The HITRUST Common Security Framework (CSF) helps organizations implement stringent security controls and comply with over 50 major regulations and standards. In particular, its data-driven assessment and certification processes enable effortless trust building with customers and other stakeholders.
Obtaining a HITRUST certificate requires a solid understanding of the platform’s unique scoring system, known as the Control Maturity Scoring Rubric (also called “the Rubric”). It’s a specific tool devised to numerically measure an organization’s cybersecurity and compliance efforts, and how well they align with HITRUST CSF requirements.
In this guide, you’ll learn:
- How to use the Control Maturity Scoring Rubric
- What score thresholds get your organization certified
- What challenges you might run into while scoring your controls
What is the Control Maturity Scoring Rubric?
The Control Maturity Scoring Rubric is a visual self-assessment tool used during the HITRUST certification process. It helps both the assessed entities and external assessors score the control maturity of each requirement statement involved in the HITRUST audit.
Using the Rubric, you can score your security controls against the PRISMA model, which consists of five maturity levels:
- Policy
- Procedure
- Implemented
- Measures
- Managed
While the Rubric’s scoring elements vary according to maturity levels, they refer to two dimensions of security control implementation—as explained below:
These two dimensions and their ranges form a matrix that you’ll use to place a security control in the corresponding field that reflects its maturity level.
Additionally, the maturity levels you need to evaluate depend on your HITRUST certification level (e1, i1, or r2):
- e1 and i1: Only the Implemented level is evaluated
- r2: All five PRISMA maturity levels are evaluated
Regardless of the certification level, the scoring process will be the same.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
How to use the Control Maturity Scoring Rubric
Once you choose your preferred HITRUST certification level and determine the assessment scope, you can use the Rubric to score the in-scope requirement statements. To demonstrate what this looks like in practice, let’s follow a simplified example of the following requirement statement:
“The organization has a formal information protection program based on an accepted industry framework that is reviewed and updated as needed.”
- If we assume you implement such a program for 80% of your IT infrastructure, this implies the implementation strength is 80% and falls under Tier 3 (66%–89% of scope)
- If the percentage of compliant evaluative elements is 93%, this means the coverage is graded as Very High (90%–100%)
By looking at the Implemented Rubric, we can see that in this case, the control would be rated as Mostly Compliant, which means you’d get 75% of the total points awarded for it. For reference, the following table shows the point percentage for all compliance scenarios:
If you were pursuing r2 certification, you’d repeat the process for the other maturity levels (Policy, Procedure, Measures, and Managed) and use the following weights to calculate the final score:
In our example, the final score for the implemented maturity level would be 30 (40% of 75). After doing the same calculation for each maturity level, you’ll add up all scores to get the total for the requirement statement.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
What score must you reach to obtain a HITRUST certificate?
The HITRUST certification threshold depends on your chosen certification level:
- 83+ points for e1 and i1
- 62+ points for r2
Keep in mind that these thresholds refer to the total scores for each control domain, not the individual requirement statements. They are expressed as the average score of all requirement statements for each of HITRUST’s 19 control domains:
- Information Protection Program
- Endpoint Protection
- Portable Media Security
- Mobile Device Security
- Wireless Security
- Configuration Management
- Vulnerability Management
- Network Protection
- Transmission Protection
- Password Management
- Access Control
- Audit Logging & Monitoring
- Education, Training and Awareness
- Third Party Assurance
- Incident Management
- Business Continuity & Disaster Recovery
- Risk Management
- Physical & Environmental Security
- Data Protection & Privacy
There are several certification scenarios you might encounter. Besides full certification without issues, you might achieve certification with gaps or CAPs (corrective action plans).
For example, a gap may be present if the requirement didn’t score Fully Compliant, but the associated control reference has a score of 80 or more (71 or more for r2). If the control reference has a lower score, a CAP might be needed. Once identified, CAPs are addressed through a form that explains how and when you plan to remediate the discovered issue.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Control Maturity Scoring Rubric: Common challenges
Using the HITRUST Rubric demands comprehensive security reviews and evidence collection, considering that the self-assessed scores need to be demonstrated to the HITRUST external assessor during the validated assessment.
Naturally, maintaining elaborate evidence that can back up each score without any ambiguity is the most challenging part of the process. Typically, the assessor would need evidence in the form of:
- Observed information
- Verbal information
- Electronic information
- Paper documents
Other issues related to collecting and demonstrating evidence for rubric scores include:
- Blocked workforce: Disparate documentation and evidence collection systems slow down both internal and external HITRUST assessments and lead to extensive busy work.
- Pressure on IT and security teams: Your team might be overwhelmed by the amount of manual evidence maintenance work they need to complete to demonstrate the effectiveness of in-scope controls.
- Prolonged certification timeframe: HITRUST certification can take unnecessarily long if you don’t have a streamlined way to track evidence and make it readily accessible to assessors.
The good news is that you can now complete the evidence-gathering process in a more organized and efficient manner with Vanta, an automation solution vetted by HITRUST.
