Hacker News new | ask | show | jobs
by tristor 1515 days ago
I understand exactly what you mean, but having done HITRUST CSF certification for a system, I will say that it is not as bad as some others, because at least HITRUST is /very/ clear in its requirements, so there's not as much vagaries and back and forth with auditors after the fact, or rushed changes. It's truly a nightmare to meet, but once done you can be assured you will pass the audit fairly.