Comment on Common Questions About the HITRUST CSF by HITRUST

In reply to Roman Zeltser.

Thank you for your question. The HITRUST requirement is in place to ensure an organization is managing its network and has current information that is updated periodically. The level of detail is not stipulated, so our recommendation would be to provide as much detail as you need in the course of managing your network. Often times, multiple diagrams may be necessary to achieve both functionality and requisite detail. Further, a determination as to whether the level of detail is sufficient – or not – is generally left to the HITRUST CSF Assessor firm, after which, HITRUST could potentially become involved through the QA process.