Get your organization HITRUST-ready with Vanta
Vanta is an end-to-end trust management platform that automates up to 80% of the HITRUST certification requirements. It’s the first (and currently the only) automaton platform with HITRUST-approved frameworks to get ready for e1/i1 and r2 assessments.
The platform offers a dedicated HITRUST CSF solution that helps you perform a readiness assessment seamlessly and address control deficiencies before external reviews.
Vanta streamlines evidence collection by integrating with over 350 other platforms, including HITRUST’s MyCSF audit platform for seamless evidence upload. It can also perform a gap analysis to help you assess your progress and patch up your controls to improve the relevant rubric scores..
Here are some other key features that bring peace of mind during your certification journey:
- Prescriptive guidance to automate several HITRUST requirements with centralized tracking
- Automated cross-referencing of supported frameworks to reduce duplicative work
- Resources like policy templates and tests for efficient workflows
Vanta also helps you find expert HITRUST assessors via its service partner network.
You can schedule a custom demo today to explore Vanta’s HITRUST CSF features firsthand.
{{cta_simple16="/cta-modules"}} | HITRUST product page
HITRUST requirements
HITRUST scoring rubric: What it is and how to use it
HITRUST requirements
The HITRUST Common Security Framework (CSF) helps organizations implement stringent security controls and comply with over 50 major regulations and standards. In particular, its data-driven assessment and certification processes enable effortless trust building with customers and other stakeholders.
Obtaining a HITRUST certificate requires a solid understanding of the platform’s unique scoring system, known as the Control Maturity Scoring Rubric (also called “the Rubric”). It’s a specific tool devised to numerically measure an organization’s cybersecurity and compliance efforts, and how well they align with HITRUST CSF requirements.
In this guide, you’ll learn:
- How to use the Control Maturity Scoring Rubric
- What score thresholds get your organization certified
- What challenges you might run into while scoring your controls
What is the Control Maturity Scoring Rubric?
The Control Maturity Scoring Rubric is a visual self-assessment tool used during the HITRUST certification process. It helps both the assessed entities and external assessors score the control maturity of each requirement statement involved in the HITRUST audit.
Using the Rubric, you can score your security controls against the PRISMA model, which consists of five maturity levels:
- Policy
- Procedure
- Implemented
- Measures
- Managed
While the Rubric’s scoring elements vary according to maturity levels, they refer to two dimensions of security control implementation—as explained below:
These two dimensions and their ranges form a matrix that you’ll use to place a security control in the corresponding field that reflects its maturity level.
Additionally, the maturity levels you need to evaluate depend on your HITRUST certification level (e1, i1, or r2):
- e1 and i1: Only the Implemented level is evaluated
- r2: All five PRISMA maturity levels are evaluated
Regardless of the certification level, the scoring process will be the same.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
How to use the Control Maturity Scoring Rubric
Once you choose your preferred HITRUST certification level and determine the assessment scope, you can use the Rubric to score the in-scope requirement statements. To demonstrate what this looks like in practice, let’s follow a simplified example of the following requirement statement:
“The organization has a formal information protection program based on an accepted industry framework that is reviewed and updated as needed.”
- If we assume you implement such a program for 80% of your IT infrastructure, this implies the implementation strength is 80% and falls under Tier 3 (66%–89% of scope)
- If the percentage of compliant evaluative elements is 93%, this means the coverage is graded as Very High (90%–100%)
By looking at the Implemented Rubric, we can see that in this case, the control would be rated as Mostly Compliant, which means you’d get 75% of the total points awarded for it. For reference, the following table shows the point percentage for all compliance scenarios:
If you were pursuing r2 certification, you’d repeat the process for the other maturity levels (Policy, Procedure, Measures, and Managed) and use the following weights to calculate the final score:
In our example, the final score for the implemented maturity level would be 30 (40% of 75). After doing the same calculation for each maturity level, you’ll add up all scores to get the total for the requirement statement.
{{cta_webinar3="/cta-modules"}} | Choosing the right HITRUST certification level and streamlining implementation
What score must you reach to obtain a HITRUST certificate?
The HITRUST certification threshold depends on your chosen certification level:
- 83+ points for e1 and i1
- 62+ points for r2
Keep in mind that these thresholds refer to the total scores for each control domain, not the individual requirement statements. They are expressed as the average score of all requirement statements for each of HITRUST’s 19 control domains:
- Information Protection Program
- Endpoint Protection
- Portable Media Security
- Mobile Device Security
- Wireless Security
- Configuration Management
- Vulnerability Management
- Network Protection
- Transmission Protection
- Password Management
- Access Control
- Audit Logging & Monitoring
- Education, Training and Awareness
- Third Party Assurance
- Incident Management
- Business Continuity & Disaster Recovery
- Risk Management
- Physical & Environmental Security
- Data Protection & Privacy
There are several certification scenarios you might encounter. Besides full certification without issues, you might achieve certification with gaps or CAPs (corrective action plans).
