HITRUST CSF
HITRUST CSF coverage
How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to HITRUST CSF v11 control references. HITRUST harmonises HIPAA, ISO 27001, and NIST into a single control framework, so the configuration evidence LockList already collects lines up directly with the technical controls a HITRUST assessor looks for.
Readiness mapping, not a HITRUST certification. LockList evidences the technical/configuration controls these platforms expose, strong alignment with HITRUST's foundational e1 / i1 control sets. HITRUST CSF also includes policy, process, and physical controls a config scan can't see, and the required control set is scoped per organisation in MyCSF. A HITRUST certification is issued by the HITRUST Alliance through a validated assessment by an authorized external assessor.
01 · Access Control
| Control | What LockList assesses |
|---|---|
| 01.aAccess control policy | Conditional Access policy visibility and Security Defaults posture, the baseline access control configuration across the tenant. |
| 01.bUser registration | Guest / external user privilege review (M365), how external identities are provisioned and what they can reach. |
| 01.cPrivilege management | Privileged role assignments, directory roles, and PIM just in time elevation (M365); super admin count and admin role assignments (Google); organisation owners (GitHub); root account access keys (AWS). |
| 01.dUser password management | Self service password reset (M365); IAM password policy and access key rotation (AWS); deploy key inventory (GitHub). |
| 01.eReview of user access rights | Privileged role inventory (M365); super admin and admin role review (Google); owner and outside collaborator review (GitHub). |
| 01.jUser authentication for external connections | Legacy / basic authentication blocking and named location conditions (M365); SAML SSO enforcement (GitHub). |
| 01.qUser identification & authentication | MFA for admins and all users, MFA registration coverage and methods, Security Defaults (M365); 2-Step Verification coverage and admin enrollment (Google); org wide 2FA (GitHub); root and IAM user MFA (AWS). |
| 01.rPassword management system | IAM password policy strength, length and complexity requirements (AWS); SSPR enablement (M365). |
| 01.vInformation access restriction | PIM, high privilege application consents and guest privileges (M365); SharePoint / OneDrive external sharing (M365); account level S3 Block Public Access (AWS). |
| 01.xMobile computing & communications | Intune device management coverage and non compliant device count (M365); RMM device inventory and agent coverage (NinjaOne). |
| 02.iRemoval of access rights | Suspended and dormant account review (Google), evidencing timely deprovisioning of departing users. |
09 · Communications & Operations Management
| Control | What LockList assesses |
|---|---|
| 09.aaAudit logging | Sign in and directory audit log accessibility (M365); login and admin audit logs (Google); CloudTrail trail configuration (AWS); activity log accessibility (NinjaOne). |
| 09.abMonitoring system use | Applied Conditional Access visibility, risky user detection via Identity Protection, and Microsoft Secure Score monitoring (M365); open alert review and stale / offline agent detection (NinjaOne). |
| 09.adAdministrator & operator logs | Directory audit logs (M365); admin audit logs (Google); multi region CloudTrail management event logging (AWS). |
| 09.jControls against malicious code | Microsoft Defender / email security licensing posture (M365); antivirus coverage and health across managed endpoints (NinjaOne). |
| 09.mNetwork controls | Legacy authentication blocking and named location (trusted IP) conditions (M365). |
| 09.sInformation exchange policies | SharePoint / OneDrive external sharing and external email auto forwarding (M365); account level S3 public access posture (AWS). |
10 · Systems Acquisition, Development & Maintenance
| Control | What LockList assesses |
|---|---|
| 10.kChange control procedures | Default branch protection rules requiring review before merge (GitHub). |
| 10.mControl of technical vulnerabilities | Secret scanning and push protection (GitHub); non compliant device detection (M365); OS patch status across managed endpoints (NinjaOne). |
06 / 07 · Compliance & Asset Management
| Control | What LockList assesses |
|---|---|
| 06.gCompliance with security policies | Microsoft Secure Score as an ongoing measurement of configuration against the security baseline. |
| 07.aInventory of assets | Tenant licensing / subscription inventory (M365); organisation and verified domain inventory (Google); RMM device and organisation inventory (NinjaOne). |
Every finding in your LockList Report carries its HITRUST CSF control reference alongside SOC 2, ISO 27001, CIS, and HIPAA mappings. Run a free assessment →