CSF v9.3 Summary of Changes PDF
CSF v9.3 Summary of Changes PDF
CSF v9.3 Summary of Changes PDF
3 Summary of Changes
Incorporates changes stemming from
the California Consumer Privacy Act,
the South Carolina Insurance Data Security Act,
and NIST SP 800-171 r2
October 2019
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or
utilized other than being shared as is in full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission.
October 2019
Fundamental to HITRUST’s mission is the availability of a common security and privacy framework, the
HITRUST CSF (“CSF”), which provides the needed structure, transparency, guidance and cross-references
to authoritative sources organizations globally need to be certain of their data protection compliance.
The initial development of the CSF leveraged nationally and internationally accepted security and privacy
related regulations, standards, and frameworks–including ISO, NIST, PCI, HIPAA, and COBIT–to ensure a
comprehensive set of security and privacy controls. The CSF standardizes these requirements, providing
clarity and consistency and reducing the burden of compliance.
HITRUST ensures the CSF stays relevant and current to the needs of organizations by regularly updating
the CSF to integrate and normalize applicable requirements and best practices as authoritative sources.
The HITRUST CSF v9.3 release includes changes based on feedback from the HITRUST community;
miscellaneous corrections; added language to the glossary to better clarify terms found in the
framework; and incorporation of regulatory requirements from the California Consumer Privacy Act
(CCPA), the South Carolina Insurance Data Security Act (SCIDSA), and NIST SP 800-171 r2 (DFARS). These
updates reflect HITRUST’s commitment to provide a framework fitting for any organization globally.
Minor administrative updates, such as the correction of grammar or formatting errors, are generally not
reflected in the Summary of Changes. Simple mapping updates from one version of a source to a newer
version, which do not impact existing content, are also generally not reflected.
The table below provides a summary of the changes to the CSF broken down by Control Specification and
Implementation Requirement Level.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be
reproduced or utilized other than being shared as is in full, in any form or by any means, electronical or mechanical, without HITRUST’s prior
written permission.
CSF Control Authoritative
Summary of Changes Remarks
Cntrl Level Source Cross-
Reference(s)
Added:
Added:
Annually, insurers are required to submit a written Necessitates new MyCSF requirement
00.a SCIDSA statement by the 15th of February, certifying SCIDSA 33-99-20(I) statement industry specific to SCIDSA
compliance with the South Carolina Insurance Data (011202.00aSCIDSAOrganizational.2)
Security Act and maintain all required records for a
period of five years.
Added:
Consistent with existing content
00.a 2 SCIDSA 33-99-20(G)
SCIDSA Cross Reference (0102.00a2Organizational.123)
Update:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 3
Update:
Added:
ISO/IEC 27799:2016 9.1.1 Consistent with existing content
01.a 2 ISO/IEC 27799:2016 9.1.2 (1104.01a2Organizational.123)
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.2.1
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.1.1
01.a 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.2.1 (1105.01a2Organizational.4)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 4
Added:
Consistent with existing content
NIST Cybersecurity
01.a 1 (1101.01a1Organizational.1245)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 PR:SC-6
Added:
Consistent with existing content
NIST Cybersecurity
01.a 1 (1103.01a1Organizational.67)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 PR.AC-6
Added:
Consistent with existing content
01.a 1 NIST SP 800-171 r2 3.1.1 (1101.01a1Organizational.1245)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.1
01.a 1 NIST SP 800-171 r2 Cross Reference (1103.01a1Organizational.67)
NIST SP 800-171 r2 3.1.2
Added:
Consistent with existing content
01.b 1 NIST SP 800-171 r2 3.1.1 (1106.01b1System.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.b 1 NIST SP 800-171 r2 3.1.2 (1139.01b1System.68)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 5
Updated:
The organization disables accounts of users posing a Updated requirement statement due to new CMS ARS 3.1
significant risk immediately, not to exceed 30 minutes CMSRs v3.1 AC-02(13) language
01.b CMS
within sixty (60) minutes of after discovery of the risk, (HIGH) (1141.01bCMSSystem.12)
and all disabled accounts are deleted during the
annual re-certification process.
Removed:
Removed segment and requirement; as language was removed in
CMSRs v3.1 AC-02(13) CMS ARS v3.1
01.b HIX Disabled accounts are deleted during the annual re- (HIGH) (1142.01bHIXSystem.1)
certification process.
Removed:
Added:
Consistent with existing content
01.c 1 ISO/IEC 27799:2016 9.2.3 (1143.01c1System.123)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.c 2 ISO/IEC 27799:2016 9.2.3 (1147.01c2System.456)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 6
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.1.1
01.c 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.2.3 (1148.01c2System.78)
Added:
Consistent with existing content
01.c 3 ISO/IEC 27799:2016 9.2.3 (1151.01c3System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
01.c 2 (1147.01c2System.456)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 PR.AC-6
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.2
01.c 1 (1143.01c1System.123)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.5
Added:
Consistent with existing content
01.c 1 NIST SP 800-171 r2 3.1.5 (1144.01c1System.4)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.5
01.c 2 (1148.01c2System.78)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.6
Added:
Consistent with existing content
01.c 2 NIST SP 800-171 r2 3.1.2 (1149.01c2System.9)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.5
01.c 3 (1151.01c3System.1)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.7
Added:
Consistent with existing content
01.c 3 NIST SP 800-171 r2 3.1.7 (1152.01c3System.2)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 7
Added:
Consistent with existing content
01.c 3 NIST SP 800-171 r2 3.4.6 (1153.01c3System.35)
NIST SP 800-171 r2 Cross Reference
Updated:
Updated:
Updated:
The organization authorizes network access to Updated requirement statement due to new CMS ARS 3.1
privileged commands only for defined compelling CMSRs v3.1 AC-06(03) language
01.c CMS
operational needs documented as defined in the (HIGH) (1156.01cCMSSystem.3)
system sSecurity pPlan and documents the rationale
for the information system.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 8
Updated:
11182.01cCISSystem.8
Updated:
11183.01cCISSystem.9
Updated:
11184.01cCISSystem.10
Updated:
If the operating environment allows, the organization Updated requirement statement due to new CMS ARS v3.1
requires at least six (6) characters to be changed. CMSRs v3.1 IA-05(01) language
01.d CMS
enforces a minimum of number of changed (HIGH)(MOD) (1031.01dCMSSystem.5)
characters when new passwords are created, set the
value at 12 for High and 6 for Moderate systems.
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.4.2
01.d 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.3 (1002.01d1System.1)
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.3.1
01.d 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.3 (1004.01d1System.8913)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 9
Added: Consistent with existing content
01.d 1 ISO/IEC 27799:2016 9.2.4 (1015.01d1System.14,
ISO/IEC 27799:2016 Cross Reference 1008.01d2System.3)
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.3.1
01.d 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.3 (1031.01d1System.34510)
Added:
Consistent with existing content
01.d 2 ISO/IEC 27799:2016 9.2.4 (1009.01d2System.4)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.5.10
01.d 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.5.11 (1005.01d1System.1011)
Added:
Consistent with existing content
01.d 1 NIST SP 800-171 r2 3.5.9 (1031.01d1System.34510)
NIST SP 800-171 r2 Cross Reference
Updated:
Updated:
1023.01dCISSystem.6
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 10
Updated:
1028.01dPCISystem.4
Added:
Consistent with existing content
01.e 1 ISO/IEC 27799:2016 9.2.5 (1166.01e1System.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.e 1 NIST SP 800-171 r2 3.9.2 (1166.01e1System.12)
NIST SP 800-171 r2 Cross Reference
Removed:
Removed segment and requirement; as requirement was
CMSRs 2013v2 AC-2 removed in CMS ARS 3.1
01.e CMS All information system accounts are reviewed to (HIGH) (1169.01eCMSSystem.1)
receive annual certification.
