The HITRUST CSF (Common Security Framework) offers a comprehensive risk management and regulatory compliance framework to organizations, especially those in healthcare and technology sectors. It represents a map of industry-standard security controls drawn from 50+ standards and regulations. By becoming HITRUST-certified, you can strengthen your security posture and build trust with stakeholders.
To achieve the certification, though, you’ll need to undergo a stringent HITRUST audit. This multi-step process provides the necessary assurance that your organization meets HITRUST standards.
This guide will explain all essential information about HITRUST audits. We’ll cover:
- HITRUST audit basics
- Seven key steps involved in the audit process
- Bonus tips to help you prepare for a HITRUST audit efficiently
What is a HITRUST audit?
A HITRUST audit involves a thorough evaluation of an organization’s security controls to ensure they meet HITRUST’s certification requirements. It examines an organization’s security posture to verify the existence and effectiveness of in-scope HITRUST controls before certification, which includes processes like:
- Gathering and validating evidence
- Conducting interviews with task owners
- Getting third-party assurances
- Documenting findings
- Addressing corrective action plans
The main goal of a HITRUST audit is to ensure the assessed entity implements the prescribed security controls to protect itself in a diverse risk environment and achieve compliance. With HITRUST’s harmonization of over 50 authoritative regulations and standards, the audit can also help organizations prepare for other compliance audits.
For example, if you run a healthtech company and need to comply with HIPAA and SOC 2, pursuing the HITRUST certification can help you reuse overlapping controls within these frameworks to ensure time and resource efficiency.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Who conducts a HITRUST audit?
A complete HITRUST audit includes dual assessments—a readiness assessment and a validated assessment. A readiness assessment can be a self-assessment, although some organizations may outsource the task to an independent assessor or auditor. The validated assessment is a third-party assessment performed by an authorized external assessor. The external assessor primarily reviews the scores you’ve assigned to the scoped controls, determining their validity and alignment with HITRUST requirements.
All the key phases of the HITRUST audit are performed using the MyCSF platform. Some of the platform’s main features include:
- Assessment scope configuration
- Assessment centralization and tracking
- Scoring reports, charts, and dashboards
Who needs a HITRUST audit?
Undergoing a HITRUST audit is necessary for every organization that wants to obtain a HITRUST certification. Initially, HITRUST was aimed at organizations in the healthcare sector, but today, it’s applicable to any organization looking to enhance its security posture.
The HITRUST certification is especially useful for organizations that collect, store, or manage protected health information (PHI). Examples of such organizations besides healthcare providers include:
- Pharmacies
- Insurance companies
- Faxing companies
Even if your organization doesn’t manage PHI, you can benefit from the HITRUST certification if you want to comply with one of the 50+ standards and regulations HITRUST harmonizes, such as:
- HIPAA
- SOC 2
- GDPR
- PCI DSS
- NIST Cybersecurity Framework
7 key steps to a successful HITRUST audit
The steps before and during a HITRUST audit—or HITRUST assessment—allow organizations to implement the necessary controls, gather evidence, and even take corrective measures as necessary. Here’s an outline of the process:
- Choose your certification level
- Complete a pre-assessment
- Understand the HITRUST CSF security domains
- Perform a readiness assessment
- Undergo a validated assessment
- Review and address corrective action plans or CAPs
- Go through quality assurance
Step 1: Choose your certification level
HITRUST offers three certification levels that determine the breadth of audit procedures:
- e1
- i1
- r2
Each level comes with a different number of controls and is aimed at specific organizations, as explained in this table:
Lower certification tiers, e1 and i1, are easier to prepare for as they come with a predefined set of controls you need to implement. As you complete the lower tiers, you can store progress in your HITRUST MyCSF account, which will make the eventual audits more efficient.
e1 and i1 certifications serve as onramps for the r2 assessment, which requires more comprehensive custom controls—you can expect a longer prep time before the audit.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Step 2: Complete a pre-assessment
After choosing a certification level, you’ll need to complete a corresponding pre-assessment. If you choose e1 or i1, the pre-assessment will involve the completion of five web forms:
- Name and Security
- Assessment Options
- Organization Information
- Scope of the Assessment
- Default Scoring Profile
If you’re preparing for an r2 audit, you’ll also need to fill out the Factors web form. This form lets you tailor your HITRUST requirement statements and controls according to your organization’s inherent risk.
