Accessibility Statement Skip Navigation
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • Data Privacy
  • Français
  • my CNW 
    • Login
    • Register
  • Client Login 
    • Online Member Centre
    • Next Gen Communications Cloud
    • Cision Communications Cloud®
  • Sign Up
  • Send a Release
Return to PR Newswire homepage
  • News
  • Products
  • Contact
When typing in this field, a list of search results will appear and be automatically updated as you type.

Searching for your content...

No results found. Please change your search terms and try again.
Advanced Search
  • News in Focus
      • Browse News Releases

      • All News Releases
      • All Public Company
      • News Releases Overview

      • Multimedia Gallery

      • All Multimedia
      • All Photos
      • All Videos
      • Multimedia Gallery Overview

      • Trending Topics

      • All Trending Topics
  • Business
      • Auto & Transportation

      • All Automotive & Transportation
      • Aerospace, Defense
      • Air Freight
      • Airlines & Aviation
      • Automotive
      • Maritime & Shipbuilding
      • Railroads and Intermodal Transportation
      • Supply Chain/Logistics
      • Transportation, Trucking & Railroad
      • Travel
      • Trucking and Road Transportation
      • Auto & Transportation Overview

      • View All Auto & Transportation

      • Business Technology

      • All Business Technology
      • Blockchain
      • Broadcast Tech
      • Computer & Electronics
      • Computer Hardware
      • Computer Software
      • Data Analytics
      • Electronic Commerce
      • Electronic Components
      • Electronic Design Automation
      • Financial Technology
      • High Tech Security
      • Internet Technology
      • Nanotechnology
      • Networks
      • Peripherals
      • Semiconductors
      • Business Technology Overview

      • View All Business Technology

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Financial Services & Investing

      • All Financial Services & Investing
      • Accounting News & Issues
      • Acquisitions, Mergers and Takeovers
      • Banking & Financial Services
      • Bankruptcy
      • Bond & Stock Ratings
      • Conference Call Announcements
      • Contracts
      • Cryptocurrency
      • Dividends
      • Earnings
      • Earnings Forecasts & Projections
      • Financing Agreements
      • Insurance
      • Investments Opinions
      • Joint Ventures
      • Mutual Funds
      • Private Placement
      • Real Estate
      • Restructuring & Recapitalization
      • Sales Reports
      • Shareholder Activism
      • Shareholder Meetings
      • Stock Offering
      • Stock Split
      • Venture Capital
      • Financial Services & Investing Overview

      • View All Financial Services & Investing

      • General Business

      • All General Business
      • Awards
      • Commercial Real Estate
      • Corporate Expansion
      • Earnings
      • Environmental, Social and Governance (ESG)
      • Human Resource & Workforce Management
      • Licensing
      • New Products & Services
      • Obituaries
      • Outsourcing Businesses
      • Personnel Announcements
      • Real Estate Transactions
      • Residential Real Estate
      • Small Business Services
      • Socially Responsible Investing
      • Surveys, Polls and Research
      • Trade Show News
      • General Business Overview

      • View All General Business

  • Science & Tech
      • Consumer Technology

      • All Consumer Technology
      • Artificial Intelligence
      • Blockchain
      • Cloud Computing/Internet of Things
      • Computer Electronics
      • Computer Hardware
      • Computer Software
      • Consumer Electronics
      • Cryptocurrency
      • Data Analytics
      • Electronic Commerce
      • Electronic Gaming
      • Financial Technology
      • Mobile Entertainment
      • Multimedia & Internet
      • Peripherals
      • Social Media
      • STEM (Science, Tech, Engineering, Math)
      • Supply Chain/Logistics
      • Wireless Communications
      • Consumer Technology Overview

      • View All Consumer Technology

      • Energy & Natural Resources

      • All Energy
      • Alternative Energies
      • Chemical
      • Electrical Utilities
      • Gas
      • General Manufacturing
      • Mining
      • Mining & Metals
      • Oil & Energy
      • Oil and Gas Discoveries
      • Utilities
      • Water Utilities
      • Energy & Natural Resources Overview

      • View All Energy & Natural Resources

      • Environ­ment

      • All Environ­ment
      • Conservation & Recycling
      • Environmental Issues
      • Environmental Policy
      • Environmental Products & Services
      • Green Technology
      • Natural Disasters
      • Environ­ment Overview

