
Sign up to save your podcasts
Or


Cybersecurity frameworks can learn a lot from HITRUST.
In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.
I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.
Here’s what stood out to me:
The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.
HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.
I personally think that commercial cybersecurity frameworks should take a look at HITRUST.
What were your biggest takeaways? Let me know in the comments.
Follow Ryan on LinkedIn: https://www.linkedin.com/in/ryan-patrick-3699117a/
HITRUST Website: https://hitrustalliance.net/
-----------
Thanks to our sponsor Vanta!
Get back time to focus on strengthening security and scaling your business.
Discover the new way to GRC here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e8&utm_campaign=courses
#hitrust
By Jacob Hill5
44 ratings
Cybersecurity frameworks can learn a lot from HITRUST.
In this episode, Ryan Patrick of HITRUST explains how HITRUST approaches the assurance problem, from centralizing the certification process to frequent updates to the control sets based on threat data.
I barely knew anything about HITRUST going in, but it’s clear they’re tackling the cybersecurity assurance problem in a radically different way.
Here’s what stood out to me:
The centralized approach of HITRUST allows them to provide feedback to its assessment community after each and every assessment which results in assessments that are more consistent and higher quality.
HITRUST certified organizations are contractually required to report incidents which then allows them to evaluate the effectiveness of their controls.
I personally think that commercial cybersecurity frameworks should take a look at HITRUST.
What were your biggest takeaways? Let me know in the comments.
Follow Ryan on LinkedIn: https://www.linkedin.com/in/ryan-patrick-3699117a/
HITRUST Website: https://hitrustalliance.net/
-----------
Thanks to our sponsor Vanta!
Get back time to focus on strengthening security and scaling your business.
Discover the new way to GRC here: https://vanta.com/grcacademy
-----------
Governance, Risk, and Compliance Academy (GRC) Academy is a training and research platform!
Online GRC Training: https://grcacademy.io/courses/?utm_source=podcast&utm_medium=s2-e8&utm_campaign=courses
#hitrust

2,000 Listeners

775 Listeners

653 Listeners

8,012 Listeners

177 Listeners

315 Listeners

189 Listeners

74 Listeners

136 Listeners

2 Listeners

14 Listeners

3 Listeners

2 Listeners

0 Listeners

0 Listeners