Skip to main content

Populating the Required Information Into myCSF

What do I need to input into myCSF and what are the guidelines to support me?

M
Written by Matthew Udicious
Updated over a month ago

Populating the Organization Information in myCSF

Populating the Organization Information page in MyCSF is a critical first step in the HITRUST assessment process. This section serves as the foundation for your assessment by capturing key details about your organization's structure, operational footprint, and risk profile. Accurately completing this page ensures that the right scoping factors, inheritance options, and control requirements are applied throughout the assessment. It is important to note that all of the fields on this page become directly transposed onto the HITRUST Report - ensure the organization name is spelled correctly and no grammatical errors are present throughout.

Below we walkthrough the Organizational Information in HITRUST myCSF and how to fill this out:

Organization/Company Background:

Write a 1–2 paragraph overview of your organization. Suitable content includes your mission statement, values, or business lines (similar to your “About Us” webpage).

Do:

  • Keep it to 1–2 paragraphs

  • Check for grammar/spelling

  • Give a clear overview of what your organization does

Do Not:

  • Include employee count, geographies served, or compliance/scope details

  • Use undefined acronyms or industry jargon

  • Add marketing language (e.g., "We’re the top service provider")

Overview of the Security Organization:

Limit to 3 paragraphs covering:

  • Security framework used

  • Security team structure and responsibilities

  • Governance, monitoring, and objectives of the InfoSec program

Do:

  • Be concise and use spelling/grammar tools

  • Keep it high level

Do Not:

  • Mention specific tools

  • Disclose scope details or confidential internal information

The last step on this page is to ensure your Contact Info and Primary Mailing Address are current.

This information will be transposed onto the final HITRUST report, so ensure the fields are accurate and free of spelling/grammatical errors.

Populating the Scope of Assessment in myCSF

Scoping is the foundational step in any HITRUST engagement, as it defines the exact boundaries of what will be evaluated for certification. Accurate and well-considered scoping ensures that all relevant systems, applications, networks, and facilities that handle or support sensitive data are properly identified and included. It also helps avoid unnecessary assessment overhead by excluding components that are out of scope. A clear and defensible scope sets the direction for the entire assessment, determines applicable controls, and ensures alignment between the assessed entity, external assessor, and HITRUST.

Below we walkthrough the scope in HITRUST myCSF and how to fill this out:

  1. Platforms/Systems:

    • Go to PLATFORMS/SYSTEMS > ADD to list your primary in-scope systems (e.g., cloud-hosted platforms, on-prem applications). (see example screenshot above)

    • Include component types like:

      • Application(s)

      • Operating System(s)

      • Database(s)

      • Network(s) (if on-premise network is applicable)

      • Facility(s)

    • Exclude secondary components (e.g., endpoints, reporting tools, code repositories, AAA platforms), which are implicitly covered.

  2. Facilities:

    • List only the physical/cloud facilities that host in-scope platforms/systems.

      • For cloud systems, include your cloud provider’s data center.

    • For on-premise systems or networking dependencies, include relevant on-site facilities.

  3. Services Outsourced for In-Scope Systems:

    • Identify outsourced services supporting your in-scope systems (e.g., AWS, GCP, Azure hosting).

For additional guidance, see the HITRUST Scoping Handbook here.

Did this answer your question?