      • View All Environ­ment

      • Heavy Industry & Manufacturing

      • All Heavy Industry & Manufacturing
      • Aerospace & Defense
      • Agriculture
      • Chemical
      • Construction & Building
      • General Manufacturing
      • HVAC (Heating, Ventilation and Air-Conditioning)
      • Machinery
      • Machine Tools, Metalworking and Metallurgy
      • Mining
      • Mining & Metals
      • Paper, Forest Products & Containers
      • Precious Metals
      • Textiles
      • Tobacco
      • Heavy Industry & Manufacturing Overview

      • View All Heavy Industry & Manufacturing

      • Telecomm­unications

      • All Telecomm­unications
      • Carriers and Services
      • Mobile Entertainment
      • Networks
      • Peripherals
      • Telecommunications Equipment
      • Telecommunications Industry
      • VoIP (Voice over Internet Protocol)
      • Wireless Communications
      • Telecomm­unications Overview

      • View All Telecomm­unications

  • Lifestyle & Health
      • Consumer Products & Retail

      • All Consumer Products & Retail
      • Animals & Pets
      • Beers, Wines and Spirits
      • Beverages
      • Bridal Services
      • Cannabis
      • Cosmetics and Personal Care
      • Fashion
      • Food & Beverages
      • Furniture and Furnishings
      • Home Improvement
      • Household, Consumer & Cosmetics
      • Household Products
      • Jewelry
      • Non-Alcoholic Beverages
      • Office Products
      • Organic Food
      • Product Recalls
      • Restaurants
      • Retail
      • Supermarkets
      • Toys
      • Consumer Products & Retail Overview

      • View All Consumer Products & Retail

      • Entertain­ment & Media

      • All Entertain­ment & Media
      • Advertising
      • Art
      • Books
      • Entertainment
      • Film and Motion Picture
      • Magazines
      • Music
      • Publishing & Information Services
      • Radio & Podcast
      • Television
      • Entertain­ment & Media Overview

      • View All Entertain­ment & Media

      • Health

      • All Health
      • Biometrics
      • Biotechnology
      • Clinical Trials & Medical Discoveries
      • Dentistry
      • FDA Approval
      • Fitness/Wellness
      • Health Care & Hospitals
      • Health Insurance
      • Infection Control
      • International Medical Approval
      • Medical Equipment
      • Medical Pharmaceuticals
      • Mental Health
      • Pharmaceuticals
      • Supplementary Medicine
      • Health Overview

      • View All Health

      • Sports

      • All Sports
      • General Sports
      • Outdoors, Camping & Hiking
      • Sporting Events
      • Sports Equipment & Accessories
      • Sports Overview

      • View All Sports

      • Travel

      • All Travel
      • Amusement Parks and Tourist Attractions
      • Gambling & Casinos
      • Hotels and Resorts
      • Leisure & Tourism
      • Outdoors, Camping & Hiking
      • Passenger Aviation
      • Travel Industry
      • Travel Overview

      • View All Travel

  • Policy & Public Interest
      • Policy & Public Interest

      • All Policy & Public Interest
      • Advocacy Group Opinion
      • Animal Welfare
      • Canadian Federal Government
      • Canadian Municipal Government
      • Canadian Provincial Government
      • Corporate Social Responsibility
      • Domestic Policy
      • Economic News, Trends, Analysis
      • Education
      • Environmental
      • European Government
      • FDA Approval
      • Federal and State Legislation
      • Federal Executive Branch & Agency
      • Foreign Policy & International Affairs
      • Homeland Security
      • Labor & Union
      • Legal Issues
      • Natural Disasters
      • Not For Profit
      • Patent Law
      • Public Safety
      • Trade Policy
      • Policy & Public Interest Overview

      • View All Policy & Public Interest

  • People & Culture
      • People & Culture

      • All People & Culture
      • Aboriginal, First Nations & Native American
      • African American
      • Asian American
      • Children
      • Diversity, Equity & Inclusion
      • Hispanic
      • Lesbian, Gay & Bisexual
      • Men's Interest
      • People with Disabilities
      • Religion
      • Senior Citizens
      • Veterans
      • Women
      • People & Culture Overview

