When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".
Marking a requirement statement ''Not Applicable (N/A)'' requires careful justification. In r2 assessments, compliance factors such as HIPAA, PCI-DSS, GDPR, or state-specific laws may trigger requirements that would not otherwise apply. Therefore, an assessor must verify that all compliance factors have been considered before permitting an N/A designation. For example, a requirement related to cardholder data might seem irrelevant unless PCI-DSS was selected as a compliance factor; in that case, it becomes mandatory. HITRUST QA scrutinizes N/A markings to ensure they are not misused to exclude applicable requirements. Incorrect use of N/A may result in CAPs or QA rejection. Thus, compliance factors must always be reviewed first to confirm whether the requirement is truly outside scope.
Caitlin
10 hours agoCoral
6 days agoBrynn
11 days agoMacy
16 days agoElke
21 days agoJulene
26 days agoStephane
1 month agoMyra
1 month agoDion
1 month agoLavonna
2 months agoThea
2 months agoWynell
2 months agoLura
2 months agoJosephine
2 months agoElbert
2 months agoRex
3 months agoBreana
3 months agoMickie
3 months agoNatalya
4 months agoDiane
4 months agoWillodean
4 months agoFreida
4 months agoKristofer
4 months agoGerald
4 months agoWilda
5 months agoBrittney
3 months ago