Halfway through an r2 assessment, management asks to add six implemented systems to the scope of primary components. What would the assessor need to do within MyCSF?
How would you score implemented coverage for one system if two of four evaluative elements were in place?
If a requirement statement beginning with "The Privacy Officer..." scored a 50 instead of 42, would the overall assessment achieve certification?

Upon submission of an assessment object by the assessor, how many days does HITRUST take to either accept or reject the assessment?
Pre-populated default maturity level scores cannot be changed across an assessment object.
On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.
David, a member of an external assessor org, helped his client remediate a control gap. As part of the validation process David can then review the remediation for appropriateness. [0141]
An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor.
Sampling is generally not required when testing a manual control. [0055]
Is the HITRUST CSF a replacement standard for HIPAA or NIST 800-53?