Hacker News new | ask | show | jobs
by tuke 1929 days ago
This has bugged me for a long time.

My company complies with HITRUST. Many of the HITRUST controls are syntheses of controls found in NIST, ISO, and other organizations.

In some cases, I want to know where a HITRUST control comes from: But since I can't look at ISO without paying, I am blocked from understanding the provenance of some HITRUST controls.

I don't like that.