RSK-05: Does the organization identify and assign a risk ranking to newly discovered security vulnerabilities that is based on industry-recognized practices?

Mechanisms exist to identify and assign a risk ranking to newly discovered security vulnerabilities that is based on industry-recognized practices.

Description

Mechanisms exist to identify and assign a risk ranking to newly discovered security vulnerabilities that is based on industry-recognized practices.