During this step, the main challenge you might encounter is assessment scoping. The scope of your audit can depend on several factors, most notably:
- Available personnel and resources
- Security and privacy program maturity
- Expected changes in the IT infrastructure
The purpose of this step is to ensure your audit outcomes align with your risk profile. You can take several approaches to define an assessment scope, such as:
- Enterprise-level
- Service- or platform-focused
- Shared IT services
Step 3: Understand the HITRUST CSF security domains
The HITRUST CSF has a significant advantage over other security frameworks—it’s more comprehensive and uses a clear structure to remove any ambiguity during audits.
In this step, you should familiarize yourself with HITRUST’s structure and implement your controls to the scoped requirements, especially if you’re pursuing an r2 certification. You should go over the following key components of HITRUST with your security team:
- 14 control categories
- 49 control objectives
- 156 control references
- 2,600+ requirement statements
Additionally, you need to understand various requirement statements split into 19 security domains:
- Information Protection Program
- Endpoint Protection
- Portable Media Security
- Mobile Device Security
- Wireless Security
- Configuration Management
- Vulnerability Management
- Network Protection
- Transmission Protection
- Password Management
- Access Control
- Audit Logging & Monitoring
- Education, Training and Awareness
- Third Party Assurance
- Incident Management
- Business Continuity & Disaster Recovery
- Risk Management
- Physical & Environmental Security
- Data Protection & Privacy
The outcome of this step should be to have a tailored list of controls you want to achieve. You can also assign task owners to review specific control frameworks and conduct a gap analysis.
Step 4: Perform a readiness assessment
A readiness assessment is a useful procedure that helps you identify and remediate any HITRUST compliance gaps internally before you start the validated assessment necessary for certification. It’s not mandatory or reviewed by HITRUST, but it’s highly recommended because it can make your audit process smooth and productive.
To perform a readiness assessment, you’ll carry out robust security reviews to determine whether your in-scope controls meet HITRUST’s benchmarks and implement remedial steps for existing gaps.
Step 5: Undergo a validated assessment
The essence of the HITRUST audit and certification process is a validated assessment. It involves self-assessment of your controls using HITRUST’s Control Maturity Scoring Rubric.
The rubric measures your control’s compliance according to the PRISMA model. For r2 assessments, you’ll need to evaluate all five maturity levels of the model, namely:
- Policy
- Procedure
- Implemented
- Measured
- Managed
For e1 and i1 assessments, you only need to score the Implemented level.
This step resembles an external audit. A HITRUST external assessor (an individual or entity independent of the organization) will review and perform testing of your self-assessment and look for proof that the scores are valid. You’ll need to present sufficient evidence to demonstrate the controls’ effectiveness and scoring accuracy.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Step 6: Review and address corrective action plans or CAPs
A validated assessment might not be successful immediately. In some cases, you’ll need to address corrective action plans (CAPs). The criteria for CAPs vary between certification levels, as explained below:
If a CAP is needed, you’ll fill out the corresponding web form that explains how and when you plan on remediating the identified control issues. The assessment will then go back to the external assessor, who will audit the CAP.
Step 7: Go through quality assurance
After successful validation, your assessment will undergo a final audit layer—namely, quality assurance performed by HITRUST’s QA analyst. The analyst will review various aspects of the assessment, such as:
- Pre-assessment
- Relevant web forms and documents
- CAPs
- Measured and managed score sample (only for r2 assessments)
In some cases, the QA analyst might leave tasks for the external assessor and your organization to complete, which can be:
- General: Requests to address a QA concern
- Proposed: Advisable changes the external assessor or your organization should implement
After addressing the above tasks and completing the QA process, you should receive your final QA report, and, eventually, the HITRUST certificate.
3 tips for efficient HITRUST audits
A HITRUST audit can be extensive, which warrants a streamlined workflow. To complete the process without friction, you can follow these tips:
- Map your security and compliance landscape
- Familiarize yourself with the shared responsibility model
- Consider a reliable automation solution
1. Map your security and compliance landscape
A successful HITRUST audit requires a thorough understanding of your security posture. By performing regular security reviews, you can fast-track the evidence collection and control scoring processes once you enter the assessment process.
You should also understand your compliance landscape to see how a HITRUST certification will contribute to compliance with other regulations and standards. Once you obtain the certification (especially for r2), many controls necessary for regulatory compliance will already be in place. Taking a proactive approach to understanding the relationship between HITRUST and other frameworks will make your compliance workflows efficient over time.
2. Familiarize yourself with the shared responsibility model
HITRUST uses the shared responsibility model, which lets organizations inherit controls from the cloud service providers (CSPs). Leveraging inheritable controls brings many benefits, such as:
- Fewer security controls to implement and review
- Enhanced auditing efficiency
- Shorter HITRUST certification time frame
You should review your CSP’s security controls to see if you inherit some of them and also determine how this should be demonstrated during audits.
