1. An offering does not need to meet all aspects of a requirement statement to be mapped. Rationales are a suitable place to explain which aspects of the requirement statement the offering does and does not help with.
  1. Rationales do not need to be long or involved. Sometimes a statement as simple as, “As an endpoint protection package we help detect and prevent malware” is all that is needed.
  1. Rationales can be generic (i.e., they can be reused across many HITRUST CSF requirements). Generic rationales can be a more general statement about the offering.

Was this helpful?

Yes No
You indicated this topic was not helpful to you ...
Could you please leave a comment telling us why? Thank you!
Thanks for your feedback.