The HITRUST Common Security Framework (CSF) is one of the industry-leading frameworks for ensuring security and privacy in high-stakes sectors like healthcare and tech. Obtaining a HITRUST certificate brings many growth-boosting benefits, from enhanced security to easier trust-building with clients.
To access these benefits, you’ll first need to go through a HITRUST assessment, which can be entry-level, moderate, or complex. You can choose among HITRUST’s three assessment and certification levels. If you're not sure which option is the best fit for your organization, this guide is for you. We’ll help you make an informed decision by explaining the three HITRUST CSF certification levels and the corresponding effort required for each.
What are HITRUST assessments?
A HITRUST CSF assessment is a multi-step process for reviewing your security controls and comparing them to the established HITRUST certification requirements. The idea is to evaluate whether your IT systems, processes, and policies adhere to your industry’s security and privacy standards.
The platform requires both self-assessments (called readiness assessments) and external assessments (called validated assessments). During a typical HITRUST audit, you’ll self-assess your different security domains and score them against the requirement statements, which will then be validated by an external assessor and later reviewed by HITRUST’s QA analyst.
Initially, HITRUST only required the validated assessment, where an organization would work with an approved HITRUST external assessor for certification. As the HITRUST CSF evolved, it offered options for lighter certification levels with less restrictive self-assessment requirements.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
HITRUST assessments explained: e1, i1, and r2 levels
Currently, you can opt for one of three HITRUST assessment levels, namely:
- HITRUST e1
- HITRUST i1
- HITRUST r2
1. HITRUST e1
The HITRUST Essentials, 1-year (e1) assessment is the entry-level and most easily completed assessment in the HITRUST portfolio. It includes 44 critical controls that should be implemented by every organization that wants to safeguard itself from basic security threats.
Practice has shown that organizations can get an e1 certificate in six to eight weeks because of the minimal number of controls. The effective time investment and effort can vary depending on how many controls are already in place or inheritable from a higher-level system.
It’s worth noting that HITRUST e1 certification alone is enough to bring you close to HIPAA compliance.
Some of the main use cases of the e1 certificate include the following:
- Ensuring baseline cybersecurity practices
- Building trust with customers and other stakeholders as a startup
- Preparing for more robust HITRUST assessments
2. HITRUST i1
The HITRUST Implemented, 1-year (i1) assessment is more robust than e1 and provides moderate-level assurance, including third-party assurance, for organizations looking to mature their security and controls setup. It encompasses 187 controls, including the 44 from the e1 assessment. So, passing the e1 assessment automatically gives you a head start for i1.
You can expect a more elaborate assessment process here compared to e1 because of:
- More comprehensive evidence collection
- Granular security reviews
- Higher chances of uncovering control gaps that need remediation
Although the i1 certification process is more complex, it’s still worth going through it if you want to do any of the following:
- Upgrade your security program and demonstrate its effectiveness to stakeholders
- Develop a robust third-party risk management (TPRM) program
- Prepare for r2 certification
3. HITRUST r2
The HITRUST Risk-based, 2-year (r2) assessment is the Alliance’s most comprehensive and granular assessment. Unlike e1 and i1, which have a fixed number of controls, r2 comes with custom controls based on a risk assessment questionnaire. There are over 2,000 controls in total, with the average size of the assessment being 385 controls.
Another considerable difference is that an r2 certificate is valid for two years. However, after a year, you’ll need to complete an interim assessment to verify if your controls still meet requirements. e1 and i1 certificates are only valid for a year.
By choosing r2 certification, you can fully leverage HITRUST CSF’s harmonization with 50+ authoritative frameworks and standards to facilitate efficient and resource-savvy compliance. The framework is mapped to some of the most prominent standards and regulations, most notably:
Due to its size and complexity, r2 certification can take a significant amount of time and effort. Ideally, you’ll streamline different activities like evidence collection and control scoring using automation to avoid unnecessary delays.
When it comes to the main use cases, r2 is best suited for the following:
- Implementing the highest level of security with robust assurance
- Executing risk-based control mapping to reduce your risk exposure
- Ensuring compliance in highly regulated business environments
Which HITRUST assessment is right for me?