3. Consider a reliable automation solution
Leveraging automation is essential for resource-efficient HITRUST audits because the certification and assessment workflows are time-consuming if done manually. Process inefficiencies can arise during various stages, such as:
- Control reviews
- Evidence collection
- Gap remediation
To overcome these obstacles and go through the audits smoothly, leverage Vanta—HITRUST’s official automation partner.
{{cta_testimonial11="/cta-modules"}} | US Med-Equip Customer Story
Streamline your HITRUST audit with Vanta
Vanta is an end-to-end trust management platform designed to automate the majority of HITRUST certification requirements. Vanta’s HITRUST solution lets you access pre-built frameworks and workflows to achieve certification seamlessly.
The solution is tailored to HITRUST frameworks and simplifies audits through core features, such as:
- Automated gap assessments
- Cross-referencing other frameworks for existing controls
- Centralized tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Ready-to-use document templates
- Prescriptive guidance with 200+ resources like controls, automated tests, and policy addendums
- Integration with MyCSF platform to sync evidence (documents, tests, etc.) seamlessly
If you need help navigating the HITRUST MyCSF platform or finding an external assessor, Vanta can help. You can tap into Vanta’s extensive service partner network to find a reputable external assessor who can personalize your certification process and provide support with MyCSF.
Schedule a custom demo to have experts from Vanta help you explore the platform.
{{cta_simple16="/cta-modules"}} | HITRUST product page
Preparing for HITRUST certification
How to get ready for a HITRUST audit: A step-by-step guide
Preparing for HITRUST certification
The HITRUST CSF (Common Security Framework) offers a comprehensive risk management and regulatory compliance framework to organizations, especially those in healthcare and technology sectors. It represents a map of industry-standard security controls drawn from 50+ standards and regulations. By becoming HITRUST-certified, you can strengthen your security posture and build trust with stakeholders.
To achieve the certification, though, you’ll need to undergo a stringent HITRUST audit. This multi-step process provides the necessary assurance that your organization meets HITRUST standards.
This guide will explain all essential information about HITRUST audits. We’ll cover:
- HITRUST audit basics
- Seven key steps involved in the audit process
- Bonus tips to help you prepare for a HITRUST audit efficiently
What is a HITRUST audit?
A HITRUST audit involves a thorough evaluation of an organization’s security controls to ensure they meet HITRUST’s certification requirements. It examines an organization’s security posture to verify the existence and effectiveness of in-scope HITRUST controls before certification, which includes processes like:
- Gathering and validating evidence
- Conducting interviews with task owners
- Getting third-party assurances
- Documenting findings
- Addressing corrective action plans
The main goal of a HITRUST audit is to ensure the assessed entity implements the prescribed security controls to protect itself in a diverse risk environment and achieve compliance. With HITRUST’s harmonization of over 50 authoritative regulations and standards, the audit can also help organizations prepare for other compliance audits.
For example, if you run a healthtech company and need to comply with HIPAA and SOC 2, pursuing the HITRUST certification can help you reuse overlapping controls within these frameworks to ensure time and resource efficiency.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Who conducts a HITRUST audit?
A complete HITRUST audit includes dual assessments—a readiness assessment and a validated assessment. A readiness assessment can be a self-assessment, although some organizations may outsource the task to an independent assessor or auditor. The validated assessment is a third-party assessment performed by an authorized external assessor. The external assessor primarily reviews the scores you’ve assigned to the scoped controls, determining their validity and alignment with HITRUST requirements.
All the key phases of the HITRUST audit are performed using the MyCSF platform. Some of the platform’s main features include:
- Assessment scope configuration
- Assessment centralization and tracking
- Scoring reports, charts, and dashboards
Who needs a HITRUST audit?
Undergoing a HITRUST audit is necessary for every organization that wants to obtain a HITRUST certification. Initially, HITRUST was aimed at organizations in the healthcare sector, but today, it’s applicable to any organization looking to enhance its security posture.
