Populating the Organization Information in myCSF
Populating the Organization Information page in MyCSF is a critical first step in the HITRUST assessment process. This section serves as the foundation for your assessment by capturing key details about your organization's structure, operational footprint, and risk profile. Accurately completing this page ensures that the right scoping factors, inheritance options, and control requirements are applied throughout the assessment. It is important to note that all of the fields on this page become directly transposed onto the HITRUST Report - ensure the organization name is spelled correctly and no grammatical errors are present throughout.
Below we walkthrough the Organizational Information in HITRUST myCSF and how to fill this out:
Organization/Company Background:
Write a 1–2 paragraph overview of your organization. Suitable content includes your mission statement, values, or business lines (similar to your “About Us” webpage).
Do:
Keep it to 1–2 paragraphs
Check for grammar/spelling
Give a clear overview of what your organization does
Do Not:
Include employee count, geographies served, or compliance/scope details
Use undefined acronyms or industry jargon
Add marketing language (e.g., "We’re the top service provider")
Overview of the Security Organization:
Limit to 3 paragraphs covering:
Security framework used
Security team structure and responsibilities
Governance, monitoring, and objectives of the InfoSec program
Do:
Be concise and use spelling/grammar tools
Keep it high level
Do Not:
Mention specific tools
Disclose scope details or confidential internal information
The last step on this page is to ensure your Contact Info and Primary Mailing Address are current.
This information will be transposed onto the final HITRUST report, so ensure the fields are accurate and free of spelling/grammatical errors.
Populating the Scope of Assessment in myCSF
Scoping is the foundational step in any HITRUST engagement, as it defines the exact boundaries of what will be evaluated for certification. Accurate and well-considered scoping ensures that all relevant systems, applications, networks, and facilities that handle or support sensitive data are properly identified and included. It also helps avoid unnecessary assessment overhead by excluding components that are out of scope. A clear and defensible scope sets the direction for the entire assessment, determines applicable controls, and ensures alignment between the assessed entity, external assessor, and HITRUST.
Below we walkthrough the scope in HITRUST myCSF and how to fill this out:
Platforms/Systems:
Go to PLATFORMS/SYSTEMS > ADD to list your primary in-scope systems (e.g., cloud-hosted platforms, on-prem applications). (see example screenshot above)
Include component types like:
Application(s)
Operating System(s)
Database(s)
Network(s) (if on-premise network is applicable)
Facility(s)
Exclude secondary components (e.g., endpoints, reporting tools, code repositories, AAA platforms), which are implicitly covered.
Facilities:
List only the physical/cloud facilities that host in-scope platforms/systems.
For cloud systems, include your cloud provider’s data center.
For on-premise systems or networking dependencies, include relevant on-site facilities.
Services Outsourced for In-Scope Systems:
Identify outsourced services supporting your in-scope systems (e.g., AWS, GCP, Azure hosting).
For additional guidance, see the HITRUST Scoping Handbook here.