an Assessment
There are many components to completing an assessment. This includes: Answering an Assessment Statement, Assigning Respondents, Related Authoritative Sources, Risk Factors, History Statement Log, Illustrative Procedures, Adding a Document, and CAP Management. …
Submitting an Assessment
Assessment Questionnaire » Submitting an Assessment
Whether submitting a Self-Assessment or a Validated Assessment by your assessor organization, the Assessment Questionnaire can be submitted either by each fully completed domain (Validated only) or by completing the entire Assessment (Self-Assessment/Validated…
Selecting Your Assessment
Homepage » Selecting Your Assessment
After setting your Organization an Assessment table will appear with all of the Assessments within your account. Atop the ‘Assessments’ table, is a donut chart displaying a consolidation of the statuses of your Assessments. Click on portions of the donut chart to…
Controlling Assessment Roles
Administration » People Management » Controlling Assessment Roles
Follow the instructions below to manage a user’s Assessment Privileges. From the Homepage, click the ‘Administration’ button at the at the top Menu bar or below your Subscription Information. Click on the name of the Assessment you wish to update. From the…
Cloning an Assessment
Pre-Assessment » Creating a New Assessment » Name & Security » Cloning an Assessment
Cloning an Assessment gives you the ability to transfer all maturity scores, comments, and documents from an existing Assessment into a newly created one. If you wish to complete a new Assessment with existing data from a previous Assessment, follow the instructions…
Viewing an Assessment
Pre-Assessment » Creating a New Assessment » Viewing an Assessment
From the Hompage of MyCSF, you can view any Assessment that has been generated. To view an Assessment, please follow the steps below to access and view an Assessment within your MyCSF Account. From the Homepage, there is an ‘Assessments’ table that includes…
Creating a New Assessment
Pre-Assessment » Creating a New Assessment
If you are an Account Administrator, you’ll be able to simply add a new Assessment directly through the homepage of MyCSF. From the MyCSF Homepage, click the ‘+ Create Assessment’ button on the ‘Assessments’ table found under the Organization panel. You…
Viewing an Assessment Domain
Assessment Questionnaire » Completing an Assessment » Viewing an Assessment Domain
To view the Assessment Statements you have generated in the Scope of your Assessment click on the Clipboard in the left Nav bar so you may be able to view your Assessment Questionnaire. Choose one of your nineteen domains to begin answering one of your Assessment…
Answering an Assessment Statement
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement
There are many components to completing an assessment. This includes: Answering a Statement, Assigning a Respondent, Related Authoritative Sources, Risk Factors, History Assessment Log, Illustrative Procedures, Adding Documents, and CAP Management. r2 Assessment: …
Assessment Domain Status Filters
Assessment Questionnaire » Completing an Assessment » Viewing an Assessment Domain » Assessment Domain Status Filters
On your Table of Assessment Domains, you will be able to filter each domain within your assessment by its respective status. A corresponding count and color will appear within a badge icon for each status currently found in a domain. Here is a list of all possible…
Inheriting an Assessment Statement
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Inheriting an Assessment Statement
See Inheriting an Assessment Statement
Offline Assessment – Inheritance
Assessment Questionnaire » Completing an Assessment » Offline Assessment – Inheritance
The Offline Assessment feature may be used to populate inheritance requests. For more information refer to the following link: How to Request Inheritance using the Offline Assessment Template
Creating an Offline Assessment
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment
An Offline Assessment gives you the ability to complete an Assessment outside of MyCSF using a spreadsheet and seamlessly import it back into the application. If you have a MyCSF Subscription and wish to complete your Assessment offline, follow the instructions below…
Interim Assessment (r2 only)
Interim Assessment (r2 only)
If you are coming up on your 1-year Anniversary of your CSF Certification, you will need to perform an Interim Assessment. The Interim Assessment is to ensure that the scope of your CSF Certification is still valid. If you have a MyCSF Subscription, click here for…
Re-validating the Assessment
Interim Assessment (r2 only) » Recreating a Validated Assessment Object » Re-validating the Assessment
As you would in any Validated Assessment, you as the Assessor will need to validate all of the Assessment Questions completed by your Client. You will have to ensure the maturity scores entered are identical to their Original CSF Certification. From the Homepage,…
View the Assessment Statement Log
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Assessment Statement Log
Keep track of the users who have answered an Assessment Statement by accessing the Assessment Statement Log. MyCSF archives who modified a statement and when they did it. From the Assessment Domain, click on the Assessment Statement you wish to view the…