The HITRUST certification is especially useful for organizations that collect, store, or manage protected health information (PHI). Examples of such organizations besides healthcare providers include:
- Pharmacies
- Insurance companies
- Faxing companies
Even if your organization doesn’t manage PHI, you can benefit from the HITRUST certification if you want to comply with one of the 50+ standards and regulations HITRUST harmonizes, such as:
- HIPAA
- SOC 2
- GDPR
- PCI DSS
- NIST Cybersecurity Framework
7 key steps to a successful HITRUST audit
The steps before and during a HITRUST audit—or HITRUST assessment—allow organizations to implement the necessary controls, gather evidence, and even take corrective measures as necessary. Here’s an outline of the process:
- Choose your certification level
- Complete a pre-assessment
- Understand the HITRUST CSF security domains
- Perform a readiness assessment
- Undergo a validated assessment
- Review and address corrective action plans or CAPs
- Go through quality assurance
Step 1: Choose your certification level
HITRUST offers three certification levels that determine the breadth of audit procedures:
- e1
- i1
- r2
Each level comes with a different number of controls and is aimed at specific organizations, as explained in this table:
Lower certification tiers, e1 and i1, are easier to prepare for as they come with a predefined set of controls you need to implement. As you complete the lower tiers, you can store progress in your HITRUST MyCSF account, which will make the eventual audits more efficient.
e1 and i1 certifications serve as onramps for the r2 assessment, which requires more comprehensive custom controls—you can expect a longer prep time before the audit.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Step 2: Complete a pre-assessment
After choosing a certification level, you’ll need to complete a corresponding pre-assessment. If you choose e1 or i1, the pre-assessment will involve the completion of five web forms:
- Name and Security
- Assessment Options
- Organization Information
- Scope of the Assessment
- Default Scoring Profile
If you’re preparing for an r2 audit, you’ll also need to fill out the Factors web form. This form lets you tailor your HITRUST requirement statements and controls according to your organization’s inherent risk.
During this step, the main challenge you might encounter is assessment scoping. The scope of your audit can depend on several factors, most notably:
- Available personnel and resources
- Security and privacy program maturity
- Expected changes in the IT infrastructure
The purpose of this step is to ensure your audit outcomes align with your risk profile. You can take several approaches to define an assessment scope, such as:
- Enterprise-level
- Service- or platform-focused
- Shared IT services
Step 3: Understand the HITRUST CSF security domains
The HITRUST CSF has a significant advantage over other security frameworks—it’s more comprehensive and uses a clear structure to remove any ambiguity during audits.
In this step, you should familiarize yourself with HITRUST’s structure and implement your controls to the scoped requirements, especially if you’re pursuing an r2 certification. You should go over the following key components of HITRUST with your security team:
- 14 control categories
- 49 control objectives
- 156 control references
- 2,600+ requirement statements
Additionally, you need to understand various requirement statements split into 19 security domains:
- Information Protection Program
- Endpoint Protection
- Portable Media Security
- Mobile Device Security
- Wireless Security
- Configuration Management
- Vulnerability Management
- Network Protection
- Transmission Protection
- Password Management
- Access Control
- Audit Logging & Monitoring
- Education, Training and Awareness
- Third Party Assurance
- Incident Management
- Business Continuity & Disaster Recovery
- Risk Management
- Physical & Environmental Security
- Data Protection & Privacy
The outcome of this step should be to have a tailored list of controls you want to achieve. You can also assign task owners to review specific control frameworks and conduct a gap analysis.
Step 4: Perform a readiness assessment
A readiness assessment is a useful procedure that helps you identify and remediate any HITRUST compliance gaps internally before you start the validated assessment necessary for certification. It’s not mandatory or reviewed by HITRUST, but it’s highly recommended because it can make your audit process smooth and productive.
To perform a readiness assessment, you’ll carry out robust security reviews to determine whether your in-scope controls meet HITRUST’s benchmarks and implement remedial steps for existing gaps.
Step 5: Undergo a validated assessment
The essence of the HITRUST audit and certification process is a validated assessment. It involves self-assessment of your controls using HITRUST’s Control Maturity Scoring Rubric.
The rubric measures your control’s compliance according to the PRISMA model. For r2 assessments, you’ll need to evaluate all five maturity levels of the model, namely:
- Policy
- Procedure
- Implemented
- Measured
- Managed
For e1 and i1 assessments, you only need to score the Implemented level.
This step resembles an external audit. A HITRUST external assessor (an individual or entity independent of the organization) will review and perform testing of your self-assessment and look for proof that the scores are valid. You’ll need to present sufficient evidence to demonstrate the controls’ effectiveness and scoring accuracy.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Step 6: Review and address corrective action plans or CAPs
A validated assessment might not be successful immediately. In some cases, you’ll need to address corrective action plans (CAPs). The criteria for CAPs vary between certification levels, as explained below:
If a CAP is needed, you’ll fill out the corresponding web form that explains how and when you plan on remediating the identified control issues. The assessment will then go back to the external assessor, who will audit the CAP.
