03.11: Risk Assessment

Controls

03.11.01: Risk Assessment

Assess the risk (including supply chain risk) of unauthorized disclosure resulting from the processing, storage, or transmission of CUI. Update risk assessments [Assignment: organization-defined frequency].

03.11.02: Vulnerability Monitoring and Scanning

Monitor and scan the system for vulnerabilities [Assignment: organization-defined frequency] and when new vulnerabilities affecting the system are identified. Remediate system vulnerabilities within [Assignment: organization-defined response times]. Update system vulnerabilities to be scanned [Assignment: organization-defined frequency] and when new vulnerabilities are identified and reported.