Organizations can secure sensitive information through a shift to a more threat-adaptive approach, nested assessment levels, and better alignment with existing cybersecurity risks. New versions of the v11 framework keep adding new requirements and authoritative source mappings.
This HITRUST migration guide is designed to explain the most important changes, differences between HITRUST e1, i1, and r2 requirements, the migration process, and typical mistakes of migration to v11.
Key Takeaways
v11 includes e1, i1, and r2 evaluations.
E1 is the baseline security evaluation, and I1 adds another 182 controls for threats.
r2 takes i1 a step further by requiring risk-based controls.
MFA, Cloud computing, APIs, Ransomware, and Encryption need better controls.
Begin the migration process with a gap assessment, not a MyCSF assessment.
Gathering evidence continuously will help avoid any assessment gaps and delays.
Source: https://qualysec.com/hitrus ...