Step 7: Go through quality assurance
After successful validation, your assessment will undergo a final audit layer—namely, quality assurance performed by HITRUST’s QA analyst. The analyst will review various aspects of the assessment, such as:
- Pre-assessment
- Relevant web forms and documents
- CAPs
- Measured and managed score sample (only for r2 assessments)
In some cases, the QA analyst might leave tasks for the external assessor and your organization to complete, which can be:
- General: Requests to address a QA concern
- Proposed: Advisable changes the external assessor or your organization should implement
After addressing the above tasks and completing the QA process, you should receive your final QA report, and, eventually, the HITRUST certificate.
3 tips for efficient HITRUST audits
A HITRUST audit can be extensive, which warrants a streamlined workflow. To complete the process without friction, you can follow these tips:
- Map your security and compliance landscape
- Familiarize yourself with the shared responsibility model
- Consider a reliable automation solution
1. Map your security and compliance landscape
A successful HITRUST audit requires a thorough understanding of your security posture. By performing regular security reviews, you can fast-track the evidence collection and control scoring processes once you enter the assessment process.
You should also understand your compliance landscape to see how a HITRUST certification will contribute to compliance with other regulations and standards. Once you obtain the certification (especially for r2), many controls necessary for regulatory compliance will already be in place. Taking a proactive approach to understanding the relationship between HITRUST and other frameworks will make your compliance workflows efficient over time.
2. Familiarize yourself with the shared responsibility model
HITRUST uses the shared responsibility model, which lets organizations inherit controls from the cloud service providers (CSPs). Leveraging inheritable controls brings many benefits, such as:
- Fewer security controls to implement and review
- Enhanced auditing efficiency
- Shorter HITRUST certification time frame
You should review your CSP’s security controls to see if you inherit some of them and also determine how this should be demonstrated during audits.
3. Consider a reliable automation solution
Leveraging automation is essential for resource-efficient HITRUST audits because the certification and assessment workflows are time-consuming if done manually. Process inefficiencies can arise during various stages, such as:
- Control reviews
- Evidence collection
- Gap remediation
To overcome these obstacles and go through the audits smoothly, leverage Vanta—HITRUST’s official automation partner.
{{cta_testimonial11="/cta-modules"}} | US Med-Equip Customer Story
Streamline your HITRUST audit with Vanta
Vanta is an end-to-end trust management platform designed to automate the majority of HITRUST certification requirements. Vanta’s HITRUST solution lets you access pre-built frameworks and workflows to achieve certification seamlessly.
The solution is tailored to HITRUST frameworks and simplifies audits through core features, such as:
- Automated gap assessments
- Cross-referencing other frameworks for existing controls
- Centralized tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Ready-to-use document templates
- Prescriptive guidance with 200+ resources like controls, automated tests, and policy addendums
- Integration with MyCSF platform to sync evidence (documents, tests, etc.) seamlessly
If you need help navigating the HITRUST MyCSF platform or finding an external assessor, Vanta can help. You can tap into Vanta’s extensive service partner network to find a reputable external assessor who can personalize your certification process and provide support with MyCSF.
Schedule a custom demo to have experts from Vanta help you explore the platform.
{{cta_simple16="/cta-modules"}} | HITRUST product page
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Role: | GRC responsibilities: |
---|---|
Board of directors | Central to the overarching GRC strategy, this group sets the direction for the compliance strategy. They determine which standards and regulations are necessary for compliance and align the GRC strategy with business objectives. |
Chief financial officer | Primary responsibility for the success of the GRC program and for reporting results to the board. |
Operations managers from relevant departments | This group owns processes. They are responsible for the success and direction of risk management and compliance within their departments. |
Representatives from relevant departments | These are the activity owners. These team members are responsible for carrying out specific compliance and risk management tasks within their departments and for integrating these tasks into their workflows. |
Contract managers from relevant department | These team members are responsible for managing interactions with vendors and other third parties in their department to ensure all risk management and compliance measures are being taken. |
Chief information security officer (CISO) | Defines the organization’s information security policy, designs risk and vulnerability assessments, and develops information security policies. |
Data protection officer (DPO) or legal counsel | Develops goals for data privacy based on legal regulations and other compliance needs, designs and implements privacy policies and practices, and assesses these practices for effectiveness. |
GRC lead | Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the organization’s library of security controls. |
Cybersecurity analyst(s) | Implements and monitors cybersecurity measures that are in line with the GRC program and business objectives. |
Compliance analyst(s) | Monitors the organization’s compliance with all regulations and standards necessary, identifies any compliance gaps, and works to mitigate them. |
Risk analyst(s) | Carries out the risk management program for the organization and serves as a resource for risk management across various departments, including identifying, mitigating, and monitoring risks. |
IT security specialist(s) | Implements security controls within the IT system in coordination with the cybersecurity analyst(s). |