During a CMMC assessment, an assessor discovers an OSC has unpatched critical vulnerabilities on servers that store CUI. What is the appropriate assessor action?
-
A
Recommend a patch management vendor to the OSC
-
B
Document the finding as 'Not Met' for the relevant patching/vulnerability management practices
-
C
Ignore it if the server has perimeter firewall protection
-
D
Defer the finding pending OSC remediation