Updated:
11185.01eCISSystem.3
Updated:
11186.01eCISSystem.3
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 11
Added: Consistent with existing content
01.f 1 ISO/IEC 27799:2016 9.3.1 (1011.01f1Organizational.1,
ISO/IEC 27799:2016 Cross Reference 1020.01f1System.2)
Added:
Consistent with existing content
01.g 1 ISO/IEC 27799:2016 11.2.8 (0210.01g1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.h 1 ISO/IEC 27799:2016 11.2.9 (1114.01h1Organizational.123)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.h 1 ISO/IEC 27799:2016 8.2.3 (1115.01h1Organizational.45)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.h 1 NIST SP 800-171 r2 3.8.1 (1114.01h1Organizational.123)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.i 1 ISO/IEC 27799:2016 9.1.2 (0801.01i1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.i 2 ISO/IEC 27799:2019 9.1.2 (0802.01i2Organizational.123)
ISO/IEC 27799:2016 Cross Reference
Added:
NIST SP 800-171 r2 3.1.1 Consistent with existing content
01.i 2 NIST SP 800-171 r2 3.1.2 (0802.01i2Organizational.123)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.16
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.1
01.i 2
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.20 (0803.01i2Organizational.4)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 12
Added:
Consistent with existing content
01.i 2 NIST SP 800-171 r2 3.1.20 (0804.01i2Organizational.5)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.j HIX NIST SP 800-171 r2 3.1.12 (1188.01jHIXOrganizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.5.2
01.j 1 (1116.01j1Organizational.145)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.7.5
Added:
Consistent with existing content
01.j 1 NIST SP 800-171 r2 3.7.5 (1117.01j1Organizational.23)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.16
01.j 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.17 (1174.01j1Organizational.7)
Added:
Consistent with existing content
NIST SP 800-171 r2 3.5.1
01.j 1 (1175.01j1Organizational.8)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.5.2
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.13
01.j 3
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.15 (1121.01j3Organizational.2)
Added:
Consistent with existing content
01.j 3 NIST SP 800-171 r2 3.1.12 (1179.01j3Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.j 2 NIST SP 800-171 r2 3.1.13 (1118.01j2Organizational.124)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 13
Updated:
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 14
Updated:
1892.01l1Organizational.1
Added:
Consistent with existing content
01.m 1 ISO/IEC 27799:2016 13.1.3 (0805.01m1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.m 2 ISO/IEC 27799:2016 13.1.3 (0806.01m2Organizational.12356)
ISO/IEC 27799:2016 Cross Reference
Added:
NIST SP 800-171 r2 3.1.3 Consistent with existing content
01.m 1 NIST SP 800-171 r2 3.13.1 (0805.01m1Organizational.12)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.13.5
Added:
Consistent with existing content
01.m 2 NIST SP 800-171 r2 3.13.5 (0806.01m2Organizational.12356)
NIST SP 800-171 r2 Cross Reference
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 15
Updated:
The organization creates separate virtual local area Updated requirement statement due to new CIS CSC v7.1
networks (VLANs) for BYOD systems or other language
01.m CIS CIS CSC v7.1 15.10
untrusted devices (e.g., legacy devices). Enterprise (0897.01mCISOrganizational.10)
access from this network should be treated as
untrusted and filtered and audited accordingly.
Updated:
0893.01mCISOrganizational.4
Removed:
Removed requirement; as requirement was removed in CIS CSC
The organization operates critical services on v7.1
01.m CIS CIS CSC v6 9.5
separate physical or logical host machines, such as (0898.01m2Organizational.11)
DNS, file, mail, Web and database servers.
Updated:
0892.01mCISOrganizational.3
Updated:
0895.01mCISOrganizational.8
Updated:
0896.01mCISOrganizational.9
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 16
Updated:
0897.01mCISOrganizational.10
Added:
Consistent with existing content
01.n 1 NIST SP 800-171 r2 3.13.6 (0814.01n1Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.n 2 NIST SP 800-171 r2 3.1.14 (0809.01n2Organizational.1234)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.n 2 NIST SP 800-171 r2 3.13.8 (0810.01n2Organizational.5)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.n 2 NIST SP 800-171 r2 3.13.7 (0812.01n2Organizational.8)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.o 1 ISO/IEC 27799:2016 13.1.3 (0850.01o1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Removed:
Removed requirement; as requirement was re-written in CIS CSC
Internet access from virtual local area networks
01.o CIS CIS CSC v6 15.9 v7.1
(VLANs) for BYOD systems or other untrusted devices
(08100.01o2Organizational.5)
(e.g., legacy devices) goes through at least the same
border as corporate traffic.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 17
Updated:
Updated:
0899.01oCISOrganizational.4
Removed:
Removed segment and requirement; as requirement was made
01.p CMS CMSRs v3.1 AC-09 non-mandatory in CMS ARS v3.1
The information system notifies the user upon
(11106.01pCMSOrganizational.4)
successful logon (access) to the system of the date
and time of the last logon (access).
Updated:
Added:
Consistent with existing content
01.p 1 ISO/IEC 27799:2016 9.4.2 (11102.01p1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 18
Added:
Consistent with existing content
01.p 2 ISO/IEC 27799:2016 9.4.2 (11103.01p2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 7.2.2
01.p 3
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.2 (11104.01p3Organizational.13)
Added:
Consistent with existing content
ISO/IEC 27799:2016 7.2.2
01.p 3
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.2 (1312.01p3Organizational.2)
Added:
Consistent with existing content
01.p 1 NIST SP 800-171 r2 3.1.8 (11102.01p1Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.p 2 NIST SP 800-171 r2 3.1.8 (11103.01p2Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.p 3 NIST SP 800-171 r2 3.1.8 (11104.01p3Organizational.13)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.q 1 ISO/IEC 27799:2016 9.2.3 (1123.01q1System.2)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.q 1 ISO/IEC 27799:2016 9.2.1 (1124.01q1System.34)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 19
Added: Consistent with existing content
01.q 2 ISO/IEC 27799:2016 9.2.1 (1127.01q2System.3,
ISO/IEC 27799:2016 Cross Reference 1128.01q2System.5)
Added:
Consistent with existing content
NIST Cybersecurity
01.q CMS (11114.01qCMSOrganizational.12)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 PR.AC-7
Added:
Consistent with existing content
01.q 1 NIST SP 800-171 r2 3.5.5 (11109.01q1Organizational.57)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.5
01.q 1 (1123.01q1System.2)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.6
Added:
Consistent with existing content
01.q 3 NIST SP 800-171 r2 3.5.3 (11113.01q3Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 R2 3.5.2
01.q 2
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 R2 3.5.4 (11112.01q2Organizational.67)
Added:
Consistent with existing content
NIST SP 800-171 R2 3.5.1
01.q 2
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 R2 3.5.2 (1128.01q2System.5)
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 20
Updated:
11188.01qCISOrganizational.8
Updated:
11189.01qCISOrganizational.8
Updated:
1126.01qPCISystem.PCI
Added:
Consistent with existing content
ISO/IEC 27799:2016 9.2.4
01.r 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.4.3 (1012.01r1System.12345)
Added:
Consistent with existing content
01.r 2 ISO/IEC 27799:2016 9.4.3 (1013.01r2System.12345)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 R2 3.5.7
01.r 2
NIST SP 800-171 R2 Cross Reference NIST SP 800-171 R2 3.5.8 (1013.01r2System.12345)
Added:
Consistent with existing content
01.s 1 ISO/IEC 27799:2016 9.4.4 (11124.01s1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.s 2 ISO/IEC 27799:2016 9.4.4 (11125.01s2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 21
Updated:
For systems that are publicly positioned, A a time-out Requirement statement updated for clarity
01.t 2 system (e.g., a screen saver) pauses the session N/A (11127.01t2Organizational.1)
screen after two minutes of inactivity and closes
network sessions after 30 minutes of inactivity.
