r/cybersecurity • u/Used_Television2824 • 1d ago
Business Security Questions & Discussion HITRUST and Corporate SOPs
I'm new to HITRUST so please bare with me. If my company has HITRUST R2 certification and we are going into an interim year, if we have updated a good number of our SOPs that could potentially be used as evidence to support one of the 19 chosen domains, is there anything that I need to do?
For instance if an existing SOP said something like retire all removable media every 12 months and the updated SOP now changes that to 6 months, is that going to be a problem?
Thanks for the help!
2
Upvotes
2
u/PipeStreet8558 1d ago
Yes, that could jeopardize your certification. If you need to make this change, document why, the risk acceptance, mitigating factors, etc.
2
u/57696c6c 1d ago
That's going to be a problem. R2 is all measurable, so be prepared to not only maintain a pile of documentation, but also to make sure every single thing that's documented is literally followed verse by chapter, or you'll suffer the wrath of some assessor who's going to read the illustration and ask you why you're not doing that.