Considering the differences in scope and use cases, each HITRUST certification level and its corresponding assessment may have specific user profiles. Refer to the following table to compare the three HITRUST assessment levels and choose one based on your preferences:
As for the primary industry, HITRUST is aimed at organizations in healthcare and technology, but any organization that processes or stores sensitive data, such as protected health information (PHI), can find it useful for building trust and expanding its customer base.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Readiness vs. validated HITRUST assessments
Let’s dig deeper into HITRUST assessments from the perspective of the party conducting them:
- Readiness assessment: An internal HITRUST assessment used for conducting a gap analysis and getting an organization’s controls ready for the certification process
- Validated assessment: A formal HITRUST assessment serving as the prerequisite for successful certification
A readiness assessment isn’t reviewed by HITRUST and doesn’t directly impact the outcome of the certification process. It’s also voluntary, so some organizations may choose to skip it altogether and jump right into the validated assessment. However, there is a higher likelihood of encountering gaps in controls in such cases.
Uncovering gaps doesn’t mean you won’t get certified—you’ll most likely need to implement remediation measures that prolong the certification timeline.
Other benefits of opting for a readiness assessment before the validated assessment include:
- Increased efficiency as a result of familiarity with the assessment process
- Precise knowledge of your security posture and gaps ahead of external assessment
- Less resource waste and back-and-forth during the certification process
HITRUST CSF assessment process explained
HITRUST assessments require you to engage with HITRUST’s online platform, MyCSF. Regardless of your chosen certification level, the assessment process remains the same—here’s a brief overview:
- Pre-assessment: The pre-assessment involves completing six questionnaires via MyCSF (five for e1 and i1 assessments) to define your organization’s chosen certification level and assessment scope.
- Readiness assessment: During the readiness assessment, you review your controls against the in-scope requirements statements to identify and bridge potential gaps.
- Self-assessment: HITRUST certification requires a self-assessment based on the PRISMA model. You’ll score your controls using HITRUST’s Control Maturity Scoring Rubric—a visual tool for assessing your compliance with the framework’s requirements.
- Validation: Your self-assessed scores must be validated by an external assessor who will look for evidence—verbal, written, and other forms—that your controls meet the necessary requirements.
- CAP input and reviews: If some of your controls aren’t up to HITRUST’s standards, they’ll either be identified as potential quality issues (PQIs) and/or require a corrective action plan (CAP).
- Quality assurance: Once the external assessor is done validating your assessment, a HITRUST QA analyst will review it.
- Deliverable preparation and reviews: After the QA process is done, you’ll receive a draft report. You can accept it or request revisions within 30 days, after which you’ll get the final report.
The scoring threshold for obtaining a HITRUST certificate varies according to your chosen certification level, as shown in the following table:
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Streamline HITRUST CSF assessment for all levels with Vanta
HITRUST offers an efficient and straightforward method for completing compliance across all assessment levels, especially with its MyCSF platform that streamlines all inherent workflows. Still, pursuing the certification can lead to busy work if you consider processes like control implementation, documentation, and evidence gathering.
To complete HITRUST effortlessly, the best solution is to leverage Vanta—a trust management platform that automates up to 80% of the HITRUST requirements.
As HITRUST’s official automation partner, Vanta has comprehensive functionalities built specifically around HITRUST frameworks across all levels. Here are some of its most notable features:
- Centralized tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Automated gap analysis to perform a readiness assessment quickly
- Cross-referencing other frameworks for mapping existing control
- Prescriptive guidance in the form of:some text
- New controls
- Documents
- Automated tests
- Policy addendums
- Integration with MyCSF
To see these features in action, you can watch Vanta’s free HITRUST webinar or schedule a custom demo of the HITRUST suite.
You can also tap into Vanta’s service partner network to find HITRUST-approved external assessors who can help you navigate your certification journey and manage the MyCSF platform.
{{cta_simple16="/cta-modules"}} | HITRUST product page
Introduction to HITRUST
HITRUST CSF assessments for e1, i1, and r2: A comparative breakdown
Introduction to HITRUST
The HITRUST Common Security Framework (CSF) is one of the industry-leading frameworks for ensuring security and privacy in high-stakes sectors like healthcare and tech. Obtaining a HITRUST certificate brings many growth-boosting benefits, from enhanced security to easier trust-building with clients.
To access these benefits, you’ll first need to go through a HITRUST assessment, which can be entry-level, moderate, or complex. You can choose among HITRUST’s three assessment and certification levels. If you're not sure which option is the best fit for your organization, this guide is for you. We’ll help you make an informed decision by explaining the three HITRUST CSF certification levels and the corresponding effort required for each.
What are HITRUST assessments?
A HITRUST CSF assessment is a multi-step process for reviewing your security controls and comparing them to the established HITRUST certification requirements. The idea is to evaluate whether your IT systems, processes, and policies adhere to your industry’s security and privacy standards.