Added:
Consistent with existing content
01.t 1 ISO/IEC 27799:2016 9.4.2 (11126.01t1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.t 2 ISO/IEC 27799:2016 9.4.2 (11127.01t2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.10
01.t 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.11 (11126.01t1Organizational.12)
Added:
Consistent with existing content
01.t 2 NIST SP 800-171 r2 3.13.9 (11127.01t2Organizational.1)
NIST SP 800-171 r2 Cross Reference
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 22
Added:
Consistent with existing content
01.u 1 ISO/IEC 27799:2016 9.4.2 (11131.01u1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.v 1 ISO/IEC 27799:2016 9.4.1 (1129.01v1System.12)
ISO/IEC 27799:2016 Cross Reference
Added: Consistent with existing content
01.v 2 ISO/IEC 27799:2016 9.4.1 (1130.01v2System.1,
ISO/IEC 27799:2016 Cross Reference 1131.01v2System.2)
Added:
Consistent with existing content
NIST Cybersecurity
01.v 2 (1133.01v2System.4)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 PR.AC-7
Added:
Consistent with existing content
01.w 1 ISO/IEC 27799:2016 9.1.1 (08114.01wSRSystem.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.x HIX NIST SP 800-171 r2 3.1.18 (0414.01xHIXOrganizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.1.18
01.x 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.1.19 (0401.01x1System.124579)
Added:
Consistent with existing content
01.x 1 NIST SP 800-171 r2 3.1.18 (0403.01x1System.8)
NIST SP 800-171 r2 Cross Reference
Consistent with existing content
Added:
(0408.01y3Organizational.12
01.y 3 ISO/IEC 27799:2016 6.2.2 0409.01y3Organizational.3,
ISO/IEC 27799:2016 Cross Reference
0416.01y3Organizational.4)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 23
Added:
Consistent with existing content
01.y 1 ISO/IEC 27799:2016 6.2.2 (0405.01y1Organizational.12345678)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.y 1 ISO/IEC 27799:2016 6.2.1 (0415.01y1Organizational.10)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
01.y 1 NIST SP 800-171 r2 3.1.13 (0405.01y1Organizational.12345678)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.y 1 NIST SP 800-171 r2 3.10.6 (0415.01y1Organizational.10)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
01.y 2 NIST SP 800-171 r2 3.10.6 (0407.01y2Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.1.1
02.a 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 7.1.2 (0104.02a1Organizational.12)
Added:
Consistent with existing content
02.a 1 ISO/IEC 27799:2016 6.1.1 (0137.02a1Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
02.a 2 ISO/IEC 27799:2016 7.1.2 (0106.02a2Organizational.23)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 24
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 25
Added: Consistent with existing content
02.c 2 ISO/IEC 27799:2016 7.1.2 (0152.02c2Organizational.1,
ISO/IEC 27799:2016 Cross Reference 0153.02c2Organizational.23)
Updated:
0154.02cHIPAAOrganizational.4
Added:
Consistent with existing content
02.d 1 ISO/IEC 27799:2016 7.2.1 (0109.02d1Organizational.4)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
02.d 2 ISO/IEC 27799:2016 7.2.1 (0110.02d2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
02.e 1 ISO/IEC 27799:2016 7.2.2 (1301.02e1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added: Consistent with existing content
02.e 2 ISO/IEC 27799:2016 7.2.2 (1302.02e2Organizational.134,
ISO/IEC 27799:2016 Cross Reference 1315.02e2Organizational.67)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 26
Added:
Consistent with existing content
NIST SP 800-171 r2 3.2.1
02.e 1 (1301.02e1Organizational.12)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.2.2
Added:
Consistent with existing content
02.e 1 NIST SP 800-171 r2 3.6.1 (1313.02e1Organizational.3)
NIST SP 800-171 r2 Cross Reference
Added:
NIST SP 800-171 r2 3.2.1 Consistent with existing content
02.e 2 NIST SP 800-171 r2 3.2.2 (1302.02e2Organizational.134)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.2.3
Added:
Consistent with existing content
NIST SP 800-171 r2 3.2.1
02.e 3 (1304.02e3Organizational.1)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.2.2
Removed:
Removed:
Removed requirement; as requirement was removed in CIS CSC
The organization uses security skills assessments for
02.e CIS CIS CSC v6 17.5 v7.1
each of the mission-critical roles to identify skills gaps
(1330.02e2Organizational.11)
and hands-on, real-world examples to measure
mastery.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 27
Updated:
1328.02eCISOrganizational.9
Updated:
Added:
Consistent with existing content
02.f 2 ISO/IEC 27799:2016 7.2.3 (1503.02f2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
02.f 1 AICPA 2017 CC1.1 (1501.02f1Organizational.123)
AICPA 2017 Cross Reference
Added:
Consistent with existing content
02.g 1 ISO/IEC 27799:2016 9.2.6 (11143.02g1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
ISO/IEC 27799:2016 6.1.1 Consistent with existing content
02.g 1 ISO/IEC 27799:2016 7.3.1 (11144.02g1Organizational.234)
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 9.2.6
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 28
Consistent with existing content
Added:
(11143.02g1Organizational.1,
02.g 1 NIST SP 800-171 r2 3.9.2 11144.02g1Organizational.234,
NIST SP 800-171 r2 Cross Reference
11145.02g1Organizational.5)
Added:
Consistent with existing content
02.h 1 NIST SP 800-171 r2 3.9.2 (11152.02h1Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
02.i 2 ISO/IEC 27799:2016 9.2.6 (1136.02i2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added: Consistent with existing content
02.i 1 ISO/IEC 27799:2016 9.2.6 (11154.02i1Organizational.5,
ISO/IEC 27799:2016 Cross Reference 1135.02i1Organizational.1234)
Added:
Consistent with existing content
02.i 2 NIST SP 800-171 r2 3.9.2 (11155.02i2Organizational.2)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
03.a 1 (1701.03a1Organizational.12345678)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 ID.SC-2
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 29
Added:
Consistent with existing content
03.a 1 NIST SP 800-171 r2 3.11.1 (1701.03a1Organizational.12345678)
NIST SP 800-171 r2 Cross Reference
Added:
Removed:
Removed requirement; as requirement was made non-
The organization employs automated mechanisms to
CMSRs 2013v2 CA-5(1) mandatory in CMS ARS v3.1
03.b CMS help ensure that the Plan of Action and Milestones (HIGH) (1729.03cCMSOrganizational.1)
(POA&M) for the information system is accurate, up
to date, and readily available.
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.6.1
03.b 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 17.1.1 (1704.03b1Organizational.12)
Added:
Consistent with existing content
03.b 1 NIST SP 800-171 r2 3.11.1 (1704.03b1Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
03.b 2 NIST SP 800-171 r2 3.12.1 (1705.03b2Organizational.12)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 30
Updated:
1706.03bHIPAAOrganizational.3
Added:
ISO/IEC 27799:2016 12.6.1 Consistent with existing content
03.c 2 ISO/IEC 27799:2016 12.7.1 (1708.03c2Organizational.12)
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 17.1.1
Added:
Consistent with existing content
03.c 1 NIST SP 800-171 r2 3.12.2 (1707.03c1Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
03.c 2 NIST SP 800-171 r2 3.12.2 (1708.03c2Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
03.d 1 NIST SP 800-171 r2 3.11.1 (1733.03d1Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
04.a 1 ISO/IEC 27799:2016 5.1.1 (0113.04a1Organizational.123)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
04.b 1 ISO/IEC 27799:2016 5.1.2 (0114.04b1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 31
Added:
Consistent with existing content
04.b 3 ISO/IEC 27799:2016 5.1.2 (0116.04b3Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
04.b 2 ISO/IEC 27799:2016 5.1.2 (0115.04b2Organizational.123)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.a 1 ISO/IEC 27799:2016 5.1.1 (0119.05a1Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.a 3 ISO/IEC 27799:2016 18.2.1 (0125.05a3Organizational.2)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.a 3 ISO/IEC 27799:2016 5.1.1 (0165.05a3Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.a 3 NIST SP 800-171 r2 3.12.1 (0125.05a3Organizational.2)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.b 1 NIST SP 800-171 r2 3.12.4 (0126.05b1Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.b 2 NIST SP 800-171 r2 3.12.4 (0129.05b2Organizational.3)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.c 1 ISO/IEC 27799:2016 6.1.1 (0172.05c1Organizational.123)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 32
Added:
Consistent with existing content
05.c 2 ISO/IEC 27799:2016 6.1.3 (0175.05c2Organizational.67)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.c 3 ISO/IEC 27799:2016 6.1.1 (0176.05c3Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Removed:
Added:
Consistent with existing content
05.f 2 ISO/IEC 27799:2016 6.1.3 (1746.05f2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.1.3
05.f 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 6.1.6 (1747.05f2Organizational.23)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 33
Added:
Consistent with existing content
05.f 1 NIST SP 800-171 r2 3.6.1 (1744.05f1Organizational.23)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.f 2 NIST SP 800-171 r2 3.6.2 (1746.05f2Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.g 1 ISO/IEC 27799:2016 6.1.4 (1749.05g1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
05.g 2 (1751.05g2Organizational.23)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 RS.AN-5
Added:
Consistent with existing content
05.h 2 ISO/IEC 27799:2016 18.2.1 (0180.05h2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.12.1
05.h 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.12.3 (0177.05h1Organizational.12)
Added:
Consistent with existing content
05.h 2 NIST SP 800-171 r2 3.12.1 (0180.05h2Organizational.1)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 34
Added:
ISO/IEC 27799:2016 15.1.1 Consistent with existing content
05.i 1 ISO/IEC 27799:2016 15.1.2 (1401.05i1Organizational.1239)
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 15.1.3
Added:
Consistent with existing content
05.i 1 NIST SP 800-171 r2 3.1.13 (1402.05i1Organizational.45)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
05.j 2 ISO/IEC 27799:2016 14.1.2 (1424.05j2Organizational.5)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
05.j 2 NIST SP 800-171 r2 3.1.9 (1423.05j2Organizational.4)
NIST SP 800-171 r2 Cross Reference
Updated:
1420.05jHIPAAOrganizational.34
Added:
ISO/IEC 27799:2016 15.1.1 Consistent with existing content
05.k 1 ISO/IEC 27799:2016 15.1.2 (1428.05k1Organizational.2)
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 15.1.3
Added:
Consistent with existing content
ISO/IEC 27799:2016 15.1.2
05.k 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 15.1.3 (1429.05k1Organizational.34)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 35
Added:
Consistent with existing content
05.k 1 ISO/IEC 27799:2016 15.1.2 (1430.05k1Organizational.56)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
05.k 2 (1407.05k2Organizational.1)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 ID.SC-1
Added:
Consistent with existing content
ISO/IEC 27799:2016 7.2.2
06.a 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 18.1.1 (0181.06a1Organizational.12)
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.1.4
06.a 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 18.1.1 (0182.06a2Organizational.12)
Added:
Consistent with existing content
06.b 1 ISO/IEC 27799:2016 18.1.2 (19135.06b1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.b 2 ISO/IEC 27799:2016 18.1.2 (19136.06b2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.c 1 ISO/IEC 27799:2016 8.2.1 (19143.06c1Organizational.9)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 36
Updated:
Updated requirement statement for clarity
06.c HIPAA If retained, the organization ensures PHI individually HIPAA § 160.103 (1905.06cHIPAAOrganizational.6)
identifiable information is safeguarded for a period of
50 years following the date of death of the individual.
