A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]
When testing implementation, the population must include the full set of in-scope assets, not just a subset filtered by existing controls.
AV console (A) only shows devices with AV installed; it would exclude noncompliant assets.
IT asset inventory (C) provides the complete list of laptops, making it the proper source for random sample selection.
Risk register (D) lists risks, not devices.
Capital assets only (B) not comprehensive for all laptops.
Extract Reference (HITRUST Assessment Sampling Guidance, CCSFP [0173]):
Sampling must be based on the complete population from the IT asset inventory; reliance on control-based systems (e.g., AV console) introduces bias.
Annamae
3 days ago