When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".
Marking a requirement statement ''Not Applicable (N/A)'' requires careful justification. In r2 assessments, compliance factors such as HIPAA, PCI-DSS, GDPR, or state-specific laws may trigger requirements that would not otherwise apply. Therefore, an assessor must verify that all compliance factors have been considered before permitting an N/A designation. For example, a requirement related to cardholder data might seem irrelevant unless PCI-DSS was selected as a compliance factor; in that case, it becomes mandatory. HITRUST QA scrutinizes N/A markings to ensure they are not misused to exclude applicable requirements. Incorrect use of N/A may result in CAPs or QA rejection. Thus, compliance factors must always be reviewed first to confirm whether the requirement is truly outside scope.
Willard
2 months agoCaitlin
3 months agoCoral
3 months agoBrynn
3 months agoMacy
4 months agoElke
4 months agoJulene
4 months agoStephane
4 months agoMyra
4 months agoDion
4 months agoLavonna
5 months agoThea
5 months agoWynell
5 months agoLura
5 months agoJosephine
5 months agoElbert
5 months agoRex
6 months agoBreana
6 months agoMickie
6 months agoNatalya
7 months agoDiane
7 months agoWillodean
7 months agoFreida
7 months agoKristofer
7 months agoGerald
8 months agoWilda
8 months agoFletcher
2 months agoPeter
2 months agoDulce
2 months agoBrittney
6 months ago