CSF v11.8.0 is here, and the clock has started on v11.7 assessment creation. Lexie Jurgielewicz shares what these two new advisories from HITRUST mean for organizations navigating e1 and i1 assessments, including why the new OWASP LLM mappings are a signal worth taking seriously. Questions about your HITRUST readiness? Connect with LBMC's HITRUST team today: https://lnkd.in/eGBmb8kR #hitrust #cybersecurity #riskmanagement #AI
HITRUST released two advisories this week that are definitely worth paying attention to for organizations currently working through or planning e1 and i1 assessments. 🔹 HAA 2026-002 | HITRUST CSF v11.8.0 Release The latest CSF release includes several notable updates, including: ✔️ Continued requirement consolidation to reduce overlap ✔️ New mappings for NIST SP 800-137 ✔️ New ISO/IEC 29100:2024 privacy framework mappings ✔️ Added OWASP Top 10 for LLM Applications 2025 mappings ✔️ Updates to PCI DSS v4.0.1 and SOC 2 mappings The addition of OWASP LLM guidance really stood out to me. It’s another clear indicator that AI and LLM-related risks are no longer being treated as “future concerns.” They’re becoming part of the core cybersecurity and assurance conversation. 🔹 HAA 2026-003 | CSF v11.7 Creation Deadline for e1 and i1 Assessments As of May 7, 2026, organizations can no longer create new e1 or i1 assessments in CSF v11.7.0. All new assessments must now be created in v11.8.0, although existing v11.7 assessments can still be submitted. For teams actively preparing for HITRUST assessments, these updates are a good reminder of how quickly the framework continues to evolve alongside emerging threats, AI security considerations, and changing compliance expectations. Definitely worth reviewing now to understand any potential impacts to assessment planning, readiness efforts, and inherited control mappings. LBMC Cybersecurity HITRUST #Cybersecurity #Compliance #AISecurity #LLM #RiskManagement #InformationSecurity https://lnkd.in/eX2w5UfY