Search
Related topics are listed below.
Creating a New Assessment
Pre-Assessment » Creating a New Assessment
If you are an Account Administrator, you’ll be able to simply add a new Assessment directly through the homepage of MyCSF. From the MyCSF Homepage, click the ‘+ Create Assessment’ button on the ‘Assessments’ table found under the Organization panel. You…
Creating a Custom Assessment Library
Homepage » Creating a Custom Assessment Library
Account Administrators are able to create and manage a Custom Assessment using the HITRUST CSF and its Authoritative Sources using HITRUST provided questions. Please follow the steps below on how to create a customized Assessment Library. From the MyCSF Homepage,…
Creating an Offline Assessment
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment
An Offline Assessment gives you the ability to complete an Assessment outside of MyCSF using a spreadsheet and seamlessly import it back into the application. If you have a MyCSF Subscription and wish to complete your Assessment offline, follow the instructions below…
Recreating a Validated Assessment Object
Interim Assessment (r2 only) » Recreating a Validated Assessment Object
Once an Interim Assessment has been provisioned, please note that you will have to answer all the Pre-Assessment and Assessment Questionnaire identical to your CSF Certification. *If you still have access to the Original Certified Assessment Object, you do not need to…
Pre-Assessment
Pre-Assessment
Topics in Pre-Assessment include: Creating a New Assessment and Scoping an Assessment. Organization Information Subtopics Creating a New Assessment Scoping an Assessment
Assessment Name
Pre-Assessment » Creating a New Assessment » Name & Security » Assessment Name
On the Name & Security page, there is a text input reserved for the name of the Assessment. The name will help you identify it easily from any other assessment you may have. For example: “2019 ABC Company Validated Assessment”, “2019 ABC Company…
Assessment Questionnaire
Assessment Questionnaire
After completing the Scope of your Assessment, you can begin answering the questions that have been generated based on your scope. Topics range from: Completing an Assessment, Marking Not-Applicable, Assigning a User, CAP Management, Authoritative Sources, Assessment…
Assessment Options
Pre-Assessment » Scoping an Assessment » Assessment Options
Answer the dropdowns provided to determine what kind of assessment will be generated by MyCSF. This includes Targeted, CSF Security, CSF Security & Privacy, CSF Comprehensive Security, and CSF Comprehensive Security & Privacy Assessments. The level of validation will…
Assessment Report
Analytics » Reports » External Reports » Assessment Report
Contains the responses of the HITRUST CSF Assessment categorizes by the nineteen domains. This is separate from the purchasable Self-Assessment report. Assessment Report After authenticating through the ‘MyCSF Portal’, click on ‘Analytics’ in the…
Adding a New Person
Administration » Subscriber Management » Adding a New Person
If you are wishing to add a new person to your MyCSF Account, please follow the steps below: From the Homepage, click the ‘Administration’ button at the top Menu bar or below your Subscription Information. From the Subscriber Management page, click the ‘+ Add…
Creating and Importing Assessor Evaluation for an Offline Assessment
Assessment Questionnaire » Completing an Assessment » Creating and Importing Assessor Evaluation for an Offline Assessment
When a Validated Assessment has been submitted to an Assessor, you the Assessor has the ability to fill-out your evaluation outside of MyCSF using a spreadsheet and seamlessly import your evaluation back into the application. Follow the instructions below on Creating…
Adding a New Custom Role
Administration » Subscriber Management » Adding a New Custom Role
If you have a Corporate Level Subscription or above and you are wishing to add a new custom role to your MyCSF Account, please follow the steps below: From the Homepage, click the ‘Administration’ button at the top Menu bar or below your Subscription…
Adding a New API User
Administration » Subscriber Management » Adding a New API User
If you are wishing to add a new API User to your MyCSF Account, please follow the steps below: From the Homepage, click the ‘Administration’ button at the top Menu bar or below your Subscription Information. From the Subscriber Management page, click the ‘+…
Adding a User to an Assessment Domain
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a User to an Assessment Domain
Assigning a User to an Assessment Domain is a beneficial tool to better manage resources and aggregate a collection of responses. From the Assessment Questionnaire, click on the Assessment Domain you wish to assign. From the Assessment Domain, click on the…
Scoping an Assessment
Pre-Assessment » Scoping an Assessment