Creating a Custom Assessment Library
Homepage » Creating a Custom Assessment Library
Account Administrators are able to create and manage a Custom Assessment using the HITRUST CSF and its Authoritative Sources using HITRUST provided questions. Please follow the steps below on how to create a customized Assessment Library. From the MyCSF Homepage,…
Manually Generating an Interim Assessment
Interim Assessment (r2 only) » Manually Generating an Interim Assessment
If you are coming up on your 1-year Anniversary of your CSF Certification and have a MyCSF Subscription, please note that your Interim Assessment will auto-generate 90 days prior to the Anniversary of the Certification Date of your Original Assessment. If you wish to…
Recreating a Validated Assessment Object
Interim Assessment (r2 only) » Recreating a Validated Assessment Object
Once an Interim Assessment has been provisioned, please note that you will have to answer all the Pre-Assessment and Assessment Questionnaire identical to your CSF Certification. *If you still have access to the Original Certified Assessment Object, you do not need to…
Performing an Interim Review Assessment
Interim Assessment (r2 only) » Performing an Interim Review Assessment
If you are coming up on your 1-year Anniversary of your CSF Certification, you will need to perform an Interim Assessment. The Interim Assessment is to ensure that the scope of your CSF Certification is still valid. From the Homepage, click on the Assessment with…
Setting Assessment Statements as Not Applicable
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Setting Assessment Statements as Not Applicable
Assessment Statements may need to be marked as Not Applicable (N/A). If there are Assessment Statements that you feel you do not need to comply, check the N/A box within a statement. *You will be required to provide rationale in the comments. From the…
How to Publish (Enable) Assessment Inheritability
Inheritance » External Inheritance » Inheritance Providers » How to Publish (Enable) Assessment Inheritability
From the ‘Name & Security’ pre-assessment page, check the box next to “Published” and click Confirm when prompted to agree to the Inheritance User Terms and Conditions. A published assessment will show a banner icon with a hover-over tooltip next the…
How to Unpublish (Disable) Assessment Inheritability
Inheritance » External Inheritance » Inheritance Providers » How to Unpublish (Disable) Assessment Inheritability
From the ‘Name & Security’ pre-assessment page, uncheck the box next to “Published” and click Confirm when prompted. *Note: The system will automatically unpublish an assessment on its date of expiration—for the r2 Certification: the 2-year…
Enabling Internal Assessors On Your Assessment
Internal Assessors » Enabling Internal Assessors On Your Assessment
After your Internal Assessor application has been approved, the Name and Security page on your Organization’s Assessment will be altered to include a checkbox allowing you to mark your Assessment as having been tested by Internal Assessors. When selected, you will be…
Assigning Internal Assessors to an Assessment
Internal Assessors » Assigning Internal Assessors to an Assessment
If an Internal Assessor Function has been chosen for an Assessment (Link to Enabling Internal Assessors On Your Assessment), the Subscriber People table will be augmented to include a new column that is reserved for Internal Assessors. Those that have been delegated…
Assessment with HITRUST CSF Implementation Report
Analytics » Reports » External Reports » Assessment with HITRUST CSF Implementation Report
Contains the responses of the HITRUST CSF Assessment categorized by the nineteen domains. This is separate from the purchasable Self-Assessment report. Assessment with HITRUST CSF Implementation Report After authenticating through the ‘MyCSF Portal’,…
How To View Internally-Inherited Assessment Scores
Inheritance » Internal Inheritance » How To View Internally-Inherited Assessment Scores
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal. 2. Within the Inheritance Modal, click on the ‘Scoring’ tab. The first line shows the internal assessment from which…
How To View Externally-Inherited Assessment Scores
Inheritance » External Inheritance » Inheritance Requestors » How To View Externally-Inherited Assessment Scores
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal. 2. Within the Inheritance Modal, click on the ‘Scoring’ tab. The first line shows the external assessment from which…
Corrective Action Plans (CAPs) in Your Assessment
Assessment Questionnaire » Corrective Action Plans (CAPs) in Your Assessment
Because CAPs can be linked to Statements within an Assessment, you may be interested in which CAPs have been associated collectively to an Assessment. This can be done by simply going to the Assessment (link to viewing an assessment) for which you wish to see the…
Answering CAPs & Generating an Interim Assessment
Interim Assessment (r2 only) » Recreating a Validated Assessment Object » Answering CAPs & Generating an Interim Assessment
