This document is about Daniel Nutkis of HITRUST providing testimony on how HITRUST's Risk Management Framework, including the HITRUST Common Security Framework (CSF) and Assurance Program, can serve as a model implementation of the NIST Cybersecurity Framework for employee benefit plans. Nutkis explains how the HITRUST CSF can be applied to non-healthcare benefit plans to provide a comprehensive, scalable, and industry-vetted approach to cybersecurity risk management.