Family 3.11 3 requirements
Risk Assessment.
Know your risks. Watch for new ones.
The big picture
Assessors want a real risk register and real vulnerability scans on a real cadence — not a one-off snapshot.
Theme 1
All practices.
3.11.1 — 3.11.3Periodic risk assessments, vulnerability scanning, and remediating what you find.
- 3.11.1 Assess Your Risks. Formal risk assessments at defined intervals — threats, vulnerabilities, likelihood, impact. 3.11.2 Scan for Vulnerabilities. Regular vulnerability scans plus ad-hoc scans when new critical vulnerabilities are disclosed. 3.11.3 Fix What You Find. Remediate vulnerabilities prioritized by risk — critical first, tracked to closure.