HITRUST MyCSF
About HITRUST MyCSF
HITRUST MyCSF Pricing
Free trial:
Not Available
Free version:
Not Available
Most Helpful Reviews for HITRUST MyCSF
1 - 10 of 10 Reviews
Ross
Biotechnology, 11-50 employees
Used daily for less than 2 years
OVERALL RATING:
5
EASE OF USE
4
VALUE FOR MONEY
4
CUSTOMER SUPPORT
5
FUNCTIONALITY
4
Reviewed November 2021
Productive tool.
There is no getting away from the detail and tedium of this type of activity, no matter what tool is used. My experience with HITRUST has been much more positive than it has been with other similar tools (RSA Archer, for example).
PROSWhen compared to other tools used to manage the compliance/risk/assurance aspect of a business, I find HITRUST to be more user friendly and less tedious to use. No tool like this will be any better than the input provided to it, and to this point, I find the MyCSF to be more precise, more focused - from the scoping exercise to the information capture activity - than other products in this area.
CONSCannot comment on this point yet. I prefer to await the future product integration with the FAIR risk management structure and comment after using that.
Todd
Security and Investigations, 11-50 employees
Used daily for more than 2 years
OVERALL RATING:
5
EASE OF USE
4
VALUE FOR MONEY
5
CUSTOMER SUPPORT
5
FUNCTIONALITY
4
Reviewed September 2022
HITRUST MyCSF - Mostly great interface for working with the HITRUST CSF
Building an assessment, running reports, and accessing the CSF library are relatively easy, and the new tasks, workflows, and webforms are great.
CONSThe new document viewer functionality when accessing linked documents is a huge pain; viewing the documents in the browser is not ideal, controls are limited, and saving the document out of the viewer often does not maintain the original filename, even when you choose the options to get the "original" document. I would not be sad to see it go.
Allison
Accounting, 5,001-10,000 employees
Used weekly for less than 12 months
OVERALL RATING:
3
EASE OF USE
3
VALUE FOR MONEY
2
CUSTOMER SUPPORT
3
FUNCTIONALITY
3
Reviewed May 2023
MyCSF HITRUST Reviee
This software does a great job of condensing large amounts of information into smaller manageable chucks with the ability to begin submitting domains as they are completed vs the entire audit. The ability to use the offline assessment for external assessors is a time saving feature that would be nice to have for all credits not just subscriptions.
CONSThe training required to use the software is very expensive and seems to be more of a sales pitch vs a training. The documentation upload features are very clunky and require a lot of linking if not using the offline assessment.
Brooke
Insurance, 5,001-10,000 employees
Used daily for less than 2 years
OVERALL RATING:
4
EASE OF USE
2
VALUE FOR MONEY
3
CUSTOMER SUPPORT
5
FUNCTIONALITY
3
Reviewed November 2021
Handy tool, but not as user friendly as it could be.
We use MyCSF for our annual HITRUST validation efforts. It is a tool that we have to use to remain HITRUST Certified. It is not something we would use otherwise.
PROSIt is a good way to track and store the evidence needed for the annual HITRUST validation efforts.
CONSWe tend to only use MyCSF for the tasks that must be reported through the tool for the annual Validation process. Instead, we track our audit and compliance efforts outside of the tool. MyCSF is not as user friendly and intuitive as I, and others at my company, would like. It is not a great tool for storing documents, as they need to be uploaded in many different places and then those policies or procedure documents are not always easy to find.
Raj
Hospital & Health Care, 11-50 employees
Used weekly for more than 2 years
OVERALL RATING:
5
EASE OF USE
2
VALUE FOR MONEY
5
CUSTOMER SUPPORT
4
FUNCTIONALITY
5
Reviewed November 2021
Why should you use MyCSF
Helps businesses to understand the prescriptive nature of the HITRUST controls including the implementation, measured and managed maturity
PROSAssess once, review many times, and update as needed so keep the security posture of the scope in check. Thus creating efficiency for compliance, regulatory and security needs.
CONSImprovements around third party GRC products or tracking software would be ideal. Don't have to depend on the myCSF tool all the time.
Reason for choosing HITRUST MyCSF
None
Rick
Marketing and Advertising, 501-1,000 employees
Used monthly for more than 2 years
OVERALL RATING:
3
EASE OF USE
3
VALUE FOR MONEY
4
CUSTOMER SUPPORT
2
FUNCTIONALITY
4
Reviewed November 2021
Want to be certified? Use MyCSF!
The MyCSF tool has a single minded focus on one thing, and does that one thing pretty well - helping you scope, organize, and complete HITRUST assessments. Recent releases have focused heavily on making the tool easier to use and less opaque for those who don't have a deep understanding of the HITRUST methodology and process, including better commenting, more clear assessment status messages, and automated error checking instead of waiting for a human to do all of the QA.
CONSThe tool can be confusing to navigate for new users, and documentation on the process can be a bit lacking in some areas. MyCSF does not allow you to link files or evidence from internal GRC platforms or private storage systems (Dropbox, Google Drive, etc), it must be uploaded to the tool directly.
Marcus
Health, Wellness and Fitness, 1,001-5,000 employees
Used weekly for less than 2 years
OVERALL RATING:
4
EASE OF USE
4
FUNCTIONALITY
5
Reviewed December 2021
Essential tool for HITRUST
It's been a great tool to keep track of control statement, make comparisons to other authoritative CSFs, and interact with the assessments.
PROSIt's very intuitive and easy to figure out. For the most part, I was able to get right in and play around the environment without much training or guidance.
CONSThere are a number of key features that are somewhat hidden from the assessment that you have to know where to find. When completing the factors section of the "admin and scoping" section of the assessment, I wish I knew how much use the "need help" button on the right side would have cleared up certain definitions.
Robert
Facilities Services, 201-500 employees
Used monthly for more than 2 years
OVERALL RATING:
3
EASE OF USE
3
VALUE FOR MONEY
3
CUSTOMER SUPPORT
5
FUNCTIONALITY
3
Reviewed September 2022
Serves its Purpose
It definitely serves its purpose, but this is used more because it is the tool of choice for our auditor.
PROSThe easy of communications while providing evidence to and from the auditors handling your validated assessment helps the assessment go much smoother.
CONSIt feels like this tool is better for the auditors opposed to the end user. The ability to see what evidence is linked is great but corrective actions is clunky and offered little value beyond tracking.
Abdul
Information Technology and Services, 1,001-5,000 employees
Used monthly for more than 2 years
OVERALL RATING:
4
EASE OF USE
4
VALUE FOR MONEY
2
CUSTOMER SUPPORT
4
FUNCTIONALITY
4
Reviewed November 2021
HITRUST MyCSF User Experience
MyCSF lets the user configure all the applicable domains and controls, upload evidence, and track progress. It provides explanation of the controls, and the implementation guidance. This educates the user on the evidence that should be collected to satisfy the control.
CONSWe use JIRA to track submission of evidence for the HITRUST controls. MyCSF doesn't integrate with JIRA. This creates an extra layer of submitting evidence.
Koree
Health, Wellness and Fitness, 1,001-5,000 employees
Used weekly for less than 2 years
OVERALL RATING:
4
EASE OF USE
3
VALUE FOR MONEY
4
CUSTOMER SUPPORT
5
FUNCTIONALITY
4
Reviewed December 2022
MyCSF
Proper scoping is very important and easy to do, especially after a couple of tries. :)
CONSDocument Management, but not really used since we use our own GRC.