The scope of the Assessment is the information about your organization that will be used to narrow down the most precise assessment for your compliance and security needs. Fields marked with red asterisks are mandatory. After authenticating through the HITRUST…
Deleting an Assessment
Pre-Assessment » Creating a New Assessment » Name & Security » Deleting an Assessment
Deleting an Assessment will be permanently removed from MyCSF. Only Account Admins and Assessment Leads have the privilege to delete an Assessment. The status of the Assessment must be ‘Not Started’ or ‘Answering Assessment’, as well as not submitted to the…
Completing an Assessment
Assessment Questionnaire » Completing an Assessment
There are many components to completing an assessment. This includes: Answering an Assessment Statement, Assigning Respondents, Related Authoritative Sources, Risk Factors, History Statement Log, Illustrative Procedures, Adding a Document, and CAP Management. …
Submitting an Assessment
Assessment Questionnaire » Submitting an Assessment
Whether submitting a Self-Assessment or a Validated Assessment by your assessor organization, the Assessment Questionnaire can be submitted either by each fully completed domain (Validated only) or by completing the entire Assessment (Self-Assessment/Validated…
Selecting Your Assessment
Homepage » Selecting Your Assessment
After setting your Organization an Assessment table will appear with all of the Assessments within your account. Atop the ‘Assessments’ table, is a donut chart displaying a consolidation of the statuses of your Assessments. Click on portions of the donut chart to…
Controlling Assessment Roles
Administration » People Management » Controlling Assessment Roles
Follow the instructions below to manage a user’s Assessment Privileges. From the Homepage, click the ‘Administration’ button at the at the top Menu bar or below your Subscription Information. Click on the name of the Assessment you wish to update. From the…
Cloning an Assessment
Pre-Assessment » Creating a New Assessment » Name & Security » Cloning an Assessment
Cloning an Assessment gives you the ability to transfer all maturity scores, comments, and documents from an existing Assessment into a newly created one. If you wish to complete a new Assessment with existing data from a previous Assessment, follow the instructions…
Viewing an Assessment
Pre-Assessment » Creating a New Assessment » Viewing an Assessment
From the Hompage of MyCSF, you can view any Assessment that has been generated. To view an Assessment, please follow the steps below to access and view an Assessment within your MyCSF Account. From the Homepage, there is an ‘Assessments’ table that includes…
Creating CAPs
Corrective Action Plans (CAPs) » Creating CAPs
There are two ways a CAP can be added to your Organization’s Repository: Either as a result of defining them within one of your Assessments or by adding them directly into the Repository. This topic will cover the latter. From your CAP Repository page (link), you…
Viewing an Assessment Domain
Assessment Questionnaire » Completing an Assessment » Viewing an Assessment Domain
To view the Assessment Statements you have generated in the Scope of your Assessment click on the Clipboard in the left Nav bar so you may be able to view your Assessment Questionnaire. Choose one of your nineteen domains to begin answering one of your Assessment…
Answering an Assessment Statement
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement
There are many components to completing an assessment. This includes: Answering a Statement, Assigning a Respondent, Related Authoritative Sources, Risk Factors, History Assessment Log, Illustrative Procedures, Adding Documents, and CAP Management. r2 Assessment: …
Assessment Domain Status Filters
Assessment Questionnaire » Completing an Assessment » Viewing an Assessment Domain » Assessment Domain Status Filters
On your Table of Assessment Domains, you will be able to filter each domain within your assessment by its respective status. A corresponding count and color will appear within a badge icon for each status currently found in a domain. Here is a list of all possible…
Inheriting an Assessment Statement
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Inheriting an Assessment Statement
See Inheriting an Assessment Statement
Offline Assessment – Inheritance
Assessment Questionnaire » Completing an Assessment » Offline Assessment – Inheritance
The Offline Assessment feature may be used to populate inheritance requests. For more information refer to the following link: How to Request Inheritance using the Offline Assessment Template
Interim Assessment (r2 only)
Interim Assessment (r2 only)
If you are coming up on your 1-year Anniversary of your CSF Certification, you will need to perform an Interim Assessment. The Interim Assessment is to ensure that the scope of your CSF Certification is still valid. If you have a MyCSF Subscription, click here for…
Re-validating the Assessment
