What sample size should be pulled for a manual control that operates at a defined frequency of weekly?
Correct Answer: C
HITRUST defines sample sizes for manual controls based on thefrequency of operation. For controls that operateweekly, the required sample size is5 items. This ensures that the assessor can evaluate consistency over multiple weeks without excessive burden. For example, if access logs are reviewed weekly, five weeks of logs must be tested. A higher frequency (e.g., daily controls) requires larger samples, such as 25.
Conversely, less frequent controls (e.g., monthly or quarterly) may only require 2 or 1 sample. The structured sampling methodology provides consistency across assessments, ensures sufficient evidence for scoring, and prevents under-testing of critical controls.
References:HITRUST Scoring Rubric - "Sampling Requirements by Control Frequency"; CCSFP Study Guide - "Sample Sizes for Manual Controls."