Identify, report, and correct system flaws in a timely manner.
System and information integrity covers patching, malware protection, monitoring for attacks and acting on advisories. Four of its seven requirements are Level 1 practices, and five of the seven carry the full five points, so it moves the score more than its size suggests.