For example, a gap may be present if the requirement didn’t score Fully Compliant, but the associated control reference has a score of 80 or more (71 or more for r2). If the control reference has a lower score, a CAP might be needed. Once identified, CAPs are addressed through a form that explains how and when you plan to remediate the discovered issue.
{{cta_withimage19="/cta-modules"}} | HITRUST Compliance Checklist
Control Maturity Scoring Rubric: Common challenges
Using the HITRUST Rubric demands comprehensive security reviews and evidence collection, considering that the self-assessed scores need to be demonstrated to the HITRUST external assessor during the validated assessment.
Naturally, maintaining elaborate evidence that can back up each score without any ambiguity is the most challenging part of the process. Typically, the assessor would need evidence in the form of:
- Observed information
- Verbal information
- Electronic information
- Paper documents
Other issues related to collecting and demonstrating evidence for rubric scores include:
- Blocked workforce: Disparate documentation and evidence collection systems slow down both internal and external HITRUST assessments and lead to extensive busy work.
- Pressure on IT and security teams: Your team might be overwhelmed by the amount of manual evidence maintenance work they need to complete to demonstrate the effectiveness of in-scope controls.
- Prolonged certification timeframe: HITRUST certification can take unnecessarily long if you don’t have a streamlined way to track evidence and make it readily accessible to assessors.
The good news is that you can now complete the evidence-gathering process in a more organized and efficient manner with Vanta, an automation solution vetted by HITRUST.
Get your organization HITRUST-ready with Vanta
Vanta is an end-to-end trust management platform that automates up to 80% of the HITRUST certification requirements. It’s the first (and currently the only) automaton platform with HITRUST-approved frameworks to get ready for e1/i1 and r2 assessments.
The platform offers a dedicated HITRUST CSF solution that helps you perform a readiness assessment seamlessly and address control deficiencies before external reviews.
Vanta streamlines evidence collection by integrating with over 350 other platforms, including HITRUST’s MyCSF audit platform for seamless evidence upload. It can also perform a gap analysis to help you assess your progress and patch up your controls to improve the relevant rubric scores..
Here are some other key features that bring peace of mind during your certification journey:
- Prescriptive guidance to automate several HITRUST requirements with centralized tracking
- Automated cross-referencing of supported frameworks to reduce duplicative work
- Resources like policy templates and tests for efficient workflows
Vanta also helps you find expert HITRUST assessors via its service partner network.
You can schedule a custom demo today to explore Vanta’s HITRUST CSF features firsthand.
{{cta_simple16="/cta-modules"}} | HITRUST product page
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
What’s a Rich Text element?
What’s a Rich Text element?The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.
The rich text element allows you to create and format headings, paragraphs, blockquotes, images, and video all in one place instead of having to add and format them individually. Just double-click and easily create content.Static and dynamic content editing
Static and dynamic content editingA rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!
A rich text element can be used with static or dynamic content. For static content, just drop it into any page and begin editing. For dynamic content, add a rich text field to any collection and then connect a rich text element to that field in the settings panel. Voila!How to customize formatting for each rich text
How to customize formatting for each rich textHeadings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.
Headings, paragraphs, blockquotes, figures, images, and figure captions can all be styled after a class is added to the rich text element using the "When inside of" nested selector system.Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Role: | GRC responsibilities: |
---|---|
Board of directors | Central to the overarching GRC strategy, this group sets the direction for the compliance strategy. They determine which standards and regulations are necessary for compliance and align the GRC strategy with business objectives. |
Chief financial officer | Primary responsibility for the success of the GRC program and for reporting results to the board. |
Operations managers from relevant departments | This group owns processes. They are responsible for the success and direction of risk management and compliance within their departments. |
Representatives from relevant departments | These are the activity owners. These team members are responsible for carrying out specific compliance and risk management tasks within their departments and for integrating these tasks into their workflows. |
Contract managers from relevant department | These team members are responsible for managing interactions with vendors and other third parties in their department to ensure all risk management and compliance measures are being taken. |
Chief information security officer (CISO) | Defines the organization’s information security policy, designs risk and vulnerability assessments, and develops information security policies. |
Data protection officer (DPO) or legal counsel | Develops goals for data privacy based on legal regulations and other compliance needs, designs and implements privacy policies and practices, and assesses these practices for effectiveness. |
GRC lead | Responsible for overseeing the execution of the GRC program in collaboration with the executive team as well as maintaining the organization’s library of security controls. |
Cybersecurity analyst(s) | Implements and monitors cybersecurity measures that are in line with the GRC program and business objectives. |
Compliance analyst(s) | Monitors the organization’s compliance with all regulations and standards necessary, identifies any compliance gaps, and works to mitigate them. |
Risk analyst(s) | Carries out the risk management program for the organization and serves as a resource for risk management across various departments, including identifying, mitigating, and monitoring risks. |
IT security specialist(s) | Implements security controls within the IT system in coordination with the cybersecurity analyst(s). |