If you had CAPs identified within your Original CSF Certification, you will have to add the same corrective action plan identical to your Original CSF Certification. If you do not have any mandatory Corrective Action Plans, you can immediately generate the Interim…
Adding a User to an Assessment Domain
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a User to an Assessment Domain
Assigning a User to an Assessment Domain is a beneficial tool to better manage resources and aggregate a collection of responses. From the Assessment Questionnaire, click on the Assessment Domain you wish to assign. From the Assessment Domain, click on the…
How To Request Inheritance Using the Offline Assessment Template
Inheritance » External Inheritance » Inheritance Requestors » How To Request Inheritance Using the Offline Assessment Template
To create inheritance requests using the offline assessment, first generate the offline assessment worksheet using the process outlined in the Creating an Offline Assessment section of the User Guide. Locate and click the “Inheritance” tab in the Offline…
Creating and Importing Assessor Evaluation for an Offline Assessment
Assessment Questionnaire » Completing an Assessment » Creating and Importing Assessor Evaluation for an Offline Assessment
When a Validated Assessment has been submitted to an Assessor, you the Assessor has the ability to fill-out your evaluation outside of MyCSF using a spreadsheet and seamlessly import your evaluation back into the application. Follow the instructions below on Creating…
Inheritance
Inheritance
Inheritance is a feature within MyCSF that allows maturity level scores associated with specific requirements to be transferred, or “inherited”, from previously scored assessment objects. Maturity scores that originated from an “inheritable” assessment…
External Inheritance
Inheritance » External Inheritance
External Inheritance allows users to “inherit” assessment results that are shared by the same or different organizational entity. Access and use of external inheritance is subject to the following requirements and available functionality: The owner of the…
How To Use the Kanban View To Track Inheritance Requests
Inheritance » External Inheritance » Inheritance Requestors » How To Use the Kanban View To Track Inheritance Requests
The Kanban reporting view can be used to confirm the submitted inheritance requests. Find the Kanban board by: 1. Clicking the Views option in MyCSF and selecting the Kanban View. 2. Then filter for the assessment object name. Hovering over the assessment tile…
View the Illustrative Procedures
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Illustrative Procedures
r2 Assessment: Use the Illustrative Procedures to help clarify the necessary components to accurately score the statement. From the MyCSF Homepage, click the Assessment name you would like to view. From the Assessment Domain, click on the Assessment Statement of…
Assessor Report
Analytics » Reports » External Reports » Assessor Report
Contains the responses and assessor comments of the HITRUST CSF Assessment categorized by the nineteen domains. Assessment with HITRUST CSF Implementation Report After authenticating through the ‘MyCSF Portal’, click on ‘Analytics’ in the top Menu…
Status
Analytics » Dashboards » Assessments » Assessments » Status
View your chosen Assessment by ‘Status’ to further clarify how fast your Assessment is moving in either the ‘Self-Assessment’, ‘Validated Assessment’ or ‘Targeted Assessment Process’. Assessments – View your…
Submit a Domain to an Assessor
Assessment Questionnaire » Submitting an Assessment » Submit a Domain to an Assessor
When you are ready to submit your domain to your assessor for validation, press the link located in the green banner above the Assessment Statements for the Domain that you’ve finished. This link will not become available until all of the Assessment Statements have…
People Management
Administration » People Management
If you are an Account Administrator within your Organization, you have the ability to manage people’s access as well as modify their Assessment permissions. If you are wishing to elevate or decrease a user’s Administrative rights, click here for instructions. Or,…
Linking Statements and Documents
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Linking Statements and Documents
If you have documents in your Document Repository and/or have added new documents in the excel spreadsheet, you have the ability to link them to your Assessment Statements. *Please note that Account Admins, Assessment Leads, and Assessors can do the below. 1. From…
Name & Security
Pre-Assessment » Creating a New Assessment » Name & Security
The Name & Security page is where you will be able to see the administrative information pertaining to the Assessment. You can navigate to this page while filling out this assessment whenever you like. 1. After authenticating through the MyCSF Portal, click on your…
View the Risk Factors
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Risk Factors
Review the Risk Factors that apply to an Assessment Statement. Remember you can change the scope of your assessment if the information does not look correct or if an environment change has occurred by going to **Administrative & Scoping in the Nav bar. From…
Admin
Analytics » Dashboards » Admin