Updated:
Updated:
1908.06c1Organizational.4
Added:
Consistent with existing content
06.d 2 ISO/IEC 27799:2016 18.1.3 (1904.06d2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2
06.d 1 (1903.06d1Organizational.3456711)
NIST SP 800-171 r2 Cross Reference 3.13.16
Updated:
19244.06dCISOrganizational.16
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 37
Added:
Consistent with existing content
06.e 2 NIST SP 800-171 r2 3.1.9 (1138.06e2Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 18.1.1
06.f 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 18.1.2 (19162.06f1Organizational.12)
Added:
Consistent with existing content
06.f 2 ISO/IEC 27799:2016 18.1.5 (19163.06f2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 18.2.2
06.g 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 18.2.3 (0601.06g1Organizational.124)
Added:
Consistent with existing content
06.g 1 ISO/IEC 27799:2016 18.2.2 (0602.06g1Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.g 2 ISO/IEC 27799:2016 18.2.3 (0603.06g2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.g 2 ISO/IEC 27799:2016 18.2.2 (069.06g2Organizational.56)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.g 2 NIST SP 800-171 r2 3.12.3 (0604.06g2Organizational.2)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 18.2.2
06.h 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 18.2.3 (0613.06h1Organizational.12)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 38
Added:
Consistent with existing content
06.h 2 ISO/IEC 27799:2016 18.2.3 (0614.06h2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Updated:
Removed:
Removed requirement; as requirement was removed in CIS CSC
The organization verifies that all authentication files v7.1
06.h CIS CIS CSC v6 16.14
are encrypted or hashed and cannot be accessed (0658.06h1Organizational.3)
without root or administrator privileges.
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 39
Updated:
0659.06hCISOrganizational.4
Updated:
0660.06hCISOrganizational.5
Updated:
0661.06hCISOrganizational.6
Added:
Consistent with existing content
06.i 1 ISO/IEC 27799:2016 12.7.1 (1754.06i1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.i 2 ISO/IEC 27799:2016 12.7.1 (1756.06i2Organizational.2)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.j 2 ISO/IEC 27799:2016 12.7.1 (1238.06j2Organizational.45)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
06.j 1 NIST SP 800-171 r2 3.3.8 (1235.06j1Organizational.1)
NIST SP 800-171 r2 Cross Reference
Added: Consistent with existing content
06.j 2 NIST SP 800-171 r2 3.3.9 (1236.06j2Organizational.1,
NIST SP 800-171 r2 Cross Reference 1237.06j2Organizational.23)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 40
Added:
Consistent with existing content
07.a 2 ISO/IEC 27799:2016 8.1.1 (0703.07a2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Removed:
Removed requirement; as requirement was removed in CIS CSC
The organization updates its asset inventories
07.a CIS CIS CSC v6 1.3 v7.1
whenever changes to assets occur and new devices
(0759.07a1Organizational.9)
are acquired and approved for connection to the
network.
Updated:
Update:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 41
Updated:
0760.07aCISOrganizational.10
Updated:
0761.07aCISOrganizational.2
Updated:
0762.07aCISOrganizational.6
Consistent with existing content
Added:
(0184.07b2Organizational.1,
07.b 2 ISO/IEC 27799:2016 8.1.2 0185.07b2Organizational.24,
ISO/IEC 27799:2016 Cross Reference
0187.07b2Organizational.5,
0188.07b2Organizational.6)
Added: Consistent with existing content
07.c 1 ISO/IEC 27799:2016 8.1.3 (1307.07c1Organizational.124,
ISO/IEC 27799:2016 Cross Reference 1324.07c1Organizational.3)
Added:
Consistent with existing content
07.d 3 ISO/IEC 27799:2016 8.2.1 (1767.07d3Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 8.1.2
07.d 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 8.2.1 (1758.07d2Organizational.125)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 42
Added:
Consistent with existing content
07.d 2 ISO/IEC 27799:2016 8.2.1 (1759.07d2Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 8.1.1
07.d 2
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 8.1.2 (1762.07d2Organizational.78)
Added:
Consistent with existing content
07.d 2 ISO/IEC 27799:2016 8.2.1 (1765.07d2Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
07.e 2 ISO/IEC 27799:2016 16.1.7 (19170.07e2Organizational.4)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 43
Added:
Consistent with existing content
07.e 3 NIST SP 800-171 r2 3.1.9 (19173.07e3Organizational.3)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
07.e 2 NIST SP 800-171 r2 3.8.4 (19168.07e2Organizational.2)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 11.1.1
08.a 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 11.2.6 (1828.08a1Organizational.12)
Added:
Consistent with existing content
08.a 1 ISO/IEC 27799:2016 11.1.1 (1829.08a1Organizational.34)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 44
Consistent with existing content
(1804.08b2Organizational.12,
1805.08b2Organizational.3,
Added:
1806.08b2Organizational.4,
08.b 2 ISO/IEC 27799:2016 11.1.2 1807.08b2Organizational.56,
ISO/IEC 27799:2016 Cross Reference
1808.08b2Organizational.7,
1846.08b2Organizational.8,
1848.08b2Organizational.11)
Added:
Consistent with existing content
08.b 1 NIST SP 800-171 r2 3.10.3 (1801.08b1Organizational.124)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
08.b 1 NIST SP 800-171 r2 3.10.1 (1844.08b1Organizational.6)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
08.b 1 NIST SP 800-171 r2 3.10.4 (1845.08b1Organizational.7)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
08.b 2 NIST SP 800-171 r2 3.10.4 (1806.08b2Organizational.4)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 45
Updated:
18104.08bHIXOrganizational.1
Added:
Consistent with existing content
08.c 1 ISO/IEC 27799:2016 11.1.3 (1857.08c1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Updated:
Updated to the highest level
NIST SP 800-53 R4 PE-
08.d 3 Fire authorities are automatically notified when a fire (1862.08d3Organizational.3)
13(1)
alarm is activated.
Updated:
1862.08d3Organizational.3
Consistent with existing content
Added:
(1867.08e1Organizational.12,
08.e 1 ISO/IEC 27799:2016 11.1.5 1868.08e1Organizational.34,
ISO/IEC 27799:2016 Cross Reference
1869.08e1Organizational.5)
Consistent with existing content
Added:
(1871.08f1Organizational.13,
08.f 1 ISO/IEC 27799:2016 11.1.6 1872.08f1Organizational.2,
ISO/IEC 27799:2016 Cross Reference
1873.08f1Organizational.45)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 46
Added:
Consistent with existing content
08.f 2 ISO/IEC 27799:2016 11.1.6 (1874.08f2Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 11.1.4
08.g 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 11.2.1 (1881.08g1Organizational.789)
Added:
Consistent with existing content
08.h 2 ISO/IEC 27799:2016 11.2.4 (1895.08h2Organizational.8)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
08.h 3 ISO/IEC 27799:2016 11.2.2 (1896.08h3Organizational.1)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 47
Consistent with existing content
Added: (1886.08h1Organizational.12,
08.h 1 ISO/IEC 27799:2016 11.2.2 1887.08h1Organizational.3,
ISO/IEC 27799:2016 Cross Reference 1888.08h1Organizational.456,
1889.08h1Organizational.7)
Added:
Consistent with existing content
08.i 3 ISO/IEC 27799:2016 11.2.3 (18106.08i3Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.10.1
08.i 2
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.10.2 (18105.08i2Organizational.78)
Added:
Consistent with existing content
08.j 1 ISO/IEC 27799:2016 11.2.4 (1819.08j1Organizational.23)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 48
Consistent with existing content
Added:
(1820.08j2Organizational.1,
08.j 2 ISO/IEC 27799:2016 11.2.4 1821.08j2Organizational.3,
ISO/IEC 27799:2016 Cross Reference
1822.08j2Organizational.2)
Added:
Consistent with existing content
08.j 1 NIST SP 800-171 r2 3.7.6 (18109.08j1Organizational.4)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.7.1
08.j 2 (1820.08j2Organizational.1)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.7.3
Added:
Consistent with existing content
08.j 3 NIST SP 800-171 r2 3.7.2 (1823.08j3Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.7.2
08.j 3 (1824.08j3Organizational.3)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.7.4
Added:
Consistent with existing content
08.k 1 ISO/IEC 27799:2016 11.2.6 (18122.08k1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.2.1
08.k 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 11.2.6 (18123.08k1Organizational.234)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 49
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.2.2
08.k 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 11.2.6 (18124.08k1Organizational.5)
Added:
Consistent with existing content
ISO/IEC 27799:2016 6.2
08.k 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 11.2.6 (18125.08k1Organizational.6)
Added:
Consistent with existing content
08.k 1 ISO/IEC 27799:2016 11.2.6 (18126.08k1Organizational.7)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
08.k 1 NIST SP 800-171 r2 3.10.6 (18124.08k1Organizational.5)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
08.l 1 NIST SP 800-171 r2 3.8.3 (1825.08l1Organizational.12456)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
08.m 1 NIST SP 800-171 r2 3.7.1 (18128.08m1Organizational.12)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 50
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.4.1
09.aa 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.4.2 (1202.09aa1System.1)
Added:
Consistent with existing content
09.aa 1 ISO/IEC 27799:2016 12.4.1 (1203.09aa1System.2)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.4.1
09.aa 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.4.3 (1204.09aa1System.3)
Added:
Consistent with existing content
09.aa 2 ISO/IEC 27799:2016 12.4.2 (1207.09aa2System.4)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
09.aa 2 (1206.09aa2System.23)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 ID.SC-4
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 51
Added: Consistent with existing content
NIST SP 800-171 r2 3.3.1 (1203.09aa1System.2,
09.aa 1
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.3.2 1204.09aa1System.3)
Added:
Consistent with existing content
09.aa 3 NIST SP 800-171 r2 3.3.1 (1208.09aa3System.1)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 r2 3.3.1
09.aa 3 (1209.09aa3System.2)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.3.2
Added:
NIST SP 800-171 r2 3.3.1 Consistent with existing content
09.aa 2 NIST SP 800-171 r2 3.3.2 (1206.09aa2System.23)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.3.4
Added:
Necessitates new MyCSF requirement
All records concerning cybersecurity events are statement industry specific to SCIDSA
09.aa SCIDSA SCIDSA 38-99-30(D)
maintained for at least five years from the date of the (121204.09aaSCIDSAOrganizational.1)
event and be available for inspection.
