HomeControl Library › 3.14.1
3.14 System & Information Integrity5 ptsAlso Level 1

3.14.1 — Patch and remediate flaws

Identify, report, and correct system flaws in a timely manner.

You find, prioritize, and fix vulnerabilities on a timeline.

What it actually means

Unpatched systems are how most breaches happen, so this is weighted heavily. You need a real process: identify vulnerabilities (patch management + scanning), prioritize them, and fix them on a defined timeline — not 'whenever someone gets to it.'

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library