Under the ‘Admin’ tab, you can view each Assessment’s Administrative and Scoping inputs under this subscription. Click on each function at the top of the page to access one. Admin – This option allows you to review the Pre-Assessment information…
Applying to be an Internal Assessor
Internal Assessors » Applying to be an Internal Assessor
Internal Assessors are those personnel who facilitate the CSF Assessment process by performing in-house testing in advance of an External Assessor’s validated assessment fieldwork. Internal Assessors are part of an “Internal Assessment Function.” This function…
Assigning a User
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Assigning a User
Assigning a user to an Assessment Statement is a beneficial tool to better manage resources and aggregate a collection of responses. From the Assessment Domain, click on the Assessment Statement you wish to assign. Press the ‘Actions’ button and…
Evaluating your Clients Assessment’s Statements
Assessment Questionnaire » Completing an Assessment » Creating and Importing Assessor Evaluation for an Offline Assessment » Evaluating your Clients Assessment’s Statements
Once you have downloaded the excel spreadsheet, you are now able to evaluate and validated your Assessment Statements offline. 1. From the spreadsheet, click on the ‘Assessment’ sheet to add your maturity evaluation and comments for each Assessment…
Documents & Other
Analytics » Dashboards » Assessments » Documents & Other
View all of the ‘Requirements’ that your chosen Assessment is mandated to undergo, including, relevant ‘Controls’ and ‘Authoritative Sources’ for it. Requirements – Inspect each of the required materials in any assessment…
Submitting External Assessor Reverted Controls Back to the External Assessor
Assessment Questionnaire » Submitting an Assessment » Submitting External Assessor Reverted Controls Back to the External Assessor
When an External Assessor reverts an Assessment Statement back to their client, the returned Assessment Statement will display a “Response Needed for External Assessor” status. To address these Assessment Statements, you as the client will need to do the…
View the Authoritative Sources
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Authoritative Sources
If you’re interested in the standards and regulations that comprise an Assessment Statement, use the Authoritative Sources link under the More Info dropdown. From the Assessment Domain, click on the Assessment Statement you wish to view the Authoritative…
Homepage
Homepage
The Homepage of MyCSF is the starting location for every user that authenticates through the HITRUST Portal. From here, you can easily locate Assessments, Subscription Information, Your Notifications, Custom Libraries and more. Subscription Information …
Adding a Related Document
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a Related Document
If you wish to document evidence for an Assessment Statement, use the related documents functionality. You can either reference items previously uploaded or new items that are not yet in your Document repository. From the MyCSF Homepage, click the Assessment…
Administrative
Analytics » Dashboards » Admin » Administrative
View your Organization Information and Assessment Options inputs. This is the information you entered in your Assessment under the Administrative & Scoping section of ‘MyCSF’. Administrative Details After authenticating through the MyCSF Portal, click…
Assessments
Analytics » Dashboards » Assessments
Here in the ‘Assessments’ tab, view statistics about each ‘Assessment Statement’ you have entered, and the relevant actions during ‘Completing an Assessment’ you may or may have not placed alongside it. Review your…
Internal Assessors
Internal Assessors
Organizations, that are capable of demonstrating proficiency within their Internal Audit departments, are permitted to test their own Requirement Statements and enable their External Assessor to rely on the results. Click here to learn more. Sub-topics Applying to…
Completing your Internal Assessor Time Sheet
Internal Assessors » Completing your Internal Assessor Time Sheet
Like External Assessors, Internal Assessors are obligated to document both the individuals who performed Internal Assessor duties on the Assessment as well as the hours they each committed. On the sidebar, click the ‘Internal Assessor Time Sheet’ label to be…
Missed My Submission Date
Reservations » Rescheduling/Cancelling a Reservation » Missed My Submission Date
If the submission date that is defined for your reservation passes without your assessment having been previously submitted, your reservation will be automatically cancelled. You may be issued a cancellation fee if the submission date fell after the “Last day to…
All Potential Requirements
Analytics » Dashboards » Assessments » Documents & Other » All Potential Requirements
Find your ‘Potential Requirements’ to the current state of your Assessment including ‘Statements; and Authoritative Sources’**. Requirements – Inspect each of the required materials in any assessment ranging from the…
Answering Requirement Statements
Internal Assessors » Answering Requirement Statements
