Regardless of the size of your organization, demonstrating security and trust in heavily regulated industries like healthcare and finance can always be challenging. HITRUST CSF certification resolves this issue to a great extent as it helps provide sufficient industry-level assurance to both internal and external stakeholders, including prospects and investors.
Still, the HITRUST certification process can be extensive and potentially overwhelming for the first time. In this guide, we’ll go through everything you should know so that you’re aware and prepared for all the key stages of compliance. We’ll cover the following:
- Parties involved in the certification process
- A structured seven-stage process breakdown
- Common HITRUST certification challenges and how to overcome them
Who is involved in the HITRUST certification process?
The HITRUST certification process involves three key stakeholders:
- Assessed entity: The organization looking to get certified
- External assessor: A third party authorized by HITRUST to review and verify the assessed entity’s readiness
- HITRUST: The certification body that conducts quality assurance of the external assessor’s evaluation and issues a certificate
A significant advantage of HITRUST certification is a well-defined workflow that overlaps with that of 50+ other security regulations and frameworks, including HIPAA and GDPR. HITRUST CSF also supports your team with predefined roles and clear task owners, which makes it easier to track the progress of certification initiatives.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
7 key stages of the HITRUST certification process explained
In general, pursuing HITRUST certification consists of the following essential stages:
- Pre-assessment
- Readiness assessment
- Assessment of requirement statements via rubric
- External validation
- CAP input and reviews
- Quality assurance
- Deliverable preparation and reviews
We’ll discuss the key procedural aspects of each stage below.
Stage 1: Pre-assessment
During the pre-assessment stage, you start with completing the necessary web forms. They are:
The most noteworthy step you’ll take during the pre-assessment stage is the selection of your preferred assessment level. The e1 and i1 levels come with predefined requirement statements, covering 44 or 187 controls, respectively, while the r2 assessment is risk-based and comes with a custom number of controls (selected from a pool of over 2,000 controls).
A considerable challenge at this stage can be assessment scoping. You need to precisely identify the systems, business units, and other elements that will be evaluated during the HITRUST audit.
The scope depends on several factors, most notably:
- The needs of your stakeholders
- Your resources and personnel
- The maturity level of your security and privacy program
- Data flow network
To ensure accurate assessment scoping, you should consult the relevant departments in your organization, such as IT and security.
Stage 2: Readiness assessment
A HITRUST readiness assessment is used to determine whether your security controls meet the criteria for a successful validated assessment, which gets you a HITRUST certificate. While a readiness assessment is optional, it’s highly recommended by HITRUST because it helps you review the state of your existing controls and how well they align with the chosen assessment.
The readiness assessment workflow depends on your chosen certification level:
- e1 and i1: The assessment is standardized and based on predefined requirement statements
- r2: The assessment requires the completion of a risk-based scoping questionnaire, after which the in-scope requirement statements are assessed
This stage can involve comprehensive evidence collection and control mapping. A smart solution to simplify the process is using HITRUST’s official automation partner, Vanta, which provides a dedicated solution to facilitate HITRUST certification.
Note: HITRUST doesn’t perform quality assurance reviews of readiness assessments—they’re purely for your reference so you can identify and bridge any HITRUST compliance gaps.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Stage 3: Assessment of requirement statements via rubric
To get a HITRUST certificate, you need to go through a validated assessment that involves responding to requirement statements according to the PRISMA (acronym for Preferred Reporting Items for Systematic Reviews and Meta-Analyses) model. This is done through the Control Maturity Scoring Rubric, which offers guidance and a visual representation of scored requirement statements.