      • View All People & Culture

  • Advanced Search
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Hamburger menu
  • Cision Canada
  • Send a Release
  • FR
    • Phone

    • 877-269-7890 from 8 AM - 10 PM ET

    • ALL CONTACT INFO
    • Contact Cision

      877-269-7890
      from 8 AM - 10 PM ET

  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • News in Focus
    • Browse All News
    • Multimedia Gallery
    • Trending Topics
  • Business
    • Auto & Transportation
    • Business Technology
    • Entertain­ment & Media
    • Financial Services & Investing
    • General Business
  • Science & Tech
    • Consumer Technology
    • Energy & Natural Resources
    • Environ­ment
    • Heavy Industry & Manufacturing
    • Telecomm­unications
  • Lifestyle & Health
    • Consumer Products & Retail
    • Entertain­ment & Media
    • Health
    • Sports
    • Travel
  • Policy & Public Interest
    • Policy & Public Interest
  • People & Culture
    • People & Culture
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Overview
  • Cision Communications Cloud®
  • Monitoring
  • Distribution
  • Multimedia
  • Guaranteed Paid Placement
  • AI Tools
  • IR
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media
  • Worldwide Offices
  • Send a Release
  • Sign Up
  • Resources
  • Blog
  • Journalists
  • Webcasts
  • GDPR

HITRUST Announces Continuous Assurance through the Proven HITRUST Ecosystem Français

HITRUST Assurance Program Selected by Health3PT in Alignment with Recommended Practices (PRNewsfoto/HITRUST Services Corp.)

News provided by

HITRUST Services Corp.

Oct 01, 2024, 15:00 ET

Share this article

Share toX

Share this article

Share toX

Releases 2025 Vision to Increase Security Sustainability and Outcomes through Continuous Control Monitoring

FRISCO, Texas, Oct. 1, 2024 /CNW/ -- HITRUST, the leading provider of information risk management, security, and compliance assurance, today announces HITRUST Continuous Assurance – the latest strategic evolution based on the proven HITRUST ecosystem. As organizations continue to balance the cost and complexity of security and compliance monitoring with the need to achieve security outcomes, a systematic and efficient approach for continuous assurance is essential. Security threats are not static and the need to efficiently reduce evidence decay and continually ensure that security requirements remain relevant and reliable is vital given the evolving threat landscape.

Continue Reading

"The traditional overhead and a growing number of new, proprietary and inefficient approaches trying to speed up outdated practices must fall to the side to improve cybersecurity outcomes without burdening vital services across multiple industries," said Robert Booker, Chief Strategy Officer, HITRUST during his keynote at HITRUST Collaborate conference. "Approaches that prioritize compliance over security are understandable in highly regulated industries but are unfortunately short-sighted and part of the problem and not the solution."

HITRUST Announces Continuous Assurance through the Proven HITRUST Ecosystem

Post this

Legacy approaches do not build on a proven foundation of relevant controls, do not keep up with cyber threats, do not enable cybersecurity insurance risk underwriting as they lack provable security outcomes and validation, or assurance based on quality, transparency, and integrity. The advent of transformative technologies such as generative AI make this an even more challenging problem with new threats and vulnerabilities to overcome.

Evidence decay has always been a problem for governance systems based solely on auditing and HITRUST has largely mitigated that risk through its comprehensive and centralized quality system, rapid-recertification requirements, and the validation of policies and procedures that underpin security outcomes. In addition, the HITRUST system is built on a maturity model that encourages organizations to seek higher levels of security maturity including measurement and management of security requirements.

Continuous Assurance is possible on top of the proven HITRUST ecosystem that has successfully validated and certified thousands of systems serving multiple industries. After 15 years, HITRUST continues to demonstrate high levels of success as show by the 2024 HITRUST Trust Report where 99.4% of current HITRUST certifications, including organizations of varying sizes in many industries, did not report a breach over the past two-year period (2022 and 2023) while operating in one of the most aggressive cyber-attack environments in history. This success is enabled by the combination of the HITRUST CSF alongside a required methodology that assesses control maturity using an innovative PRISMA-based control scoring model and backed by thousands of qualified and independent assessors globally – all monitored by the centralized HITRUST quality assurance system.

