to move, Enter to open, Esc to close. Try 3.5.3, AC.L2-3.1.1, MFA or unmarked.

Risk Assessment

Periodically assess risk to organizational operations and assets.

Risk assessment asks you to look for the risks and the vulnerabilities on a schedule, and to fix what the scans find. It is three requirements, one of them worth five points, and it is where scanning cadence and remediation records are examined.

  1. 3.11.1 Assess your risk periodically RA Level 2 3 pt
  2. 3.11.2 Scan for vulnerabilities RA Level 2 5 pt
  3. 3.11.3 Fix what you find RA Level 2 1 pt