Update:
Systems record logs in a standardized format such as
syslog entries or those outlined by the Common Event
Expression initiative. If systems cannot generate logs in
a standardized format, the organization deploys log Updated requirement statement due to new CIS CSC v7.1
normalization tools to convert logs into such a format. language
09.aa CIS CIS CSC v7.1 6.3
(1281.09aaCISSystem.10)
The organization enables system logging to include
detailed information such as an event source, date,
user, timestamp, source addresses, destination
addresses, and other useful elements.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 52
Updated:
Updated:
1281.09aaCISSystem.10
Updated:
1282.09aaCISSystem.11
Updated:
1284.09abCISSystem.2
Updated:
1286.09abCISSystem.11
Updated:
1285.09abCISSystem.10
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 53
Updated:
1287.09abCISSystem.12
Updated:
1288.09abCISSystem.13
Updated:
1289.09abCISSystem.14
Updated:
1291.09abCISSystem.14
Updated:
1292.09abCISSystem.15
Updated:
1293.09abCISSystem.16
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 54
Removed:
The organization interconnects and configures CMSRs 2013v2 SI-4(1) Removed requirement; as requirements were made non-
individual intrusion detection tools into a system- (HIGH) mandatory in CMS ARS v3.1
09.ab CMS
wide intrusion detection system (IDS) and employs CMSRs 2013v2 SI-4(3) (11161.09abCMSSystem.34)
automated tools to integrate intrusion detection (HIGH)
tools into access control and flow control
mechanisms.
Added:
Consistent with existing content
09.ab 2 ISO/IEC 27799:2016 12.4.1 (1214.09ab2System.3456)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.ab 2 NIST SP 800-171 r2 3.3.3 (1213.09ab2System.128)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
09.ab 2 NIST SP 800-171 r2 3.3.1 (1214.09ab2System.3456)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
09.ab 2 NIST SP 800-171 r2 3.3.6 (1215.09ab2System.7)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
09.ab 3 NIST SP 800-171 r2 3.3.5 (1222.09ab3System.8)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 55
Removed:
Updated:
1294.09acCISSystem.4
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.4.2
09.ac 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.4.3 (1223.09ac1System.1)
Updated:
Updated requirement statement due to language change in CIS
Audit logs are archived and digitally signed on a
09.ac CIS CIS CSC v7.1 6.4 CSC v7.1
periodic basis. The organization ensures that all
(1294.09acCISSystem.4)
systems that store logs have adequate storage space
for the logs generated.
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.4.1
09.ad 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.4.3 (1270.09ad1System.12)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 56
Added:
Consistent with existing content
09.ad 1 ISO/IEC 27799:2016 12.4.3 (1271.09ad1System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
09.ad 1 (1270.09ad1System.12)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 ID.SC-4
Added:
NIST SP 800-171 r2 3.3.1 Consistent with existing content
09.ad 1 NIST SP 800-171 r2 3.3.2 (1270.09ad1System.12)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.3.3
Added:
Consistent with existing content
09.af 1 ISO/IEC 27799:2016 12.4.4 (1226.09af1System.1234)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.af 1 NIST SP 800-171 r2 3.3.7 (1226.09af1System.1234)
NIST SP 800-171 r2 Cross Reference
Updated:
1295.09afCISSystem.2
Added:
Consistent with existing content
09.b 1 ISO/IEC 27799:2016 12.1.2 (0618.09b1System.1)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 57
Added:
Consistent with existing content
NIST SP 800-171 r2 3.4.4
09.b 2 (0619.09b2System.12)
NIST SP 800-171 r2 Cross Reference NIST SP 800-171 r2 3.4.5
Added:
Consistent with existing content
09.c 1 ISO/IEC 27799:2016 6.1.2 (1229.09c1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.c 3 NIST SP 800-171 r2 3.1.4 (1232.09c3Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.1.2
09.d 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.1.4 (0621.09d1System.12)
Added:
Consistent with existing content
09.d 2 ISO/IEC 27799:2016 12.1.4 (0622.09d2System.1)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 58
Added:
Consistent with existing content
09.e 1 ISO/IEC 27799:2016 15.1.1 (1408.09e1System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.e 2 ISO/IEC 27799:2016 15.2.1 (1410.09e2System.23)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.f 1 ISO/IEC 27799:2016 15.2.1 (1411.09f1System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.f 2 ISO/IEC 27799:2016 15.2.1 (1412.09f2System.12)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.f 2 ISO/IEC 27799:2016 13.1.2 (1413.09f2System.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.f 2 ISO/IEC 27799:2016 15.2.1 (1442.09f2System.456)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.g 1 ISO/IEC 27799:2016 15.2.2 (1414.09g1System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.g 2 ISO/IEC 27799:2016 15.2.2 (1415.09g2System.12)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 59
Added:
Consistent with existing content
09.h 2 ISO/IEC 27799:2016 12.1.3 (1612.09h2System.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 14.2.2
09.i 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 14.2.9 (1769.09i1System.12)
Added:
Consistent with existing content
09.i 2 ISO/IEC 27799:2016 14.2.9 (1771.09i2System.24)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
ISO/IEC 27799:2016 12.2.1
09.j 1
ISO/IEC 27799:2016 Cross Reference ISO/IEC 27799:2016 12.6.2 (1308.09j1Organizational.5)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 60
Added:
Consistent with existing content
09.j 1 NIST SP 800-171 r2 3.4.9 (1308.09j1Organizational.5)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
09.j 2 NIST SP 800-171 r2 3.13.3 (0208.09j2Organizational.7)
NIST SP 800-171 r2 Cross Reference
Removed:
The organization uses network-based anti-malware Removed requirement; as requirement was removed in CIS CSC
09.j CIS tools to identify executables in all network traffic and CSI CSC v6 8.5 v7.1
uses techniques other than signature-based detection (0233.09j2Organizational.14)
to identify and filter out malicious content before it
arrives at the endpoint.
