An Overview of the HITRUST CSF and Related Frameworks
The HITRUST CSF provides an integrated, prescriptive framework that works with the needs of the healthcare industry in order to comply with the necessary standards. This framework is able to be scaled for the various sizes and types of organizations and their control systems. It also allows for the tailoring and scaling of controls with HITRUST oversight to ensure that the integrity of the systems remain in-tact and application remains consistent.
The HITRUST CSF and ISO 27001
HITRUST recognizes the complex, global nature of healthcare industry and the need for an industry-specific approach to information protection. Because of this, ISO/IEC 27001 was chosen as the foundation from which the HITRUST CSF was built upon due to its place as an international standard for information security that could be modified and implemented for any organization.
ISO 27001 differs greatly from the HITRUST CSF, as ISO 27001 is not control-compliance based, but is instead a management/process model for the Information Management System that is assessed. One of the major benefits of the HITRUST CSF over ISO 27001 is the ability to select and create practical controls. While ISO 27001 does have the ability to tailor controls in order to better-fit organizations who cannot implement a specific control, but it is not as complete in its ability to be tailored or scaled.
The HITRUST CSF and NIST 800-53
The HITRUST CSF also pulls from NIST SP 800-53, which was designed for United States government agencies. However, the standards are applicable to many different types of organizations. One of the key differences between NIST 800-53 and the HITRUST CSF is that NIST 800-53 does not address the specific needs within the healthcare industry.
Both NIST 800-53 and HITRUST CSF are compliance solutions that assess a set of controls through gap analysis of any controls considered within the scope for the organization or system.
One of the issues with NIST 800-53 that the HITRUST CSF takes care of is the ability to scale controls to the specific organization. NIST 800-53 has no formal mechanism for an organization to do so. NIST 800-53 does have the ability to tailor controls in certain situations when an organization is unable to implement a specific control, though it is more limited than the HITRUST CSF. However, this is limited because NIST 800-53 defines control parameters based on the highest potential impact, regardless of the size or type of organization.
The HITRUST CSF and PCI DSS
PCI DSS is a payment card industry standard used to protect payment card data. Founded by the five major card brands, Visa, MasterCard, American Express, Discover and JCB, PCI DSS defines controls to enhance credit and debit card security.
In many ways, HITRUST has used this type of methodology in the creation of the HITRUST healthcare standard. HITRUST receives input from their board of directors, who are industry experts from major healthcare organizations, to tailor the framework to the industry’s needs.
While there are a variety of different audit options for any organization, the HITRUST CSF provides scalable, prescriptive solutions for organizations of any type. By pulling from major pre-existing frameworks and working with healthcare organizations to better-understand their needs, the HITRUST CSF provides a complete, certifiable security standard.