The rubric works like a matrix with two dimensions:
- Strength: The extent to which the requirement is implemented
- Coverage: The percentage of in-scope elements compliant with the requirement
During the assessment stage, you’ll score each requirement statement using the evaluated PRISMA maturity levels (depending on your chosen assessment). For e1 and i1, you’ll only score the Implemented level, while the r2 assessment requires all five levels:
- Policy
- Procedure
- Implemented
- Measures
- Managed
Stage 4: External validation
After you’ve scored all the in-scope requirement statements, an external assessor must validate their accuracy. They’ll complete extensive assessment fieldwork that includes various activities, such as:
- Walkthroughs and personnel interviews
- Review of written security policies and procedures
- Assessment of the existence and performance of relevant controls
- Technical testing of security controls
It’s not enough to only score the requirement statements—you must provide sufficient proof of implementation that verifies the scores. Your external assessor will look for different types of evidence, including:
- Verbal information
- Observed information
- Paper trail
- Electronic evidence
The type of evidence requested largely depends on the specific control, so make sure your team can back up the scores with adequate proof.
Stage 5: CAP input and reviews
If some of your requirement statements don’t meet the necessary criteria, you’ll need to define corrective action plans (CAPs). The criteria vary according to the assessment level, as explained in the following table:
You can define CAPs by completing the CAP form, which needs to include the following information:.
- Name
- Corrective action (which must be specific, measurable, and clear)
- Status:
- Not started
- Started—At risk
- Started—On track
- Completed
- Point of contact
- Scheduled completion date
After you create a CAP, your external assessor will review it for grammar, spelling, clarity, and specificity, as well as assess your organization’s ability to show related progress.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Stage 6: Quality assurance
Quality assurance is the final stage before your organization receives a HITRUST certificate. It’s performed by a HITRUST QA analyst, who will scrutinize all aspects of the assessment to determine whether your controls pass the required standards.
Specifically, the analyst will examine the following documentation:
- Pre-assessment forms
- Assessment documentation and web forms
- CAPs
- Overridden potential quality issues (PQIs)
After the QA review, the analyst may assign tasks to the external assessor and your organization. These can be of two types:
- General tasks: Requests or instructions to address a particular QA concern. You can choose to leave a comment or directly address the task.
- Proposed tasks: Suggested changes that should be considered. You can either accept or reject the suggestion.
The tasks will initially be assigned to the external assessor, who can address them, leave a comment, or send them to your organization.
Besides the standard QA process, there are two additional types you might encounter—Live QA and Escalated QA:
Stage 7: Deliverable preparation and reviews
If you complete a HITRUST assessment successfully, you can obtain one of the following certification reports, depending on your chosen certification level:
- HITRUST Essentials 1-year (e1) Certification Report
- HITRUST Implemented 1-year (i1) Certification Report
- HITRUST Risk-based, 2-year (r2) Certification Report
For e1 and c1 certificates, each domain must score 83 or above. For an r2 certificate, you need 62 or higher. If you don’t reach this threshold, you’ll obtain non-certified reports, which are referred to as validated-only.
If you choose r2 certification, you’ll get an additional NIST Cybersecurity Framework Report upon successful completion, provided you score 70 or higher on the NIST-mapped requirements.
After receiving the QA report draft, you have 30 days to review it. You can approve it or request revisions in case of misjudgments. Upon approval or revision, HITRUST will prepare and post the final report.
Common HITRUST certification challenges
Due to the multi-phase activities involved, HITRUST certification can be challenging for some organizations. The main obstacles you might encounter include:
- Assessment scoping issues: If you have a complex security infrastructure involving multiple scattered elements, scoping the HITRUST assessment might get complicated.
- Manual, inefficient workflows: Scoring requirement statements accurately requires comprehensive security reviews. Completing these processes manually can make the certification process longer than necessary.
- Overworked compliance teams: Without software support and well-defined processes, compliance and security teams might be overwhelmed by HITRUST requirements on top of their daily workload. The overwhelm can lead to team burnout and make the certification process inefficient.
- Finding a HITRUST external assessor: Your HITRUST assessor plays a key role in driving your assessment forward and enabling a reasonable certification timeline. However, finding a collaborative assessor may take some time.
One way to find a reliable HITRUST assessor is to leverage Vanta’s service partner network. Tap into the platform’s vetted network of assurance professionals who have experience in handling HITRUST clients.