Updated:
0231.09jCISOrganizational.7
Updated:
0232.09jCISOrganizational.13
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 61
Removed:
CMSRs 2013v2 SC-3(2)
Security functions enforcing access and information (HIGH)
flow control are compartmentalized and isolated CMSRs 2013v2 SC-3(3) Removed segment and requirement; as requirements were made
from each other and from non-security functions in a (HIGH) non-mandatory in CMS ARS v3.1
09.k CMS
layered structure to minimize interactions between CMSRs 2013v2 SC-3(4) (0230.09kCMSOrganizational.245)
layers of the design and avoid any dependence by (HIGH)
lower layers on the functionality or correctness of CMSRs 2013v2 SC-3(5)
higher layers. (HIGH)
Added:
Consistent with existing content
09.k 1 ISO/IEC 27799:2016 12.2.1 (0225.09k1Organizational.1)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
09.k 2 ISO/IEC 27799:2016 12.5.1 (0228.09k2Organizational.3)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST SP 800-171 R2
09.k 1 (0225.09k1Organizational.1)
NIST SP 800-171 r2 Cross Reference 3.13.13
Added:
Consistent with existing content
NIST SP 800-171 R2
09.k 2 (0227.09k2Organizational.12)
NIST SP 800-171 r2 Cross Reference 3.13.13
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 62
Consistent with existing content
Added: (1624.09l3Organizational.12,
1625.09l3Organizational.34,
09.l 3 ISO/IEC 27799:2016 12.3.1
ISO/IEC 27799:2016 Cross Reference 1626.09l3Organizational.5,
1627.09l3Organizational.6)
Added:
Consistent with existing content
09.l 1 ISO/IEC 27799:2016 15.2 (1620.09l1Organizational.8)
ISO/IEC 27799:2016 Cross Reference
Added:
Consistent with existing content
NIST Cybersecurity
09.l 1 (1616.09l1Organizational.16)
NIST Cybersecurity Framework v1.1 Cross Reference Framework v1.1 ID.SC-5
Added:
Consistent with existing content
09.l 2 NIST SP 800-171 R2 3.8.9 (1622.09l2Organizational.23)
NIST SP 800-171 r2 Cross Reference
Added:
Consistent with existing content
09.l 1 NIST SP 800-171 R2 3.8.1 (1618.09l1Organizational.45)
NIST SP 800-171 r2 Cross Reference
Removed:
Removed requirement; as requirement was revised in CIS CSC
Multiple backups are retained over time, so that in
09.l CIS CIS CSC v6 10.1 v7.1
the event of malware infection, restoration can be
(1687.09l1Organizational.9)
made from a version that is believed to predate the
original infection.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 63
Updated:
Updated:
1688.09lCISOrganizational.5
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 64
Added: Consistent with existing content
09.m 2 ISO/IEC 27799:2016 13.1.3 (0504.09m2Organizational.5,
ISO/IEC 27799:2016 Cross Reference 0820.09m2Organizational.1)
Added:
Consistent with existing content
09.m 2 ISO/IEC 27799:2016 13.1.2
(0863.09m2Organizational.910)
ISO/IEC 27799:2016 Cross Reference
Added:
ISO/IEC 27799:2016 13.1.1 Consistent with existing content
09.m 3
ISO/IEC 27799:2016 13.1.3 (0825.09m3Organizational.23)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 65
Added:
NIST SP 800-171 r2 3.1.16 Consistent with existing content
09.m 1
NIST SP 800-171 r2 3.1.17 (0502.09m1Organizational.5)
NIST SP 800-171 r2 Cross Reference
Added:
09.m 2 NIST SP 800-171 r2 3.13.6 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0504.09m2Organizational.5)
Added:
09.m 2 NIST SP 800-171 r2 3.13.14 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0864.09m2Organizational.12)
Added:
09.m 2 NIST SP 800-171 r2 3.13.6 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0865.09m2Organizational.13)
Added:
NIST SP 800-171 r2 3.13.8 Consistent with existing content
09.m 2
NIST SP 800-171 r2 3.13.11 (099.09m2Organizational.11)
NIST SP 800-171 r2 Cross Reference
Added:
09.m 3 NIST SP 800-171 r2 3.1.17 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0827.09m3Organizational.6)
Added:
09.m 3 NIST SP 800-171 r2 3.13.5 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0830.09m3Organizational.1012)
Added:
09.m 3 NIST SP 800-171 r2 3.13.6 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0870.09m3Organizational.20)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 66
Updated:
In addition to URL filtering, The organization denies Updated requirement statement due to new CIS CSC v7.1
09.m CIS CIS CSC v7.1 12.3 language
communications with known malicious or unused IP
addresses (blacklists), or and limits access only to (0958.09mCISOrganizational.16)
trusted sites (whitelists).
Updated:
0506.09mCISOrganizational.10
Updated:
08102.09mCISOrganizational.22
Updated:
0957.09mCISOrganizational.15
Updated:
0958.09mCISOrganizational.16
Updated:
0959.09mCISOrganizational.17
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 67
Added:
09.n 1 ISO/IEC 27799:2016 13.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0835.09n1Organizational.1)
Added:
NIST Cybersecurity Consistent with existing content
09.n 1
Framework v1.1 ID.SC-1 (0835.09n1Organizational.1)
NIST Cybersecurity Framework v1.1 Cross Reference
Added:
NIST Cybersecurity Consistent with existing content
09.n 2
Framework v1.1 ID.SC-3 (0888.09n2Organizational.6)
NIST Cybersecurity Framework v1.1 Cross Reference
Removed:
CMSRs 2013v2 MP-5(3) Removed requirement; as requirements were made non-
09.o CMS mandatory in CMS ARS v3.1
The organization employs an identified custodian during (HIGH)
transport of CMS information system media. (0310.09oCMSOrganizational.1)
Added:
09.o 2 ISO/IEC 27799:2016 8.3.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0302.09o2Organizational.1)
Added:
09.o 3 ISO/IEC 27799:2016 8.3.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0304.09o3Organizational.1)
Added:
09.o 1 ISO/IEC 27799:2016 8.3.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0301.09o1Organizational.123)
Added:
09.o 2 NIST SP 800-171 r2 3.8.5 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0302.09o2Organizational.1)
Added:
09.o 3 NIST SP 800-171 r2 3.8.7 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0304.09o3Organizational.1)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 68
Added:
09.o 1 NIST SP 800-171 r2 3.8.1 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0301.09o1Organizational.123)
Updated:
Updated:
The organization employs an approved method of Updated requirement statement due to new CMS ARS 3.1
CMSRs v3.1 MP-04 (HIGH;
09.o CMS cryptography to protect PII at rest, consistent with NIST language
MOD)
SP 800-66 guidance and, If PII is recorded on magnetic (19177.09oCMSOrganizational.4)
media with other data, it is protected as if it were
entirely personally identifiable information.
Updated:
0330.09oCISOrganizational.2
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 69
Added:
09.p 2 ISO/IEC 27799:2016 8.3.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1827.09p2Organizational.1)
Added:
09.p 1 NIST SP 800-171 r2 3.8.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (18130.09p1Organizational.24)
Added:
09.q 1 ISO/IEC 27799:2016 8.2.3 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0305.09q1Organizational.12)
Added:
09.q 2 ISO/IEC 27799:2016 8.2.3 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0307.09q2Organizational.12)
Added:
NIST SP 800-171 R2 3.8.1 Consistent with existing content
09.q 1
NIST SP 800-171 R2 3.8.4 (0305.09q1Organizational.12)
NIST SP 800-171 r2 Cross Reference
Added:
09.q 2 NIST SP 800-171 r2 3.8.5 Consistent with existing content
NIST SP 800-171 R2 Cross Reference (0307.09q2Organizational.12)
Added:
NIST SP 800-171 r2 3.8.5 Consistent with existing content
09.q 3
NIST SP 800-171 r2 3.8.6 (0314.09q3Organizational.2)
NIST SP 800-171 r2 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 70
Added:
09.s 1 NIST SP 800-171 r2 3.1.20 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0911.09s1Organizational.2)
Added:
09.s 1 NIST SP 800-171 r2 3.1.13 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0912.09s1Organizational.4)
Added:
09.s 1 NIST SP 800-171 r2 3.13.8 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0913.09s1Organizational.5)
Added:
09.s 2 NIST SP 800-171 r2 3.1.20 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0902.09s2Organizational.13)
Added:
NIST SP 800-171 r2 3.1.20 Consistent with existing content
09.s 2
NIST SP 800-171 r2 3.1.21 (0915.09s2Organizational.2)
NIST SP 800-171 r2 Cross Reference
Added:
09.s 2 NIST SP 800-171 r2 3.13.12 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0916.09s2Organizational.4)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 71
Removed:
Added:
09.u 1 NIST SP 800-171 r2 3.8.5 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0320.09u1Organizational.1)
Added:
09.v 1 NIST SP 800-171 r2 3.13.8 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0928.09v1Organizational.45)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 72
Added:
09.w 2 ISO/IEC 27799:2016 13.1.3 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0935.09w2Organizational.3)
Added:
NIST SP 800-171 r2 3.4.1 Consistent with existing content
09.w 2
NIST SP 800-171 r2 3.4.2 (0936.09w2Organizational.4)
NIST SP 800-171 r2 Cross Reference
Added:
09.y 1 NIST SP 800-171 r2 3.13.8 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0945.09y1Organizational.3)
Added:
09.z 3 ISO/IEC 27799:2016 14.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (19184.09z3Organizational.12)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 73
Added:
NIST Cybersecurity Consistent with existing content
09.z 3
Framework v1.1 PR.DS-8 (19184.09z3Organizational.12)
NIST Cybersecurity Framework v1.1 Cross Reference
Updated:
Added:
10.a 2 ISO/IEC 27799:2016 14.2.6 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1788.10a2Organizational.2)
Added:
10.a 2 ISO/IEC 27799:2016 14.2.5 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1789.10a2Organizational.3)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 74
Added:
10.a 2 ISO/IEC 27799:2016 17.2.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1790.10a2Organizational.45)
Added:
ISO/IEC 27799:2016 14.1.1 Consistent with existing content
10.a 2
ISO/IEC 27799:2016 14.2.1 (1793.10a2Organizational.91011)
ISO/IEC 27799:2016 Cross Reference
Added:
10.a 2 NIST SP 800-171 r2 3.13.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1789.10a2Organizational.3)
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 75
Updated:
Updated:
0763.10bCISSystem.5
Updated:
0764.10bCISSystem.6
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 76
Updated:
Added:
NIST Cybersecurity Consistent with existing content
10.c 2
Framework v1.1 PR.DS-8 (0625.10c2System.8)
NIST Cybersecurity Framework v1.1 Cross Reference
Added:
10.e 1 ISO/IEC 27799:2016 14.2.5 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (19199.10e1System.12)
Added:
10.e 2 ISO/IEC 27799:2016 14.2.5 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (19200.10e2System.1)
Added:
10.f 2 ISO/IEC 27799:2016 10.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0904.10f2Organizational.1)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 77
Added:
10.f 1 ISO/IEC 27799:2016 10.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0903.10f1Organizational.1)
Updated:
Title 21 CFR
10.f 0963.10f21CFRPart11Organizational.1 N/A Updated BUID
Part 11
0963.10fCFRPart11Organizational.1
Added:
10.g 1 ISO/IEC 27799:2016 10.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0905.10g1Organizational.12)
Added:
10.g 2 NIST SP 800-171 r2 3.13.10 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0906.10g2Organizational.13)
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 78
Added: Consistent with existing content
10.h 1 ISO/IEC 27799:2016 12.5.1 (0605.10h1System.12,
ISO/IEC 27799:2016 Cross Reference 0626.10h1System.3,
0627.10h1System.45)
Added:
NIST SP 800-171 r2 3.4.1 Consistent with existing content
10.h 1
NIST SP 800-171 r2 3.4.2 (0627.10h1System.45)
NIST SP 800-171 r2 Cross Reference
Updated:
The organization ensures that only authorized limits the Updated requirement statement due to new CIS CSC v7.1
10.h CIS use of unnecessary scripting languages are able to run in CIS CSC v7.1 7.3 language
all web browsers and email clients. This includes the use (0665.10hCISSystem.8)
of languages such as ActiveX and JavaScript on systems
where it is unnecessary to support such capabilities.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 79
Updated:
The organization's maintains an up-to-date list of Updated requirement statement due to new CIS CSC v7.1
10.h CIS authorized software and version (whitelist) that is CIS CSC v7.1 2.1 language
required in the enterprise for any business purpose on (0666.10hCISSystem.1)
any business system. is monitored by file integrity
checking tools to validate the list has not been modified.