Interim Assessment (r2 only) » Recreating a Validated Assessment Object » Re-validating the Assessment
As you would in any Validated Assessment, you as the Assessor will need to validate all of the Assessment Questions completed by your Client. You will have to ensure the maturity scores entered are identical to their Original CSF Certification. From the Homepage,…
Adding a New Person to the Portal
Administration » Organization Consolidation » User Management » Adding a New Person to the Portal
Follow the instructions below to add a new person to your Portal Account: From the Portal Administration page, click the ‘Add Person’ button on the User Management table. From the modal, enter the ‘First Name’, ‘Last Name’, and ‘Email’. Click the…
View the Assessment Statement Log
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Assessment Statement Log
Keep track of the users who have answered an Assessment Statement by accessing the Assessment Statement Log. MyCSF archives who modified a statement and when they did it. From the Assessment Domain, click on the Assessment Statement you wish to view the…
Manually Generating an Interim Assessment
Interim Assessment (r2 only) » Manually Generating an Interim Assessment
If you are coming up on your 1-year Anniversary of your CSF Certification and have a MyCSF Subscription, please note that your Interim Assessment will auto-generate 90 days prior to the Anniversary of the Certification Date of your Original Assessment. If you wish to…
Performing an Interim Review Assessment
Interim Assessment (r2 only) » Performing an Interim Review Assessment
If you are coming up on your 1-year Anniversary of your CSF Certification, you will need to perform an Interim Assessment. The Interim Assessment is to ensure that the scope of your CSF Certification is still valid. From the Homepage, click on the Assessment with…
Setting Assessment Statements as Not Applicable
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Setting Assessment Statements as Not Applicable
Assessment Statements may need to be marked as Not Applicable (N/A). If there are Assessment Statements that you feel you do not need to comply, check the N/A box within a statement. *You will be required to provide rationale in the comments. From the…
How to Publish (Enable) Assessment Inheritability
Inheritance » External Inheritance » Inheritance Providers » How to Publish (Enable) Assessment Inheritability
From the ‘Name & Security’ pre-assessment page, check the box next to “Published” and click Confirm when prompted to agree to the Inheritance User Terms and Conditions. A published assessment will show a banner icon with a hover-over tooltip next the…
How to Unpublish (Disable) Assessment Inheritability
Inheritance » External Inheritance » Inheritance Providers » How to Unpublish (Disable) Assessment Inheritability
From the ‘Name & Security’ pre-assessment page, uncheck the box next to “Published” and click Confirm when prompted. *Note: The system will automatically unpublish an assessment on its date of expiration—for the r2 Certification: the 2-year…
Enabling Internal Assessors On Your Assessment
Internal Assessors » Enabling Internal Assessors On Your Assessment
After your Internal Assessor application has been approved, the Name and Security page on your Organization’s Assessment will be altered to include a checkbox allowing you to mark your Assessment as having been tested by Internal Assessors. When selected, you will be…
Assigning Internal Assessors to an Assessment
Internal Assessors » Assigning Internal Assessors to an Assessment
If an Internal Assessor Function has been chosen for an Assessment (Link to Enabling Internal Assessors On Your Assessment), the Subscriber People table will be augmented to include a new column that is reserved for Internal Assessors. Those that have been delegated…
Assessment with HITRUST CSF Implementation Report
Analytics » Reports » External Reports » Assessment with HITRUST CSF Implementation Report
Contains the responses of the HITRUST CSF Assessment categorized by the nineteen domains. This is separate from the purchasable Self-Assessment report. Assessment with HITRUST CSF Implementation Report After authenticating through the ‘MyCSF Portal’,…
How To View Internally-Inherited Assessment Scores
Inheritance » Internal Inheritance » How To View Internally-Inherited Assessment Scores
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal. 2. Within the Inheritance Modal, click on the ‘Scoring’ tab. The first line shows the internal assessment from which…
How To View Externally-Inherited Assessment Scores
Inheritance » External Inheritance » Inheritance Requestors » How To View Externally-Inherited Assessment Scores
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal. 2. Within the Inheritance Modal, click on the ‘Scoring’ tab. The first line shows the external assessment from which…
Corrective Action Plans (CAPs) in Your Assessment
Assessment Questionnaire » Corrective Action Plans (CAPs) in Your Assessment