"HITRUST certification at the r2 level requires a solid foundation of policy, procedures and controls implementation which provides a higher level of assurance based upon direct rather than circumstantial evidence", said Bimal Sheth, EVP of Standards Development and Assurance Operations, HITRUST. "HITRUST is building on this proven framework as the foundation for Continuous Assurance."

Continuous Assurance Elements:

Continuous Assurance goes the last mile – enabling integration with technologies that provide security control measurement and management. The result is unprecedented levels of assurance by minimizing evidence decay through monitoring of key assurance evidence and security telemetry on a continuous basis – all designed to detect or avoid drift in an organization's control posture. Multiple existing and planned capabilities make Continuous Assurance possible:

  1. Continuous Monitoring Taxonomy through the Next Generation HITRUST CSF: Control requirements require different approaches to continuous assurance to ensure relevancy and reliability of security maturity oversight. The identification of control requirements categories suitable for continuous assurance will be supported in the Next Generation of the HITRUST CSF, rolling out in phases beginning in 2025, starting with HITRUST CSF v12.
  2. Continuous Monitoring Workflow Enhancements: The HITRUST MyCSF will contain new workflow capabilities that allow assessed entities to publish evidence updates and seek validation of evidence of continued control sustainability. Inspection and approval will vary by control category and the system will support the relationships and workflow needed to analyze submitted evidence and confirm that it is both suitable for the control requirement and the underlying scope of the certification. Depending on the rigor and importance of different control requirements, External Assessors will be needed to examine and validate security outcomes and will be vital contributors to Continuous Assurance outcomes.
  3. Automated Evidence Collection: HITRUST's existing Automated Evidence Collection capability supports integration with assessed entities existing technology and compliance frameworks. These services provide an important foundation by providing the baseline of evidence used for security and compliance assurance while reducing cost and complexity.
  4. Continuous Outcome Inspection: New HITRUST services will be available beginning in late 2025 that allow qualified service providers and technology suppliers to demonstrate proven fidelity, integrity and sufficient integration capabilities to HITRUST that inform security maturity scores and prove that security requirements remain achieved through their systems. Selected, qualified, and leading cloud service providers and security technology providers will provide these services all delivered on top of the robust and existing shared responsibility and inheritance capabilities provided by HITRUST.
  5. Results Distribution System: HITRUST's existing digital platform enables the seamless distribution and integration of assessment and certification results, corrective action plans (CAPS), and status updates – eliminating reliance on PDF reports and allowing for electronic examination of security outcomes plus analysis of individual maturity metrics, and monitoring of remediation commitments on demand and with higher fidelity.
  6. Governance, Risk and Compliance Integration: HITRUST assessment results and assurance outcomes may now be integrated directly into supporting third-party risk management and GRC systems, ensuring faster and more accurate analysis, quicker remediation, and increased transparency, including vital Third-Party Risk Management, workflow support with improvements in efficiency, and clear and traceable documentation. 

The HITRUST Continuous Assurance system, by design, will support both systemic control monitoring through Continuous Outcome Inspection and the collection of security artifacts with validation workflows that prove conformance with required policies and procedures. Mature and complex systems will likely require a combination of automated and artifact-oriented forms of security monitoring to ensure that policies and procedures remain relevant.

Building on a Proven Ecosystem:

Continuous assurance is only achievable when delivered on top of a proven ecosystem. Over the past 15 years, HITRUST has built the ecosystem ready to deliver Continuous Assurance including:

  1. Broad Assessment Portfolio: HITRUST offers a comprehensive range of assessment options that cover varying levels of assurance. This allows organizations and relying parties to align their risk management efforts with Threat and Adaptive Control Selection that is continuously updated as threats evolve.
  2. Cyber Threat Adaptive Controls: The HITRUST CSF is continuously updated as new cyber threats are identified and in response to active threats. This ensures organizations are continually considering the changes needed to manage their risks and sustain the required protections from the security system. Assurances only remain valid if they are implementing the correct security requirements to address present threats.
  3. Assurance Quality Management: a centralized, proven and transparent approach to quality assurance that includes examination, testing, and validation of security evidence by trained and qualified external assessors. Quality standards are published and are appropriately measured, tested, and validated first by external assessors and then by HITRUST. This ensures that the security outcomes and the resulting certification are transparent, scalable, consistent, accurate and demonstrate the integrity required by relying parties including regulators.
  4. Inheritance and Shared Responsibility: In many cases, security controls may be inherited from service providers such as Cloud Service Providers and now AI Service Providers. This capability allows assessed entities to rely on those service providers to provide components of the security fabric based upon the validation and certification of their services or to share responsibility for controls. Continuous Assurance will support the inheritance and shared responsibility of controls in appropriate use cases.