Removed:
Updated:
0664.10hCISSystem.7
Updated:
0665.10hCISSystem.8
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 80
Updated:
0666.10hCISSystem.1
Updated:
0667.10hCISSystem.2
Added: Consistent with existing content
10.i 1 ISO/IEC 27799:2016 14.3.1 (19204.10i1System.1,
ISO/IEC 27799:2016 Cross Reference 19205.10i1System.2)
Added:
Consistent with existing content
10.i 2 ISO/IEC 27799:2016 14.3.1
(19206.10i2System.1,
ISO/IEC 27799:2016 Cross Reference
19207.10i2System.2)
Removed:
For in-house developed applications, the organization Removed segment and requirement; as requirement was
10.i CIS ensures that development artifacts (sample data and CIS CSC v6 18.9 removed in CIS CSC v7.1
scripts; unused libraries, components, debug code; or (19247.10i2Organizational.3)
tools) are not included in the deployed software, or
accessible in the production environment.
Added:
10.j 1 ISO/IEC 27799:2016 9.4.5 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0633.10j1System.1)
Added:
10.j 2 ISO/IEC 27799:2016 9.4.5 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0634.10j2System.12)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 81
Update:
Updated:
The organization reviews information system changes Updated requirement statement due to new CMS ARS v3.1
CMSRs v3.1 CM-05(02)
10.k CMS weekly and when indications so warrant, to determine language
(HIGH)
whether unauthorized changes may have occurred. (0648.10kCMSOrganizational.5)
unauthorized changes or unexpected levels of system
performance are indicated.
Added:
ISO/IEC 27799:2016 14.2.3 Consistent with existing content
10.k 1
ISO/IEC 27799:2016 14.2.6 (0635.10k1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 82
Added:
10.k 2 ISO/IEC 27799:2016 14.2.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0636.10k2Organizational.1)
Added:
ISO/IEC 27799:2016 14.2.2 Consistent with existing content
10.k 2
ISO/IEC 27799:2016 14.2.4 (0637.10k2Organizational.2,
ISO/IEC 27799:2016 Cross Reference 0638.10k2Organizational.34569)
Added:
ISO/IEC 27799:2016 14.2.2 Consistent with existing content
10.k 2
ISO/IEC 27799:2016 14.2.7 (0640.10k2Organizational.1012)
ISO/IEC 27799:2016 Cross Reference
Added:
10.k 2 ISO/IEC 27799:2016 14.2.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0641.10k2Organizational.11)
Added:
NIST SP 800-171 r2 3.4.3 Consistent with existing content
10.k 2
NIST SP 800-171 r2 3.4.5 (0638.10k2Organizational.34569)
NIST SP 800-171 r2 Cross Reference
0673.10kCISSystem.6
Removed:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 83
Added:
10.l 1 ISO/IEC 27799:2016 14.2.7 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1416.10l1Organizational.1)
Added:
10.l 2 ISO/IEC 27799:2016 14.2.7 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1417.10l2Organizational.1)
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 84
Added:
10.m 1 ISO/IEC 27799:2016 12.6.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (0709.10m1Organizational.1)
Added:
10.m 1 NIST SP 800-171 r2 3.11.3 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0709.10m1Organizational.1)
Added:
10.m 2 NIST SP 800-171 r2 3.11.3 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0711.10m2Organizational.23)
Added:
10.m 2 NIST SP 800-171 r2 3.11.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0712.10m2Organizational.4)
Added:
10.m 3 NIST SP 800-171 r2 3.11.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (0718.10m3Organizational.34)
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 85
Removed:
The organization correlates event logs with information Removed requirement; as requirement was removed in CIS CSC
10.m CIS from its vulnerability scanning tools to verify the activity CIS CSC v6 4.1 v7.1
of the regular vulnerability scanning tools is itself logged (0775.10m3System.16)
and whether a given exploit was used against a target
known by the organization to be vulnerable.
Removed:
The organization monitors logs associated with any Removed requirement; as requirement was removed in CIS CSC
10.m CIS CIS CSC v6 4.6 v7.1
scanning activity and associated administrator accounts
to ensure this activity is limited to the timeframes of (0777.10m3System.18)
legitimate scans.
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 86
Updated:
Updated:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 87
Updated:
Updated
Updated:
0765.10mCISSystem.3
Updated:
0766.10mCISSystem.4
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 88
Updated:
0767.10mCISSystem.8
Updated:
0768.10mCISSystem.9
Updated:
0769.10mCISSystem.10
Updated:
0770.10mCISSystem.11
Updated:
0771.10mCISSystem.12
Updated:
0772.10mCISSystem.13
Updated:
0773.10mCISSystem.14
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 89
Updated:
0774.10mCISSystem.15
Updated:
0776.10mCISSystem.17
Updated:
0778.10mCISSystem.19
Added:
Businesses are required to notify consumers if there is New requirement in new segment.
11.a CCPA unauthorized access to the consumer's non-encrypted CCPA 1798.150(a) Necessitates new MyCSF requirement
or non-redacted personal information due to the statement industry specific to CCPA.
business's lack of sufficient security controls. (111015.11aCCPAOrganizational.1)
Updated:
Added:
11.a 3 ISO/IEC 27799:2016 16.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1514.11a3Organizational.12)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 90
Added:
11.a 3 ISO/IEC 27799:2016 16.1.6 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1515.11a3Organizational.3)
Added:
11.a 2 ISO/IEC 27799:2016 7.2.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1508.11a2Organizational.1)
Added:
ISO/IEC 27799:2016 7.2.2 Consistent with existing content
11.a 2
ISO/IEC 27799:2016 16.1.1 (1510.11a2Organizational.47)
ISO/IEC 27799:2016 Cross Reference
Added:
11.a 2 ISO/IEC 27799:2016 7.2.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1511.11a2Organizational.5)
Added:
11.a 2 ISO/IEC 27799:2016 16.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1512.11a2Organizational.8)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 91
Added:
11.a 2 NIST SP 800-171 r2 3.6.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1508.11a2Organizational.1)
Added:
The licensee is required to report, at least annually, the Necessitates new MyCSF requirement
11.a SCIDSA SCIDSA 33-99-20(E)
overall status and compliance of the information statement industry specific to SCIDSA
security program, and any matters relevant to the (151205.11aSCIDSAOrganizational.1)
program (e.g., risk assessments, events, violations, etc.).
Added;
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 92
Added:
Added:
Necessitates new MyCSF requirement
11.a SCIDSA The licensee provides notice of the security breach to SCIDSA 38-99-40(C) statement industry specific to SCIDSA
consumers residing in the State and whose information (151208.11aSCIDSAOrganizational.3)
was affected by the breach.