By Default, all Requirement Statements will be inherently owned by Management. If you wish to provide the scoring as an Internal Assessor, you can either designate individual Requirement Statements or entire Assessment Domains as having be addressed by an Internal…
Systems
Pre-Assessment » Scoping an Assessment » Systems
This is your catalog of systems that will be examined in your assessment. The ‘Selected Tab’ will show all of the systems that are to be assessed. The ‘Other Tab’ represents systems that have been applied to your organization previously but will not be…
How To Create External Inheritance Requests by Requirement
Inheritance » External Inheritance » Inheritance Requestors » How To Create External Inheritance Requests by Requirement
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal window. 2. From the ‘Requests’ tab within the Inheritance Modal, select ‘External’ from the drop-down for the…
Making a Reservation
Reservations » Making a Reservation
Reservations allow you to have more awareness into when your validated assessment will be reviewed by the HITRUST Quality Assurance team. You can set one up seamlessly within your assessment. From the MyCSF Homepage, click on the i1 or r2 validated assessment for…
How To Create/Apply Internal Inheritance Requests
Inheritance » Internal Inheritance » How To Create/Apply Internal Inheritance Requests
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button (yellow underline) to open the Inheritance window. 2. From the ‘Requests’ tab within the Inheritance window, select ‘Internal’ from the…
Adding a Diary Entry
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a Diary Entry
The Diary will enable you to enter comments on each of your Assessment Statements to communicate within your organization or assessor. 1. From the Assessment Domain, click on the Assessment Statement that you wish to input a Diary entry. 2. Click on the ‘Diary…
HITRUST’s Criteria for Submission
Assessment Questionnaire » Submitting an Assessment » HITRUST’s Criteria for Submission
If you have completed all of the Assessments Statements in either your Self or Validated Assessment to HITRUST, please verify that the below is covered before submitting it. 1. Ensure that the following Required Documents have been uploaded with the correct dates as…
Setting Assessor Access
Pre-Assessment » Creating a New Assessment » Name & Security » Setting Assessor Access
From the Name & Security page, here is where you will be able to see the assessor permissions associated with the assessment. You can also navigate to this page while filling out this assessment whenever you like by clicking on the Lock Icon. Assessor Permissions …
Filters
Analytics » Dashboards » Filters
Use the Filters module to narrow down a search on specific Statements you may be looking for and the Assessments they may lie in. This includes filters such as Not Applicable, In Scope, Required for CSF Certification, Maturity Rating, and Gap Rating. Filters –…
Assessments
Analytics » Dashboards » Assessments » Assessments
Check out each Assessment under your subscription with all of the data applicable to your Assessments under the categories ‘High Level’, ‘Responses’, ‘Results’, ‘Comparisons’, ‘Diary’, ‘Users’,…
Answering your Assessment’s Statements
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Answering your Assessment’s Statements
Once you have downloaded the excel spreadsheet, you are now able to answer your Assessment Statements offline. 1. From the spreadsheet, click on the ‘Assessment’ sheet to select if a Statement is or not applicable, maturity scores for each maturity level, and…
High Level
Analytics » Dashboards » Assessments » Assessments » High Level
View your chosen Assessment at the highest ‘Avg Maturity Level’ available, accompanied by two interactive charts relating to your Assessment’s ‘Status Filters’ and ‘GAP Status’ for your Statements. Assessments – View your…
Related Documents
Analytics » Dashboards » Assessments » Documents & Other » Related Documents
View any of the ‘Related Documents’ under your subscription that has a document attatched to any of your ‘Statements’ . Requirements – Inspect each of the required materials in any assessment ranging from the ‘Controls’…
High Level
Analytics » Dashboards » Assessments » Residual Risk » High Level
This option allows us to view the ‘Table of Domains’ and the ‘Residual Risk Ratings’ that each carries for Statements ‘Completed in your Assessment’. Residual Risk – Investigate the areas of your Assessment that may or may…
Residual Risk Rating
Analytics » Dashboards » Assessments » Residual Risk » Residual Risk Rating
Study each Statement in/out of your ‘Scope’ to find the risk you carry per Statement if it is ‘Applicable’. Residual Risk – Investigate the areas of your Assessment that may or may not require immediate attention in the ‘Scope of…
Home
Analytics » Dashboards » Home
Here you will see your total ‘Assessments’, ‘Avg. Maturity Score per Domain’, as well as your ‘Gap Status’, and ‘Residual Risk Rating’ charts. Home – Here is the homepage you will automatically arrive at upon…
Setting User Access
Pre-Assessment » Creating a New Assessment » Name & Security » Setting User Access
From the Name & Security page, you will be able to set the users associated with this Assessment under the People section. Place your users in the table as either No Access, Assessment Lead, Standard User, Customer Respondent, Read Only, or a Custom Role. You can…