To overcome the other challenges, you can use Vanta’s HITRUST CSF solution. While various platforms might promise HITRUST-centric solutions, Vanta is currently the only product that offers pre-built e1, i1, or r2 frameworks.
Complete HITRUST certification seamlessly with Vanta
Vanta is an end-to-end trust management framework that automates up to 80% of the requirements for HITRUST CSF certification. Its HITRUST CSF solution is equipped with various useful features, such as:
- Automated gap assessment that simplifies readiness assessments
- Centralized documentation and tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Integration with MyCSF (HITRUST’s compliance management portal)
Vanta gets your systems and processes ready for the HITRUST validated assessment without painstaking manual work. You can leverage the platform’s resources, such as the latest controls, pre-built document templates, automated tests, and policy addendums, to enjoy a streamlined certification process without extensive back-and-forth with assessors and QA analysts.
To learn more about the HITRUST, you can watch this webinar. You can also request a HITRUST CSF product demo tailored for your team.
{{cta_simple16="/cta-modules"}} | HITRUST product page
Preparing for HITRUST certification
HITRUST certification: A comprehensive process breakdown
Preparing for HITRUST certification
Regardless of the size of your organization, demonstrating security and trust in heavily regulated industries like healthcare and finance can always be challenging. HITRUST CSF certification resolves this issue to a great extent as it helps provide sufficient industry-level assurance to both internal and external stakeholders, including prospects and investors.
Still, the HITRUST certification process can be extensive and potentially overwhelming for the first time. In this guide, we’ll go through everything you should know so that you’re aware and prepared for all the key stages of compliance. We’ll cover the following:
- Parties involved in the certification process
- A structured seven-stage process breakdown
- Common HITRUST certification challenges and how to overcome them
Who is involved in the HITRUST certification process?
The HITRUST certification process involves three key stakeholders:
- Assessed entity: The organization looking to get certified
- External assessor: A third party authorized by HITRUST to review and verify the assessed entity’s readiness
- HITRUST: The certification body that conducts quality assurance of the external assessor’s evaluation and issues a certificate
A significant advantage of HITRUST certification is a well-defined workflow that overlaps with that of 50+ other security regulations and frameworks, including HIPAA and GDPR. HITRUST CSF also supports your team with predefined roles and clear task owners, which makes it easier to track the progress of certification initiatives.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
7 key stages of the HITRUST certification process explained
In general, pursuing HITRUST certification consists of the following essential stages:
- Pre-assessment
- Readiness assessment
- Assessment of requirement statements via rubric
- External validation
- CAP input and reviews
- Quality assurance
- Deliverable preparation and reviews
We’ll discuss the key procedural aspects of each stage below.
Stage 1: Pre-assessment
During the pre-assessment stage, you start with completing the necessary web forms. They are:
The most noteworthy step you’ll take during the pre-assessment stage is the selection of your preferred assessment level. The e1 and i1 levels come with predefined requirement statements, covering 44 or 187 controls, respectively, while the r2 assessment is risk-based and comes with a custom number of controls (selected from a pool of over 2,000 controls).
A considerable challenge at this stage can be assessment scoping. You need to precisely identify the systems, business units, and other elements that will be evaluated during the HITRUST audit.
The scope depends on several factors, most notably:
- The needs of your stakeholders
- Your resources and personnel
- The maturity level of your security and privacy program
- Data flow network
To ensure accurate assessment scoping, you should consult the relevant departments in your organization, such as IT and security.
Stage 2: Readiness assessment
A HITRUST readiness assessment is used to determine whether your security controls meet the criteria for a successful validated assessment, which gets you a HITRUST certificate. While a readiness assessment is optional, it’s highly recommended by HITRUST because it helps you review the state of your existing controls and how well they align with the chosen assessment.
