Verigo Global
//HITRUST Toolkit
Healthcare TrustHITRUST CSF · e1 · i1 · r2

The HITRUST toolkit, ready to deploy.

A complete, practitioner-maintained document set — 20 policies, 16 procedures, and all 147 CSF control reference templates across the 14 categories — tailored to your scope so you build a certifiable program without starting from a blank page.

Inside the toolkit
20
Approval-ready policies
16
Operational procedures
147
CSF control reference templates
180+
Documents, maturity & evidence
Overview

One framework that harmonizes them all — pre-built and tailored.

The Verigo HITRUST toolkit is the document backbone of a certifiable CSF program. The HITRUST CSF harmonizes HIPAA, ISO 27001, NIST, and PCI into one prescriptive, scalable framework — and this toolkit ships implementation templates for every one of its 147 control references.

Each artefact is maintained by senior practitioners and tailored to your scope and assessment type — then embedded into how you operate, the Compliance by Design way, so the evidence MyCSF needs is produced by the process itself.

Tailored to your factors

Every policy and control is shaped to your organizational, system, and regulatory factors — not a one-size-fits-all template dump.

Maturity-model ready

Each control reference is built around the CSF maturity levels — policy, process, and implemented — so scoring is structured from day one.

Cross-framework ready

Controls are mapped so the same evidence supports HIPAA, ISO 27001, and NIST without duplication.

Coverage

Built for every assessment — and all 14 categories

The toolkit scales from an e1 essentials assessment to a fully certifiable r2, covering all 14 HITRUST CSF control categories.

Three assessment types
e1
44requirements
Essentials, 1-year
Foundational assurance
Valid 1 year
i1Most popular
182requirements
Implemented, 1-year
Moderate assurance
Valid 1 year
r2
200+requirements
Risk-based, 2-year
High / Certifiable assurance
Valid 2 years
14 CSF control categories · 147 control references
00
1 refs
01
25 refs
02
9 refs
03
4 refs
04
2 refs
05
11 refs
06
10 refs
07
5 refs
08
13 refs
09
32 refs
10
13 refs
11
5 refs
12
5 refs
13
12 refs
Toolkit contents

Browse the full set — and take it with you

Explore every policy, procedure, and control reference in the toolkit. Download any list as a branded PDF; we'll ask for a few details so a practitioner can tailor it to you.

Policy Library
The complete, CSF-aligned policy set — 20 approval-ready policies covering all 14 HITRUST control categories.
01
Information Security Management Program Policy
Top-level ISMP mandate, objectives, and management commitment.
02
Access Control Policy
Rules for granting, reviewing, and revoking system access.
03
Human Resources Security Policy
Security across the employment lifecycle.
04
Risk Management Policy
How information risk is assessed, treated, and evaluated.
05
Information Security Policy
The overarching security policy document and review cadence.
06
Organization of Information Security Policy
Roles, responsibilities, and external-party coordination.
07
Compliance Policy
Meeting legal, regulatory, and contractual obligations including HIPAA.
08
Asset Management Policy
Inventory, ownership, classification, and handling of assets.
09
Physical & Environmental Security Policy
Protection of facilities, equipment, and secure areas.
10
Communications & Operations Management Policy
Secure day-to-day operation of systems and networks.
11
Malware Protection Policy
Protection against malicious and mobile code.
12
Backup Policy
Backup scope, frequency, encryption, and restoration testing.
13
Network Security Policy
Segmentation, controls, and monitoring of networks.
14
Secure Development Policy
Security requirements across the development lifecycle.
15
Cryptography & Key Management Policy
Use of encryption and cryptographic key management.
16
Vulnerability & Patch Management Policy
Identifying and remediating technical vulnerabilities.
17
Incident Management Policy
Detecting, reporting, and responding to security incidents.
18
Business Continuity Policy
Maintaining and recovering operations during disruption.
19
Privacy Policy
Lawful collection, use, retention, and disclosure of covered information.
20
Third-Party & Supplier Security Policy
Security requirements for vendors and business associates.
Samples

See exactly what you'll receive

Representative pages from the toolkit — a policy, a procedure, a CSF control reference template, and an assessment-readiness checklist.

Want the full sample?

Preview the complete package index as a branded PDF — we'll ask for a few details first.

Samples are illustrative. Delivered documents are tailored to your organization and branding.

POL-02 · Access Control Policy

Access Control Policy

Classification
Confidential
Version
2.1
Owner
CISO
Framework
HITRUST CSF v11
1.0Purpose
This policy establishes the requirements for controlling access to systems and covered information on a least-privilege, need-to-know basis, in support of HITRUST CSF control references 01.a–01.c and 01.q.
2.0Scope
Applies to all workforce members, contractors, and business associates who access organizational systems, applications, and covered information.
3.0Policy statements
  • Access is provisioned through a formal request and approval workflow tied to documented roles.
  • Privileged access is restricted, logged, and reviewed at least quarterly.
  • Multi-factor authentication is enforced for remote and administrative access.
  • Access rights are recertified periodically and revoked promptly on a leaver event.
4.0Maturity levels
Documented as policy, operationalized as process, and verified as implemented — the three CSF maturity levels scored in MyCSF.
5.0Review
Reviewed annually or upon significant change. Next review: 12 months from approval.
Packages

Build without the evaluation

Start from the document toolkit at $1,495 and add exactly what you need — see your custom total update live, then download a quote.

Starter

The complete document toolkit, ready to deploy.

All 20 policies, 16 procedures & 147 control reference templates
Editable source files (Word & Excel)
MyCSF-ready control mapping
Maturity & evidence checklists
Most popular
Professional

The toolkit tailored to you, with practitioner guidance.

Everything in Starter
Documents tailored to your scope & assessment type
Scoping & factor workshop
Online readiness self-assessment
Enterprise

End-to-end support, all the way to validated.

Everything in Professional
Hands-on implementation support
Gap assessment & remediation
MyCSF object setup & evidence packaging
Starts from $1,495 · add only what you need · live pricing
Online evaluation · assessment-aware

Know where you stand before MyCSF.

Our online HITRUST readiness evaluation scores your current state against the CSF categories for your chosen assessment type — and maps every gap straight to the toolkit documents that close it.

01

Pick your assessment type

Choose e1, i1, or r2 — your choice tailors the evaluation to exactly the categories and depth that apply.

02

Get your readiness score

An instant maturity score with a gap heat-map across the in-scope CSF categories.

03

See your next steps

A prioritized action plan showing which toolkit documents and control references close each gap.