Because CAPs can be linked to Statements within an Assessment, you may be interested in which CAPs have been associated collectively to an Assessment. This can be done by simply going to the Assessment (link to viewing an assessment) for which you wish to see the…
Answering CAPs & Generating an Interim Assessment
Interim Assessment (r2 only) » Recreating a Validated Assessment Object » Answering CAPs & Generating an Interim Assessment
If you had CAPs identified within your Original CSF Certification, you will have to add the same corrective action plan identical to your Original CSF Certification. If you do not have any mandatory Corrective Action Plans, you can immediately generate the Interim…
How To Request Inheritance Using the Offline Assessment Template
Inheritance » External Inheritance » Inheritance Requestors » How To Request Inheritance Using the Offline Assessment Template
To create inheritance requests using the offline assessment, first generate the offline assessment worksheet using the process outlined in the Creating an Offline Assessment section of the User Guide. Locate and click the “Inheritance” tab in the Offline…
Assigning a User
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Assigning a User
Assigning a user to an Assessment Statement is a beneficial tool to better manage resources and aggregate a collection of responses. From the Assessment Domain, click on the Assessment Statement you wish to assign. Press the ‘Actions’ button and…
Making a Reservation
Reservations » Making a Reservation
Reservations allow you to have more awareness into when your validated assessment will be reviewed by the HITRUST Quality Assurance team. You can set one up seamlessly within your assessment. From the MyCSF Homepage, click on the i1 or r2 validated assessment for…
Configuring a User as a HITRUST CSF practitioner
Internal Assessors » Configuring a User as a HITRUST CSF practitioner
A requirement of the Internal Assessor program is that all users performing Internal Assessor duties must be an active HITRUST CSF Certified Practitioner (CCSFP). In order to have a user validated as a CCSFP, the Account Administrator from your organization must…
Adding a Related Document
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a Related Document
If you wish to document evidence for an Assessment Statement, use the related documents functionality. You can either reference items previously uploaded or new items that are not yet in your Document repository. From the MyCSF Homepage, click the Assessment…
Adding a Diary Entry
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » Adding a Diary Entry
The Diary will enable you to enter comments on each of your Assessment Statements to communicate within your organization or assessor. 1. From the Assessment Domain, click on the Assessment Statement that you wish to input a Diary entry. 2. Click on the ‘Diary…
Approving a Draft Report
Reports » r2 and i1 Assessments » Approving a Draft Report
‘Draft Reports’ are automatically approved 30 days after posting. However, the reports can be manually approved prior to the 30 days, by selecting the ‘Approve HITRUST CSF Report’ button on the ‘CSF Reports’ section, HITRUST will then be notified to…
Rescheduling/Cancelling a Reservation
Reservations » Rescheduling/Cancelling a Reservation
Once a reservation is made on your assessment, you are entitled to modify or cancel it. Follow the steps below to accomplish this. From the MyCSF Homepage, click on the i1 or r2 Validated Assessment for which you’d like to make a reservation. On the left-hand…
Adding CAPs to a Statement
Assessment Questionnaire » Corrective Action Plans (CAPs) in Your Assessment » Adding CAPs to a Statement
For Statements that have been identified as a Gap or as requiring a Corrective Action, CAPs can be added directly from an Assessment Domain. In order to do this, it does require the “Can Manage CAPs” permission to be set if you are not an Account Administrator.…
Linking CAPs to a Statement
Assessment Questionnaire » Corrective Action Plans (CAPs) in Your Assessment » Linking CAPs to a Statement
For Statements that have been identified as a Gap or as requiring a Corrective Action, CAPs in your Repository can be linked directly from an Assessment Domain. In order to do this, it does require the “Can Manage CAPs” permission to be set if you are not an…
Unlinking CAPs from a Statement
Assessment Questionnaire » Corrective Action Plans (CAPs) in Your Assessment » Unlinking CAPs from a Statement
CAPs that you no longer wish to have linked to a Statement can be removed from a Statement in a few clicks. On the Statement, press the “CAP” button to expand the CAP table. Select the CAP you want to have disassociated from the active Statement. Once…
Overriding a Potential Quality Issue
Assessment Questionnaire » Potential Quality Issues » Overriding a Potential Quality Issue
