Periodically assess risk to organizational operations and assets.
Risk assessment asks you to look for the risks and the vulnerabilities on a schedule, and to fix what the scans find. It is three requirements, one of them worth five points, and it is where scanning cadence and remediation records are examined.