3.11.3: Remediate vulnerabilities in accordance with risk assessments

Control Family:

Risk Assessment

Control Type:

Derived

CSF v1.1 References:

Threats Addressed:

Warning icon.

Control is withdrawn in the next version of this control set and incorporated into: 03.11.02: Vulnerability Monitoring and Scanning.

Discussion

Vulnerabilities discovered, for example, via the scanning conducted in response to 3.11.2, are remediated with consideration of the related assessment of risk. The consideration of risk influences the prioritization of remediation efforts and the level of effort to be expended in the remediation for specific vulnerabilities.