Documents
Documents
Support the findings in your Assessment with the linking of evidence. A built-in Repository allows for documents to be referenced while scoring an Assessment Statement. 1. From the Assessment Homepage, there is a ‘Documents’ label on the left Sidebar. …
Uploading Evidence
Documents » Uploading Evidence
Upload a piece of evidence you believe will aid you in your assessment. The documents you provide will help support the ‘Assessor’ on why certain Maturity Value selections were made. From the MyCSF Homepage, click on the Assessment name you would like to…
Residual Risk
Analytics » Dashboards » Assessments » Residual Risk
The ‘Residual Risk’ you carry will be nested here and will carry statistics and charts that mark your vulnerability by ‘Residual Risk Score’, ‘CSF Compliance’ and ‘Residual Risk Rating’. ‘Residual Risk’…
Viewing Potential Quality Issues
Assessment Questionnaire » Potential Quality Issues » Viewing Potential Quality Issues
There are two ways within MyCSF to view the Potential Quality Issues raised within your Assessment. The first manner is observing them on a Statement while inside an Assessment Domain. The second option is to view all of the Potential Quality Issues in a consolidated…
Uploading Documents in Bulk
Documents » Uploading Evidence » Uploading Documents in Bulk
If you have a MyCSF Subscription, uploading documents in bulk is now available to do within an Assessment. Please follow the instructions below on how to bulk upload documents within an Assessment. On the sidebar, click the ‘Documents’ icon to be redirected to…
Managing your Documents
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Managing your Documents
All of the documents that exist in your Assessments Document Repository will be listed in the excel spreadsheet. You will have the ability to manage existing documents as well as adding new documents (without an attachment) in your Repository. !Please note that when…
Facilities
Pre-Assessment » Scoping an Assessment » Facilities
This is your catalog of facilities that will be addressed in your assessment. The ‘Selected Tab’ will show all of the facilities that will be addressed. The ‘Other Tab’ represents systems that have been applied to your organization previously,…
CAPs
Analytics » Dashboards » CAPs
The CAPs function is prepared by your Assessor Organization and the Assessor as applicable, and will also serve to describe a ‘Corrective Action Plan (CAP)’. These measurements describe the plan to correct deficiencies identified during the Assessment for…
Default Scoring Profile
Pre-Assessment » Scoping an Assessment » Default Scoring Profile
This option allows you to pre-score the maturity values for the Assessment. This is a desirable function for your organizations who have established trends within their Assessment. The Default Scoring Profile values defined will be applied to all Not Started…
Factors
Pre-Assessment » Scoping an Assessment » Factors
The inputs on the Factors tab are used to measure the risk inherent to your environment. The information provided within will be used to narrow down the list of assessment statements for your questionnaire. General Factors – These factors are used to…
Systems
Analytics » Dashboards » Admin » Systems
View your System inputs. This is the information you entered in your Assessment under the Administrative & Scoping section of ‘MyCSF’. Systems After authenticating through the MyCSF Portal, click on ‘Analytics’ in the top Menu bar. Once pressed,…
Facilities
Analytics » Dashboards » Admin » Facilities
View your Facility inputs. This is the information you entered in your Assessment under the Administrative & Scoping section of ‘MyCSF’. Facilities After authenticating through the MyCSF Portal, click on ‘Analytics’ in the top Menu bar. Once…
Factors
Analytics » Dashboards » Admin » Factors
View your Factor inputs. This is the information you entered in your Assessment under the Administrative & Scoping section of ‘MyCSF’. Factors After authenticating through the MyCSF Portal, click on ‘Analytics’ in the top Menu bar. Once pressed,…
How To Apply Approved External Inheritance Requests
Inheritance » External Inheritance » Inheritance Requestors » How To Apply Approved External Inheritance Requests
1. From anywhere within the Assessment view, go to the ‘Inheritance’ request page by clicking on the ‘Inheritance’ link located on the left-hand side panel after the ‘Documents’ section. 2. From the ‘Inheritance’ request page, click on the…
Adding Corrective Action Plans
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding Corrective Action Plans
For Statements where deficiencies are found, you are able to detail Corrective Actions that will help remediate the identified problem. *Note: Only the organization’s user can enter CAPs, the assessor cannot. 1. From the Assessment Domain, click on the…
Library Retention
Pre-Assessment » Scoping an Assessment » Library Retention
The Library Retention feature provides visibility into specific changes associated with HITRUST CSF version updates, and allows users to apply those changes to assessment objects created under previous versions of the framework. To begin the update process, open an…