The analysis MyCSF runs to check for Potential Quality Issues may sometimes lead to false positives. Because of this, these occurrences can be overridden and excused from remediation. However, if a Potential Quality Issue is overridden, a detailed rationale must be…
Submit a Domain to an Assessor
Assessment Questionnaire » Submitting an Assessment » Submit a Domain to an Assessor
When you are ready to submit your domain to your assessor for validation, press the link located in the green banner above the Assessment Statements for the Domain that you’ve finished. This link will not become available until all of the Assessment Statements have…
Request a Revision for an Issued Report
Reports » r2 and i1 Assessments » Request a Revision for an Issued Report
If you have discovered a spelling error or any type of inaccuracy in your ‘Draft Report’, you can request a revision by pressing the ‘Request Revision’ button. You will be able to place your comment in a text box that you can send to the HITRUST Assurance…
Homepage
Homepage
The Homepage of MyCSF is the starting location for every user that authenticates through the HITRUST Portal. From here, you can easily locate Assessments, Subscription Information, Your Notifications, Custom Libraries and more. Subscription Information …
Corrective Action Plans (CAPs)
Corrective Action Plans (CAPs)
Corrective Action Plans (CAPs) you add through MyCSF are inherently associated with your Organization in what is called the CAP Repository. This is done in an effort to allow you to reuse previously entered CAPs, vastly simplifying the management of these Corrective…
Name & Security
Pre-Assessment » Creating a New Assessment » Name & Security
The Name & Security page is where you will be able to see the administrative information pertaining to the Assessment. You can navigate to this page while filling out this assessment whenever you like. 1. After authenticating through the MyCSF Portal, click on your…
Linking Statements and Documents
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Linking Statements and Documents
If you have documents in your Document Repository and/or have added new documents in the excel spreadsheet, you have the ability to link them to your Assessment Statements. *Please note that Account Admins, Assessment Leads, and Assessors can do the below. 1. From…
Submitting External Assessor Reverted Controls Back to the External Assessor
Assessment Questionnaire » Submitting an Assessment » Submitting External Assessor Reverted Controls Back to the External Assessor
When an External Assessor reverts an Assessment Statement back to their client, the returned Assessment Statement will display a “Response Needed for External Assessor” status. To address these Assessment Statements, you as the client will need to do the…
Systems
Pre-Assessment » Scoping an Assessment » Systems
This is your catalog of systems that will be examined in your assessment. The ‘Selected Tab’ will show all of the systems that are to be assessed. The ‘Other Tab’ represents systems that have been applied to your organization previously but will not be…
Managing your Documents
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Managing your Documents
All of the documents that exist in your Assessments Document Repository will be listed in the excel spreadsheet. You will have the ability to manage existing documents as well as adding new documents (without an attachment) in your Repository. !Please note that when…
How To Use the Kanban View To Track Inheritance Requests
Inheritance » External Inheritance » Inheritance Requestors » How To Use the Kanban View To Track Inheritance Requests
The Kanban reporting view can be used to confirm the submitted inheritance requests. Find the Kanban board by: 1. Clicking the Views option in MyCSF and selecting the Kanban View. 2. Then filter for the assessment object name. Hovering over the assessment tile…
Inheritance
Inheritance
Inheritance is a feature within MyCSF that allows maturity level scores associated with specific requirements to be transferred, or “inherited”, from previously scored assessment objects. Maturity scores that originated from an “inheritable” assessment…
External Inheritance
Inheritance » External Inheritance
External Inheritance allows users to “inherit” assessment results that are shared by the same or different organizational entity. Access and use of external inheritance is subject to the following requirements and available functionality: The owner of the…
Facilities
Pre-Assessment » Scoping an Assessment » Facilities
This is your catalog of facilities that will be addressed in your assessment. The ‘Selected Tab’ will show all of the facilities that will be addressed. The ‘Other Tab’ represents systems that have been applied to your organization previously,…
Assessor Report
Analytics » Reports » External Reports » Assessor Report
Contains the responses and assessor comments of the HITRUST CSF Assessment categorized by the nineteen domains. Assessment with HITRUST CSF Implementation Report After authenticating through the ‘MyCSF Portal’, click on ‘Analytics’ in the top Menu…
