HITRUST CSF

HITRUST CSF coverage

How LockList's Microsoft 365, Google Workspace, GitHub, AWS, Azure, and NinjaOne checks map to HITRUST CSF v11 control references. HITRUST harmonises HIPAA, ISO 27001, and NIST into a single control framework, so the configuration evidence LockList already collects lines up directly with the technical controls a HITRUST assessor looks for.

Readiness mapping, not a HITRUST certification. LockList evidences the technical/configuration controls these platforms expose, strong alignment with HITRUST's foundational e1 / i1 control sets. HITRUST CSF also includes policy, process, and physical controls a config scan can't see, and the required control set is scoped per organisation in MyCSF. A HITRUST certification is issued by the HITRUST Alliance through a validated assessment by an authorized external assessor.

01 · Access Control

ControlWhat LockList assesses
01.aAccess control policyConditional Access policy visibility and Security Defaults posture, the baseline access control configuration across the tenant.
01.bUser registrationGuest / external user privilege review (M365), how external identities are provisioned and what they can reach.
01.cPrivilege managementPrivileged role assignments, directory roles, and PIM just in time elevation (M365); super admin count and admin role assignments (Google); organisation owners (GitHub); root account access keys (AWS).
01.dUser password managementSelf service password reset (M365); IAM password policy and access key rotation (AWS); deploy key inventory (GitHub).
01.eReview of user access rightsPrivileged role inventory (M365); super admin and admin role review (Google); owner and outside collaborator review (GitHub).
01.jUser authentication for external connectionsLegacy / basic authentication blocking and named location conditions (M365); SAML SSO enforcement (GitHub).
01.qUser identification & authenticationMFA for admins and all users, MFA registration coverage and methods, Security Defaults (M365); 2-Step Verification coverage and admin enrollment (Google); org wide 2FA (GitHub); root and IAM user MFA (AWS).
01.rPassword management systemIAM password policy strength, length and complexity requirements (AWS); SSPR enablement (M365).
01.vInformation access restrictionPIM, high privilege application consents and guest privileges (M365); SharePoint / OneDrive external sharing (M365); account level S3 Block Public Access (AWS).
01.xMobile computing & communicationsIntune device management coverage and non compliant device count (M365); RMM device inventory and agent coverage (NinjaOne).
02.iRemoval of access rightsSuspended and dormant account review (Google), evidencing timely deprovisioning of departing users.

09 · Communications & Operations Management

ControlWhat LockList assesses
09.aaAudit loggingSign in and directory audit log accessibility (M365); login and admin audit logs (Google); CloudTrail trail configuration (AWS); activity log accessibility (NinjaOne).
09.abMonitoring system useApplied Conditional Access visibility, risky user detection via Identity Protection, and Microsoft Secure Score monitoring (M365); open alert review and stale / offline agent detection (NinjaOne).
09.adAdministrator & operator logsDirectory audit logs (M365); admin audit logs (Google); multi region CloudTrail management event logging (AWS).
09.jControls against malicious codeMicrosoft Defender / email security licensing posture (M365); antivirus coverage and health across managed endpoints (NinjaOne).
09.mNetwork controlsLegacy authentication blocking and named location (trusted IP) conditions (M365).
09.sInformation exchange policiesSharePoint / OneDrive external sharing and external email auto forwarding (M365); account level S3 public access posture (AWS).

10 · Systems Acquisition, Development & Maintenance

ControlWhat LockList assesses
10.kChange control proceduresDefault branch protection rules requiring review before merge (GitHub).
10.mControl of technical vulnerabilitiesSecret scanning and push protection (GitHub); non compliant device detection (M365); OS patch status across managed endpoints (NinjaOne).

06 / 07 · Compliance & Asset Management

ControlWhat LockList assesses
06.gCompliance with security policiesMicrosoft Secure Score as an ongoing measurement of configuration against the security baseline.
07.aInventory of assetsTenant licensing / subscription inventory (M365); organisation and verified domain inventory (Google); RMM device and organisation inventory (NinjaOne).

Every finding in your LockList Report carries its HITRUST CSF control reference alongside SOC 2, ISO 27001, CIS, and HIPAA mappings. Run a free assessment →