For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.
If an organization's relying party is requesting an Insights Report covering AI risks, which of the following factors should be added to an assessment?
Control Objectives are a statement of the desired result or purpose to be achieved by implementing control procedures into a particular process.
Where is an Offline Assessment initiated?
Is additional work required by the assessor to generate the NIST Cybersecurity Framework Report?