View the Illustrative Procedures
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Illustrative Procedures
r2 Assessment: Use the Illustrative Procedures to help clarify the necessary components to accurately score the statement. From the MyCSF Homepage, click the Assessment name you would like to view. From the Assessment Domain, click on the Assessment Statement of…
Status
Analytics » Dashboards » Assessments » Assessments » Status
View your chosen Assessment by ‘Status’ to further clarify how fast your Assessment is moving in either the ‘Self-Assessment’, ‘Validated Assessment’ or ‘Targeted Assessment Process’. Assessments – View your…
People Management
Administration » People Management
If you are an Account Administrator within your Organization, you have the ability to manage people’s access as well as modify their Assessment permissions. If you are wishing to elevate or decrease a user’s Administrative rights, click here for instructions. Or,…
View the Risk Factors
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Risk Factors
Review the Risk Factors that apply to an Assessment Statement. Remember you can change the scope of your assessment if the information does not look correct or if an environment change has occurred by going to **Administrative & Scoping in the Nav bar. From…
Admin
Analytics » Dashboards » Admin
Under the ‘Admin’ tab, you can view each Assessment’s Administrative and Scoping inputs under this subscription. Click on each function at the top of the page to access one. Admin – This option allows you to review the Pre-Assessment information…
Library Retention
Pre-Assessment » Scoping an Assessment » Library Retention
The Library Retention feature provides visibility into specific changes associated with HITRUST CSF version updates, and allows users to apply those changes to assessment objects created under previous versions of the framework. To begin the update process, open an…
Applying to be an Internal Assessor
Internal Assessors » Applying to be an Internal Assessor
Internal Assessors are those personnel who facilitate the CSF Assessment process by performing in-house testing in advance of an External Assessor’s validated assessment fieldwork. Internal Assessors are part of an “Internal Assessment Function.” This function…
Documents & Other
Analytics » Dashboards » Assessments » Documents & Other
View all of the ‘Requirements’ that your chosen Assessment is mandated to undergo, including, relevant ‘Controls’ and ‘Authoritative Sources’ for it. Requirements – Inspect each of the required materials in any assessment…
View the Authoritative Sources
Assessment Questionnaire » Completing an Assessment » Answering an Assessment Statement » View the Authoritative Sources
If you’re interested in the standards and regulations that comprise an Assessment Statement, use the Authoritative Sources link under the More Info dropdown. From the Assessment Domain, click on the Assessment Statement you wish to view the Authoritative…
Administrative
Analytics » Dashboards » Admin » Administrative
View your Organization Information and Assessment Options inputs. This is the information you entered in your Assessment under the Administrative & Scoping section of ‘MyCSF’. Administrative Details After authenticating through the MyCSF Portal, click…
Internal Assessors
Internal Assessors
Organizations, that are capable of demonstrating proficiency within their Internal Audit departments, are permitted to test their own Requirement Statements and enable their External Assessor to rely on the results. Click here to learn more. Sub-topics Applying to…
Assessments
Analytics » Dashboards » Assessments
Here in the ‘Assessments’ tab, view statistics about each ‘Assessment Statement’ you have entered, and the relevant actions during ‘Completing an Assessment’ you may or may have not placed alongside it. Review your…
Missed My Submission Date
Reservations » Rescheduling/Cancelling a Reservation » Missed My Submission Date
If the submission date that is defined for your reservation passes without your assessment having been previously submitted, your reservation will be automatically cancelled. You may be issued a cancellation fee if the submission date fell after the “Last day to…
How To Create External Inheritance Requests by Requirement
Inheritance » External Inheritance » Inheritance Requestors » How To Create External Inheritance Requests by Requirement
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button to open the Inheritance Modal window. 2. From the ‘Requests’ tab within the Inheritance Modal, select ‘External’ from the drop-down for the…
All Potential Requirements
Analytics » Dashboards » Assessments » Documents & Other » All Potential Requirements
Find your ‘Potential Requirements’ to the current state of your Assessment including ‘Statements; and Authoritative Sources’**. Requirements – Inspect each of the required materials in any assessment ranging from the…
