graphgrc

SCF - RSK-05 - Risk Ranking

Mechanisms exist to identify and assign a risk ranking to newly discovered security vulnerabilities that is based on industry-recognized practices.

Mapped framework controls

SOC 2

Control questions

Does the organization identify and assign a risk ranking to newly discovered security vulnerabilities that is based on industry-recognized practices?