Hitrust Cyber Security Framework
October 28 2014 the hitrust common security framework csf is an important tool that healthcare organizations of all sizes can use in their approach to regulatory compliance and risk.
Hitrust cyber security framework. A voluntary cybersecurity framework to provide a prioritized flexible repeatable performance based and cost effective approach for the management of cybersecurity risk. The framework was developed to cater to the security issues organizations within the health industry face when managing it security. Rm sg members who assisted with the review of this guide include. This version integrates the department of defense dod cybersecurity maturity model cmmc version 1 0 standard into the hitrust csf and includes added language to the glossary to better clarify terms found in the framework.
The cybersecurity framework is for organizations of any size in any sector in the critical infrastructure that already have a mature cyber risk management and cybersecurity program that don t yet have a cyber risk management or cybersecurity program with a mission of helping keep up to date on managing risk and facing business or societal threats. Hitrust has launched a certification program for the nist cybersecurity framework that makes it easier for security teams to report on their implementation of the framework to upper management. Hitrust csf v9 4 overview. Advance the implementation of the cybersecurity framework in the sector and provide a forum for discussion of cybersecurity issues related to risk management among a wide variety of hph sector stakeholders.
The hitrust csf is a scalable and extensive security framework used to efficiently manage the regulatory compliance and risk management of organizations. This publication was developed in consultation with this sg. Hitrust believes these changes are consistent with the letter and intent of the president s executive order on improving critical infrastructure cybersecurity which is to help raise the bar for security and privacy protection in the private sector and improve the nation s resilience to ever increasing cybersecurity threats. As a result hitrust reviewed several cybersecurity related best practice frameworks including the sans 20 critical controls for cybersecurity.