Completing your Internal Assessor Time Sheet
Internal Assessors » Completing your Internal Assessor Time Sheet
Like External Assessors, Internal Assessors are obligated to document both the individuals who performed Internal Assessor duties on the Assessment as well as the hours they each committed. On the sidebar, click the ‘Internal Assessor Time Sheet’ label to be…
Answering Requirement Statements
Internal Assessors » Answering Requirement Statements
By Default, all Requirement Statements will be inherently owned by Management. If you wish to provide the scoring as an Internal Assessor, you can either designate individual Requirement Statements or entire Assessment Domains as having be addressed by an Internal…
How To Create/Apply Internal Inheritance Requests
Inheritance » Internal Inheritance » How To Create/Apply Internal Inheritance Requests
1. From the Assessment Domain, expand the requirement statement view and click on the ‘Inheritance’ button (yellow underline) to open the Inheritance window. 2. From the ‘Requests’ tab within the Inheritance window, select ‘Internal’ from the…
Evaluating your Clients Assessment’s Statements
Assessment Questionnaire » Completing an Assessment » Creating and Importing Assessor Evaluation for an Offline Assessment » Evaluating your Clients Assessment’s Statements
Once you have downloaded the excel spreadsheet, you are now able to evaluate and validated your Assessment Statements offline. 1. From the spreadsheet, click on the ‘Assessment’ sheet to add your maturity evaluation and comments for each Assessment…
Subscriber Management
Administration » Subscriber Management
Depending on the Subscription Level access you have to MyCSF, the Subscriber Management page, is where you can manage and access your account’s ‘People’, ‘API Users’, ‘Custom Security Roles’, ‘Assessments’, ‘Links to HAX’, and ‘IP…
HITRUST’s Criteria for Submission
Assessment Questionnaire » Submitting an Assessment » HITRUST’s Criteria for Submission
If you have completed all of the Assessments Statements in either your Self or Validated Assessment to HITRUST, please verify that the below is covered before submitting it. 1. Ensure that the following Required Documents have been uploaded with the correct dates as…
Filters
Analytics » Dashboards » Filters
Use the Filters module to narrow down a search on specific Statements you may be looking for and the Assessments they may lie in. This includes filters such as Not Applicable, In Scope, Required for CSF Certification, Maturity Rating, and Gap Rating. Filters –…
Setting Assessor Access
Pre-Assessment » Creating a New Assessment » Name & Security » Setting Assessor Access
From the Name & Security page, here is where you will be able to see the assessor permissions associated with the assessment. You can also navigate to this page while filling out this assessment whenever you like by clicking on the Lock Icon. Assessor Permissions …
Answering your Assessment’s Statements
Assessment Questionnaire » Completing an Assessment » Creating an Offline Assessment » Answering your Assessment’s Statements
Once you have downloaded the excel spreadsheet, you are now able to answer your Assessment Statements offline. 1. From the spreadsheet, click on the ‘Assessment’ sheet to select if a Statement is or not applicable, maturity scores for each maturity level, and…
Assessments
Analytics » Dashboards » Assessments » Assessments
Check out each Assessment under your subscription with all of the data applicable to your Assessments under the categories ‘High Level’, ‘Responses’, ‘Results’, ‘Comparisons’, ‘Diary’, ‘Users’,…
MyCSF Compliance and Reporting Packs
Analytics » MyCSF Compliance and Reporting Packs
MyCSF Compliance and Reporting Pack for HIPAA Step 1: Create a readiness, validated, or targeted assessment using v9.5.0 or later which includes the HIPAA breach notification rule and/or HIPAA security rule. Step 2: Go to Analytics > Compliance Packs > Select…
Related Documents
Analytics » Dashboards » Assessments » Documents & Other » Related Documents
View any of the ‘Related Documents’ under your subscription that has a document attatched to any of your ‘Statements’ . Requirements – Inspect each of the required materials in any assessment ranging from the ‘Controls’…
High Level
Analytics » Dashboards » Assessments » Assessments » High Level
View your chosen Assessment at the highest ‘Avg Maturity Level’ available, accompanied by two interactive charts relating to your Assessment’s ‘Status Filters’ and ‘GAP Status’ for your Statements. Assessments – View your…
High Level
Analytics » Dashboards » Assessments » Residual Risk » High Level
This option allows us to view the ‘Table of Domains’ and the ‘Residual Risk Ratings’ that each carries for Statements ‘Completed in your Assessment’. Residual Risk – Investigate the areas of your Assessment that may or may…