Powered by Platform Integrations:

HITRUST Continuous Assurance is building on an expanding network of integration capabilities from recognized platform and service providers. These integrations will streamline the process of managing information and cybersecurity risks and allow customers of the HITRUST ecosystem to integrate Continuous Assurance capabilities from multiple suppliers as available.

Delivering Proven Outcomes:

HITRUST Continuous Assurance delivers on top of a rich and proven maturity model. However, breaches and disruptions to services from cyber events still occur and Continuous Assurance will provide even higher security outcomes and greater levels of assurance. "The information obtained from monitoring controls in a continuous manner can help organizations continually assess the state of their information security controls and subsequently the amount of additional residual risk the organization may be incurring. Introducing more continuous, or ongoing approaches over point-in-time assessments and control gap analysis increases the fidelity of ongoing, risk-based decisions and improves cybersecurity outcomes", said Dr. Bryan Cline, Chief Research Officer, HITRUST.

Stay Informed: 

Stay informed about Continuous Assurance here

About HITRUST

HITRUST, the leader in enterprise risk management, information security, and compliance assurances, offers a certification system for the application and validation of security, privacy, and AI controls, informed by over 50 standards and frameworks. The company's threat-adaptive approach delivers the most relevant and reliable solution, including multiple selectable and traversable control sets, over 100 independent assessment firms, centralized quality reviews and certification, and a powerful SaaS platform enabling its program and ecosystem. For over 17 years, HITRUST has led the assurance industry and today is widely recognized as the most trusted solution to establish, maintain, and demonstrate security capabilities for risks management and compliance.

To learn more about HITRUST, go to: www.hitrustalliance.net

For media inquiries, please contact:
Leslie Kesselring
Kesselring Communications for HITRUST
[email protected]
503-358-1012

SOURCE HITRUST Services Corp.

Modal title

Organization Profile

HITRUST Services Corp.

    Also from this source

  • HITRUST Quarterly Threat Analysis Confirms CSF v11.2 Addresses 100% of MITRE ATT&CK® Techniques

  • HITRUST 2025 TRUST REPORT DEMONSTRATES IMPROVED CYBERSECURITY OUTCOMES FOR CERTIFIED ORGANIZATIONS

  • HITRUST Delivers on Commitment to Make Third Party Risk Management Practical and Efficient

Contact Cision

  • 866-245-2317
    from 8 AM - 10 PM ET
  • Become a Client
  • Request a Demo
  • Editorial Bureaus
  • Partnerships
  • General Enquiries
  • Media

Products

  • Cision Communications Cloud®
  • Media Monitoring
  • Content Distribution
  • Multimedia Distribution
  • Measurement & Analytics
  • Investor Relations

About

  • About Cision Canada
  • About Cision
  • Media Partners
  • Careers
  • Accessibility Statement
  • APAC
  • APAC - Simplified Chinese
  • APAC - Traditional Chinese
  • Brazil
  • Canada
  • Czech
  • Denmark
  • Finland
  • France
  • Germany
  • India
  • Indonesia
  • Israel
  • Japan
  • Korea
  • Mexico
  • Middle East
  • Middle East - Arabic
  • Netherlands
  • Norway
  • Poland
  • Portugal
  • Russia
  • Slovakia
  • Spain
  • Sweden
  • United States
  • Vietnam

My Services

  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud®
  • my CNW

Do not sell or share my personal information:

  • Submit via [email protected] 
  • Call Privacy toll-free: 877-297-8921

Contact Cision

Products

About

My Services
  • All News Releases
  • Online Member Centre
  • Next Gen Communications Cloud
  • Cision Communications Cloud
  • my CNW
877-269-7890
from 8 AM - 10 PM ET
  • Terms of Use
  • Information Security Policy
  • Site Map
  • Cookie Settings
  • Accessibility Statement
Copyright © 2025 CNW Group Ltd. All Rights Reserved. A Cision company.