The readiness assessment workflow depends on your chosen certification level:
- e1 and i1: The assessment is standardized and based on predefined requirement statements
- r2: The assessment requires the completion of a risk-based scoping questionnaire, after which the in-scope requirement statements are assessed
This stage can involve comprehensive evidence collection and control mapping. A smart solution to simplify the process is using HITRUST’s official automation partner, Vanta, which provides a dedicated solution to facilitate HITRUST certification.
Note: HITRUST doesn’t perform quality assurance reviews of readiness assessments—they’re purely for your reference so you can identify and bridge any HITRUST compliance gaps.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
Stage 3: Assessment of requirement statements via rubric
To get a HITRUST certificate, you need to go through a validated assessment that involves responding to requirement statements according to the PRISMA (acronym for Preferred Reporting Items for Systematic Reviews and Meta-Analyses) model. This is done through the Control Maturity Scoring Rubric, which offers guidance and a visual representation of scored requirement statements.
The rubric works like a matrix with two dimensions:
- Strength: The extent to which the requirement is implemented
- Coverage: The percentage of in-scope elements compliant with the requirement
During the assessment stage, you’ll score each requirement statement using the evaluated PRISMA maturity levels (depending on your chosen assessment). For e1 and i1, you’ll only score the Implemented level, while the r2 assessment requires all five levels:
- Policy
- Procedure
- Implemented
- Measures
- Managed
Stage 4: External validation
After you’ve scored all the in-scope requirement statements, an external assessor must validate their accuracy. They’ll complete extensive assessment fieldwork that includes various activities, such as:
- Walkthroughs and personnel interviews
- Review of written security policies and procedures
- Assessment of the existence and performance of relevant controls
- Technical testing of security controls
It’s not enough to only score the requirement statements—you must provide sufficient proof of implementation that verifies the scores. Your external assessor will look for different types of evidence, including:
- Verbal information
- Observed information
- Paper trail
- Electronic evidence
The type of evidence requested largely depends on the specific control, so make sure your team can back up the scores with adequate proof.
Stage 5: CAP input and reviews
If some of your requirement statements don’t meet the necessary criteria, you’ll need to define corrective action plans (CAPs). The criteria vary according to the assessment level, as explained in the following table:
You can define CAPs by completing the CAP form, which needs to include the following information:.
- Name
- Corrective action (which must be specific, measurable, and clear)
- Status:
- Not started
- Started—At risk
- Started—On track
- Completed
- Point of contact
- Scheduled completion date
After you create a CAP, your external assessor will review it for grammar, spelling, clarity, and specificity, as well as assess your organization’s ability to show related progress.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Stage 6: Quality assurance
Quality assurance is the final stage before your organization receives a HITRUST certificate. It’s performed by a HITRUST QA analyst, who will scrutinize all aspects of the assessment to determine whether your controls pass the required standards.
Specifically, the analyst will examine the following documentation:
- Pre-assessment forms
- Assessment documentation and web forms
- CAPs
- Overridden potential quality issues (PQIs)
After the QA review, the analyst may assign tasks to the external assessor and your organization. These can be of two types:
- General tasks: Requests or instructions to address a particular QA concern. You can choose to leave a comment or directly address the task.
- Proposed tasks: Suggested changes that should be considered. You can either accept or reject the suggestion.
The tasks will initially be assigned to the external assessor, who can address them, leave a comment, or send them to your organization.
Besides the standard QA process, there are two additional types you might encounter—Live QA and Escalated QA:
Stage 7: Deliverable preparation and reviews
If you complete a HITRUST assessment successfully, you can obtain one of the following certification reports, depending on your chosen certification level:
- HITRUST Essentials 1-year (e1) Certification Report
- HITRUST Implemented 1-year (i1) Certification Report
- HITRUST Risk-based, 2-year (r2) Certification Report
For e1 and c1 certificates, each domain must score 83 or above. For an r2 certificate, you need 62 or higher. If you don’t reach this threshold, you’ll obtain non-certified reports, which are referred to as validated-only.
If you choose r2 certification, you’ll get an additional NIST Cybersecurity Framework Report upon successful completion, provided you score 70 or higher on the NIST-mapped requirements.
