Given the positive fulfillment of the interim review requirement, where no breach has occurred and no significant changes have developed relating to the scoped control environment, HITRUST CSF reports with Certification are valid for two years. However, at the one-year anniversary of the Certification, I.S. Partners, LLC can perform your organization’s interim review by:
- Requesting your organization to update the scoping questions
- Reviewing the updated questionnaire for any changes to original questionnaire
- Testing at least one control/statement in each domain
- Reviewing the status of any Corrective Action Plan (CAP) from the original assessment to ensure that satisfactory progress/milestones are being met