4 ms·
I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18". That looks
by Mesmoria 5y ago
I note that section 1.6 is "Comply with all industry security standards relevant to your business such as PCI DSS, HITRUST, ISO27001, and SSAE 18".
That looks larger than all the other requirements.
- ghiculescu 5y agoYes, unsurprisingly, this is set up to protect incumbents that have collected all these certifications.
- wglb 5y agoI think the intent here is to note that there may be business requirements about these that affect the security of your business. For example, if anyone pays you through credit cards, PCI DSS is non-optional. Certain transactions of health information will require Hitrust. Without them, you won't be able to do business, and while they seem large (PCI DSS if you have another company handle the cards, is a very simple self-assessment.)
- sk5t 5y agoIME the human time cost and direct expense associated with obtaining HITRUST, even if you've already done SOC2, is roughly in line with buying a Lamborghini.