After receiving the QA report draft, you have 30 days to review it. You can approve it or request revisions in case of misjudgments. Upon approval or revision, HITRUST will prepare and post the final report.
Common HITRUST certification challenges
Due to the multi-phase activities involved, HITRUST certification can be challenging for some organizations. The main obstacles you might encounter include:
- Assessment scoping issues: If you have a complex security infrastructure involving multiple scattered elements, scoping the HITRUST assessment might get complicated.
- Manual, inefficient workflows: Scoring requirement statements accurately requires comprehensive security reviews. Completing these processes manually can make the certification process longer than necessary.
- Overworked compliance teams: Without software support and well-defined processes, compliance and security teams might be overwhelmed by HITRUST requirements on top of their daily workload. The overwhelm can lead to team burnout and make the certification process inefficient.
- Finding a HITRUST external assessor: Your HITRUST assessor plays a key role in driving your assessment forward and enabling a reasonable certification timeline. However, finding a collaborative assessor may take some time.
One way to find a reliable HITRUST assessor is to leverage Vanta’s service partner network. Tap into the platform’s vetted network of assurance professionals who have experience in handling HITRUST clients.
To overcome the other challenges, you can use Vanta’s HITRUST CSF solution. While various platforms might promise HITRUST-centric solutions, Vanta is currently the only product that offers pre-built e1, i1, or r2 frameworks.
Complete HITRUST certification seamlessly with Vanta
Vanta is an end-to-end trust management framework that automates up to 80% of the requirements for HITRUST CSF certification. Its HITRUST CSF solution is equipped with various useful features, such as:
- Automated gap assessment that simplifies readiness assessments
- Centralized documentation and tracking of HITRUST requirements
- Automated evidence collection powered by over 350 integrations
- Integration with MyCSF (HITRUST’s compliance management portal)
Vanta gets your systems and processes ready for the HITRUST validated assessment without painstaking manual work. You can leverage the platform’s resources, such as the latest controls, pre-built document templates, automated tests, and policy addendums, to enjoy a streamlined certification process without extensive back-and-forth with assessors and QA analysts.
To learn more about the HITRUST, you can watch this webinar. You can also request a HITRUST CSF product demo tailored for your team.
{{cta_simple16="/cta-modules"}} | HITRUST product page
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Role: | GRC responsibilities: |
---|---|
Board of directors | Central to the overarching GRC strategy, this group sets the direction for the compliance strategy. They determine which standards and regulations are necessary for compliance and align the GRC strategy with business objectives. |
Chief financial officer | Primary responsibility for the success of the GRC program and for reporting results to the board. |
Operations managers from relevant departments | This group owns processes. They are responsible for the success and direction of risk management and compliance within their departments. |
Representatives from relevant departments | These are the activity owners. These team members are responsible for carrying out specific compliance and risk management tasks within their departments and for integrating these tasks into their workflows. |
Contract managers from relevant department | These team members are responsible for managing interactions with vendors and other third parties in their department to ensure all risk management and compliance measures are being taken. |
Chief information security officer (CISO) | Defines the organization’s information security policy, designs risk and vulnerability assessments, and develops information security policies. |
Data protection officer (DPO) or legal counsel | Develops goals for data privacy based on legal regulations and other compliance needs, designs and implements privacy policies and practices, and assesses these practices for effectiveness. |
GRC lead | Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the organization’s library of security controls. |
Cybersecurity analyst(s) | Implements and monitors cybersecurity measures that are in line with the GRC program and business objectives. |
Compliance analyst(s) | Monitors the organization’s compliance with all regulations and standards necessary, identifies any compliance gaps, and works to mitigate them. |
Risk analyst(s) | Carries out the risk management program for the organization and serves as a resource for risk management across various departments, including identifying, mitigating, and monitoring risks. |
IT security specialist(s) | Implements security controls within the IT system in coordination with the cybersecurity analyst(s). |