The platform requires both self-assessments (called readiness assessments) and external assessments (called validated assessments). During a typical HITRUST audit, you’ll self-assess your different security domains and score them against the requirement statements, which will then be validated by an external assessor and later reviewed by HITRUST’s QA analyst.
Initially, HITRUST only required the validated assessment, where an organization would work with an approved HITRUST external assessor for certification. As the HITRUST CSF evolved, it offered options for lighter certification levels with less restrictive self-assessment requirements.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
HITRUST assessments explained: e1, i1, and r2 levels
Currently, you can opt for one of three HITRUST assessment levels, namely:
- HITRUST e1
- HITRUST i1
- HITRUST r2
1. HITRUST e1
The HITRUST Essentials, 1-year (e1) assessment is the entry-level and most easily completed assessment in the HITRUST portfolio. It includes 44 critical controls that should be implemented by every organization that wants to safeguard itself from basic security threats.
Practice has shown that organizations can get an e1 certificate in six to eight weeks because of the minimal number of controls. The effective time investment and effort can vary depending on how many controls are already in place or inheritable from a higher-level system.
It’s worth noting that HITRUST e1 certification alone is enough to bring you close to HIPAA compliance.
Some of the main use cases of the e1 certificate include the following:
- Ensuring baseline cybersecurity practices
- Building trust with customers and other stakeholders as a startup
- Preparing for more robust HITRUST assessments
2. HITRUST i1
The HITRUST Implemented, 1-year (i1) assessment is more robust than e1 and provides moderate-level assurance, including third-party assurance, for organizations looking to mature their security and controls setup. It encompasses 187 controls, including the 44 from the e1 assessment. So, passing the e1 assessment automatically gives you a head start for i1.
You can expect a more elaborate assessment process here compared to e1 because of:
- More comprehensive evidence collection
- Granular security reviews
- Higher chances of uncovering control gaps that need remediation
Although the i1 certification process is more complex, it’s still worth going through it if you want to do any of the following:
- Upgrade your security program and demonstrate its effectiveness to stakeholders
- Develop a robust third-party risk management (TPRM) program
- Prepare for r2 certification
3. HITRUST r2
The HITRUST Risk-based, 2-year (r2) assessment is the Alliance’s most comprehensive and granular assessment. Unlike e1 and i1, which have a fixed number of controls, r2 comes with custom controls based on a risk assessment questionnaire. There are over 2,000 controls in total, with the average size of the assessment being 385 controls.
Another considerable difference is that an r2 certificate is valid for two years. However, after a year, you’ll need to complete an interim assessment to verify if your controls still meet requirements. e1 and i1 certificates are only valid for a year.
By choosing r2 certification, you can fully leverage HITRUST CSF’s harmonization with 50+ authoritative frameworks and standards to facilitate efficient and resource-savvy compliance. The framework is mapped to some of the most prominent standards and regulations, most notably:
Due to its size and complexity, r2 certification can take a significant amount of time and effort. Ideally, you’ll streamline different activities like evidence collection and control scoring using automation to avoid unnecessary delays.
When it comes to the main use cases, r2 is best suited for the following:
- Implementing the highest level of security with robust assurance
- Executing risk-based control mapping to reduce your risk exposure
- Ensuring compliance in highly regulated business environments
Which HITRUST assessment is right for me?
Considering the differences in scope and use cases, each HITRUST certification level and its corresponding assessment may have specific user profiles. Refer to the following table to compare the three HITRUST assessment levels and choose one based on your preferences:
As for the primary industry, HITRUST is aimed at organizations in healthcare and technology, but any organization that processes or stores sensitive data, such as protected health information (PHI), can find it useful for building trust and expanding its customer base.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Readiness vs. validated HITRUST assessments
Let’s dig deeper into HITRUST assessments from the perspective of the party conducting them:
- Readiness assessment: An internal HITRUST assessment used for conducting a gap analysis and getting an organization’s controls ready for the certification process
- Validated assessment: A formal HITRUST assessment serving as the prerequisite for successful certification
A readiness assessment isn’t reviewed by HITRUST and doesn’t directly impact the outcome of the certification process. It’s also voluntary, so some organizations may choose to skip it altogether and jump right into the validated assessment. However, there is a higher likelihood of encountering gaps in controls in such cases.
Uncovering gaps doesn’t mean you won’t get certified—you’ll most likely need to implement remediation measures that prolong the certification timeline.