Added:
11.a 1 SCIDSA 33-99-20(H) Consistent with existing content
SCIDSA Cross Reference (1505.11a1Organizational.13)
Added:
11.a 2 SCIDSA 33-99-20(H) Consistent with existing content
SCIDSA Cross Reference (1509.11a2Organizational.236)
Updated:
Title 23 NYCRR
11.a 1594.11a23NYCRR500Organizational.1 N/A Updated BUID
Part 500
1594.11aNYCRR500Organizational.1
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 93
Added:
11.b 2 ISO/IEC 27799:2016 16.1.3 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1537.11b2Organizational.1)
Added:
NIST Cybersecurity Consistent with existing content
11.b 2
Framework v1.1 RS.AN-5 (1537.11b2Organizational.1)
NIST Cybersecurity Framework v1.1 Cross Reference
Removed:
Removed segment and requirement; as requirement was made
11.c CMS The organization employs automated mechanisms to CMSRs v3.1 IR-03(01) non-mandatory in CMS ARS v3.1
more thoroughly and effectively test/exercise the (1549.11cCMSOrganizational.1)
incident response capability.
Added:
ISO/IEC 27799:2016 16.1.1 Consistent with existing content
11.c 1
ISO/IEC 27799:2016 16.1.5 (1516.11c1Organizational.12)
ISO/IEC 27799:2016 Cross Reference
Added:
11.c 1 ISO/IEC 27799:2016 16.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1517.11c1Organizational.3)
Added:
ISO/IEC 27799:2016 16.1.3 Consistent with existing content
11.c 3
ISO/IEC 27799:2016 16.1.5 (1522.11c3Organizational.13)
ISO/IEC 27799:2016 Cross Reference
Added:
ISO/IEC 27799:2016 16.1.3 Consistent with existing content
11.c 3
ISO/IEC 27799:2016 16.1.5 (1523.11c3Organizational.24)
ISO/IEC 27799:2016 Cross Reference
Added:
NIST Cybersecurity Consistent with existing content
11.c 2
Framework v1.1 ID.SC-5 (1521.11c2Organizational.56)
NIST Cybersecurity Framework v1.1 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 94
Added:
11.c 2 NIST SP 800-171 r2 3.6.1 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1518.11c2Organizational.13)
Added:
11.c 2 NIST SP 800-171 r2 3.6.3 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1521.11c2Organizational.56)
Added:
NIST SP 800-171 r2 3.6.1 Consistent with existing content
11.c 3
NIST SP 800-171 r2 3.6.2 (1522.11c3Organizational.13)
NIST SP 800-171 r2 Cross Reference
Added:
11.c 3 NIST SP 800-171 r2 3.6.2 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1523.11c3Organizational.24)
Added:
SCIDSA 38-99-30(A) Necessitates new MyCSF requirement
11.c SCIDSA Upon notification of a cybersecurity event, the licensee SCIDSA 38-99-30(B) statement industry specific to SCIDSA
must conduct a prompt and thorough investigation of SCIDSA 38-99-30(C) (151205.11cSCIDSAOrganizational.1)
the event.
Added:
11.c 2 AICPA 2017 P6.3 Consistent with existing content
AICPA 2017 Cross Reference (1519.11c2Organizational.2)
Added:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 95
Added:
11.d 1 ISO/IEC 27799:2016 16.11.6 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1560.11d1Organizational.1)
Added:
11.d 2 NIST SP 800-171 R2 3.6.1 Consistent with existing content
NIST SP 800-171 R2 Cross Reference (1561.11d2Organizational.14)
Added:
11.e 1 ISO/IEC 27799:2016 16.1.7 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1569.11e1Organizational.12)
Added:
ISO/IEC 27799:2016 16.1.1 Consistent with existing content
11.e 2
ISO/IEC 27799:2016 16.1.7 (1574.11e2Organizational.7)
ISO/IEC 27799:2016 Cross Reference
Added:
12.a 1 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1632.12a1Organizational.1)
Added:
12.a 2 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1633.12a2Organizational.1)
Added:
12.b 1 ISO/IEC 27799:2016 17.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1634.12b1Organizational.1)
Added:
12.b 1 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1635.12b1Organizational.2)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 96
Added:
12.b 2 ISO/IEC 27799:2016 17.1.1 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1638.12b2Organizational.345)
Added:
NIST Cybersecurity Consistent with existing content
12.b 1
Framework v1.1 PR.PT-5 (1635.12b1Organizational.2)
NIST Cybersecurity Framework v1.1 Cross Reference
Added:
12.b 2 NIST SP 800-171 r2 3.11.1 Consistent with existing content
NIST SP 800-171 r2 Cross Reference (1638.12b2Organizational.345)
Updated:
CMSRs v3.1 CP-02(05)
The organization uses a sample of backup information in Updated requirement statement due to new CMS ARS v3.1
(HIGH)
12.c CMS the restoration of selected information system functions language
CMSRs v3.1 CP-09(02)
and includes a full recovery and reconstitution of the (1656.12cCMSOrganizational.810)
(HIGH)
information system to a known state as part of
contingency plan testing.
Added:
12.c 1 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1601.12c1Organizational.1238)
Added:
12.c 3 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1609.12c3Organizational.12)
Added:
12.c 2 ISO/IEC 27799:2016 17.1.2 Consistent with existing content
ISO/IEC 27799:2016 Cross Reference (1311.12c2Organizational.3)
Added:
ISO/IEC 27799:2016 11.2.2 Consistent with existing content
12.c 2
ISO/IEC 27799:2016 17.1.2 (1604.12c2Organizational.16789,
ISO/IEC 27799:2016 Cross Reference 1605.12c2Organizational.2)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 97
Consistent with existing content
Added: (1666.12d1Organizational.1235,
12.d 1 ISO/IEC 27799:2016 17.1.2 1667.12d1Organizational.4,
ISO/IEC 27799:2016 Cross Reference 1668.12d1Organizational.67,
1669.12d1Organizational.8)
Added:
NIST Cybersecurity Consistent with existing content
12.e 2
Framework v1.1 ID.SC-5 (1679.12e2Organizational.1)
NIST Cybersecurity Framework v1.1 Cross Reference
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 98
Added:
NIST Cybersecurity Consistent with existing content
12.e 1
Framework v1.1 ID.SC-5 (1673.12e1Organizational.1)
NIST Cybersecurity Framework v1.1 Cross Reference
Updated:
19300.13aGDPROrganizational.2
Added:
New requirement in new segment.
13.b CCPA Businesses are required to notify consumers of their CCPA 1798.105(b) Necessitates new MyCSF requirement
right to request deletion. statement industry specific to CCPA.
(191003.13bCCPAOrganizational.1)
Added:
Businesses that sell information or disclose it for a New requirement in new segment.
13.b CCPA business purpose are required to disclose in their notice CCPA 1798.115(c) Necessitates new MyCSF requirement
to consumers the categories of personal information it statement industry specific to CCPA.
has sold and/or disclosed for a business purpose or that (191005.13bCCPAOrganizational.2)
it has not sold and/or disclosed any.
Added:
New requirement in new segment.
13.b CCPA Businesses that sell information to third-parties are CCPA 1798.120(b) Necessitates new MyCSF requirement
required to disclose in their notice to consumers that statement industry specific to CCPA.
they have the right to opt-out. (191007.13bCCPAOrganizational.3)
Added:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 99
Added:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 100
Added:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 101
Added:
13.b 1 CCPA 1798.100(b) Consistent with existing content
CCPA Cross Reference (19315.13b1Organizational.2)
Added:
13.b 1 CCPA 1798.110(a) Consistent with existing content
CCPA Cross Reference (19315.13b1Organizational.2)
Added:
New requirement in new segment.
13.d CCPA Third-parties are required to obtain explicit consumer CCPA 1798.115(d) Necessitates new MyCSF requirement
consent before selling personal information that has statement industry specific to CCPA.
been sold to them by a business. (191006.13dCCPAOrganizational.1)
Added:
Added:
Businesses ensure that consumers who exercise any of New requirement in new segment.
13.e CCPA their rights are not discriminated against through pricing CCPA 1798.125(a) Necessitates new MyCSF requirement
or quality of goods or services. Businesses may charge a statement industry specific to CCPA.
consumer a different rate if it is reasonably related to (191009.13eCCPAOrganizational.1)
the value to the consumer of the consumer’s data.
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 102
Added:
Added:
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 103
Added:
13.f 1 CCPA 1798.105(c) Consistent with existing content
CCPA Cross Reference (19375.13f1Organizational.8)
Updated:
19406.13gGDPROrganizational.6
Updated:
Personal Data
13.g 19408.13fPDPAOrganizational.2 N/A Updated BUID
Protection Act
19408.13gPDPAOrganizational.2
Added:
13.l 1 AICPA 2017 P4.3 Consistent with existing content
AICPA 2017 Cross Reference (19494.13l1Organizational.2)
Added:
13.n 1 CCPA 1798.105(a) Consistent with existing content
CCPA Cross Reference (19498.13n1Organizational.1)
Added:
New requirement in new segment.
13.t CCPA Businesses ensure that individuals responsible for CCPA 1798.130(a)(6) Necessitates new MyCSF requirement
handling consumer inquiries are aware of all relevant statement industry specific to CCPA.
requirements. (191014.13tCCPAOrganizational.1)
© 2019 HITRUST. All rights reserved. Any commercial uses or creations of derivative works are prohibited. No part of this publication may be reproduced or utilized other than being shared as is in
full, in any form or by any means, electronical or mechanical, without HITRUST’s prior written permission. 104