HITRUST Overview and AI Assessments Webinar.pptx

AmyPoblete3 1,117 views 16 slides Mar 03, 2025
Slide 1
Slide 1 of 16
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16

About This Presentation

This webinar provides an overview of HITRUST, a widely recognized cybersecurity framework, and its application in AI assessments for risk management and compliance. It explores different HITRUST assessment options, including AI-specific frameworks, and highlights how organizations can streamline cer...


Slide Content

WEBINAR HITRUST Overview & AI Assessments

ControlCase . All Rights Reserved. 2 Agenda HITRUST CSF Why HITRUST? HITRUST Assessment Portfolio 01 02 03 HITRUST AI Assessments ControlCase Methodology Panel Discussion 04 05 06

Omkar Salunkhe Senior Vice President Presenter:

ControlCase Snapshot © ControlCase. All Rights Reserved.

© ControlCase . All Rights Reserved. 5 ControlCase Overview Best- in- Class Compliance Platform ControlCase is revolutionizing the way enterprises and organizations deal with the numerous and frequently changing IT compliance and regulatory requirements Proprietary software, including appliance and SaaS solutions, that enable CaaS (GRC and Data Discovery) Compelling proprietary offering combining proprietary software, certification/audits, and managed services on a single platform. One Audit TM enables our clientele to Assess once: Comply to Many Leadership positions in the PCI DSS, SOC 2, ISO 27001, HIPAA, HITRUST, FedRAMP and CMMC domains Serving over 1,000 customers Global footprint with offices in  the  U .S., LATAM, Europe, India, Canada , and UAE Leverages an offshore delivery infrastructure for competitive advantage IT compliance manager for multiple industry segments including banking, service providers, retail, hospitality ,  and telecom Global Vision & Solutions Enhancement Provider of Compliance as a Service (CaaS) subscription-based offering bundling proprietary GRC software and managed services Founded in 2004 Headquartered in Fairfax, VA Offices in U.S., Canada, India 250+ employees

ControlCase Snapshot © ControlCase. All Rights Reserved. 6 CERTIFICATION AND CONTINUOUS COMPLIANCE SERVICES Go beyond the auditor’s checklist to: Dramatically reduce the time, cost, and burden of maintaining IT compliance and becoming certified. Demonstrate compliance more efficiently and cost effectively (cost certainty) Offload much of the compliance burden to a trusted compliance partner Improve efficiencies by doing more with less resources and gain compliance peace of mind 1,000+ CLIENTS 10,000+ IT SECURITY CERTIFICATIONS 275+ SECURITY EXPERTS

ControlCase Snapshot – Solution © ControlCase. All Rights Reserved. 7 Certification and Continuous Compliance Services Partnership Approach Compliance HUB TM + = IT Certification Services Continuous Compliance Services &

Certification Services One Audit™ Assess Once. Comply to Many. © ControlCase. All Rights Reserved. 8

HITRUST CSF © ControlCase . All Rights Reserved. 9 HITRUST CSF is a risk management framework developed and maintained by HITRUST. Certifiable standard that harmonizes 50+ sources. Allows organizations the ability to tailor their security control baselines based on their specific information security requirements. The standard was initially targeted to cater organizations in the healthcare sector. However, it is now an industry agnostic standard that can be used by organizations across various sectors to protect sensitive data.

Why HITRUST? © ControlCase . All Rights Reserved. 10 Return on Investment Marketplace Differentiation Increase Speed of Sale Cyber Insurance – Better Rates and Coverage Threat Adaptive Multiple Levels of Validation Third Party Risk Management Prescriptive Control Language Security Compliance In 2024, HITRUST identified that HITRUST r2 certified organizations remediated 92% of controls that did not fully address the HITRUST CSF framework requirements within one year of achieving their certification.

HITRUST Assessment Portfolio © ControlCase . All Rights Reserved. 11 e1 Validated Assessment Focuses on Implementation Maturity Basic Cybersecurity Hygiene 44 Security Requirements 3 Mandatory M aturity L evels and 2 Optional Inherent Risk Factors and Compliance Factors Avg. of 275 Security Requirements i1 Validated Assessment r2 Validated Assessment Focuses on Implementation Maturity Mapped to Leading Cybersecurity Practices 182 Security Requirements As per the 2024 HITRUST Trust Report, 47.6 % of new adopters have chosen to get certified against the e1 assessment whereas i1 and r2 have been chosen by 28% and 24.4%, respectively.

HITRUST AI Assessments © ControlCase . All Rights Reserved. 12 HITRUST AI Risk Management Framework Focuses on holistic AI Risk Management Harmonizes ISO/IEC 23894:2023 and NIST AI RMF Targeted towards AI providers and users Resulting in an insights report; not a certification 51 relevant AI Risk Management controls HITRUST AI Security Assessment Focuses only on AI Security Harmonizes controls from NIST, ISO and OWASP Targeted towards AI providers only Add-on certification to the e1, i1 or r2 assessments Up to 44 AI security requirements

© ControlCase . All Rights Reserved. 13 ControlCase Methodology Scoping Readiness Assistance Validated Assessment HITRUST QA and Certification

© ControlCase . All Rights Reserved. 14 Panel Discussion - HITRUST Certification & Assessment Process Ashish Kirtikar President, Europe & UK ControlCase Moderator Sriram Lakshmanan Deputy CISO Genpact Chirag Panchal AVP – Infrastructure, Information Security and Compliance HiLabs Inc. Murugaraj Narayanan Senior Director, IT Infra and Security Prochant India Pvt. Ltd.

© ControlCase . All Rights Reserved. Q&A – Open Forum

Thank you for the opportunity to contribute to your IT compliance program. For additional queries/support [email protected]