Other benefits of opting for a readiness assessment before the validated assessment include:
- Increased efficiency as a result of familiarity with the assessment process
- Precise knowledge of your security posture and gaps ahead of external assessment
- Less resource waste and back-and-forth during the certification process
HITRUST CSF assessment process explained
HITRUST assessments require you to engage with HITRUST’s online platform, MyCSF. Regardless of your chosen certification level, the assessment process remains the same—here’s a brief overview:
- Pre-assessment: The pre-assessment involves completing six questionnaires via MyCSF (five for e1 and i1 assessments) to define your organization’s chosen certification level and assessment scope.
- Readiness assessment: During the readiness assessment, you review your controls against the in-scope requirements statements to identify and bridge potential gaps.
- Self-assessment: HITRUST certification requires a self-assessment based on the PRISMA model. You’ll score your controls using HITRUST’s Control Maturity Scoring Rubric—a visual tool for assessing your compliance with the framework’s requirements.
- Validation: Your self-assessed scores must be validated by an external assessor who will look for evidence—verbal, written, and other forms—that your controls meet the necessary requirements.
- CAP input and reviews: If some of your controls aren’t up to HITRUST’s standards, they’ll either be identified as potential quality issues (PQIs) and/or require a corrective action plan (CAP).
- Quality assurance: Once the external assessor is done validating your assessment, a HITRUST QA analyst will review it.
- Deliverable preparation and reviews: After the QA process is done, you’ll receive a draft report. You can accept it or request revisions within 30 days, after which you’ll get the final report.
The scoring threshold for obtaining a HITRUST certificate varies according to your chosen certification level, as shown in the following table:
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Streamline HITRUST CSF assessment for all levels with Vanta
HITRUST offers an efficient and straightforward method for completing compliance across all assessment levels, especially with its MyCSF platform that streamlines all inherent workflows. Still, pursuing the certification can lead to busy work if you consider processes like control implementation, documentation, and evidence gathering.
To complete HITRUST effortlessly, the best solution is to leverage Vanta—a trust management platform that automates up to 80% of the HITRUST requirements.
As HITRUST’s official automation partner, Vanta has comprehensive functionalities built specifically around HITRUST frameworks across all levels. Here are some of its most notable features:
- Centralized tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Automated gap analysis to perform a readiness assessment quickly
- Cross-referencing other frameworks for mapping existing control
- Prescriptive guidance in the form of:some text
- New controls
- Documents
- Automated tests
- Policy addendums
- Integration with MyCSF
To see these features in action, you can watch Vanta’s free HITRUST webinar or schedule a custom demo of the HITRUST suite.
You can also tap into Vanta’s service partner network to find HITRUST-approved external assessors who can help you navigate your certification journey and manage the MyCSF platform.
{{cta_simple16="/cta-modules"}} | HITRUST product page
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Role: | GRC responsibilities: |
---|---|
Board of directors | Central to the overarching GRC strategy, this group sets the direction for the compliance strategy. They determine which standards and regulations are necessary for compliance and align the GRC strategy with business objectives. |
Chief financial officer | Primary responsibility for the success of the GRC program and for reporting results to the board. |
Operations managers from relevant departments | This group owns processes. They are responsible for the success and direction of risk management and compliance within their departments. |
Representatives from relevant departments | These are the activity owners. These team members are responsible for carrying out specific compliance and risk management tasks within their departments and for integrating these tasks into their workflows. |
Contract managers from relevant department | These team members are responsible for managing interactions with vendors and other third parties in their department to ensure all risk management and compliance measures are being taken. |
Chief information security officer (CISO) | Defines the organization’s information security policy, designs risk and vulnerability assessments, and develops information security policies. |
Data protection officer (DPO) or legal counsel | Develops goals for data privacy based on legal regulations and other compliance needs, designs and implements privacy policies and practices, and assesses these practices for effectiveness. |
GRC lead | Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the organization’s library of security controls. |
Cybersecurity analyst(s) | Implements and monitors cybersecurity measures that are in line with the GRC program and business objectives. |
Compliance analyst(s) | Monitors the organization’s compliance with all regulations and standards necessary, identifies any compliance gaps, and works to mitigate them. |
Risk analyst(s) | Carries out the risk management program for the organization and serves as a resource for risk management across various departments, including identifying, mitigating, and monitoring risks. |
IT security specialist(s) | Implements security controls within the IT system in coordination with the cybersecurity analyst(s). |