The Offline Assessment function allows assessors which capability?
If an organization has a policy against uploading sensitive data to third parties, what option would facilitate providing evidence to the HITRUST QA team to support maturity level scoring?
Vulnerability testing should never be performed on client systems by an external assessor.
How many domains are there in an assessment?