Identified cybersecurity risks remain untreated for long periods of time
Context and Guidance: Identified cybersecurity risks should be resolved in a manner commensurate with the potential for adverse impact. This may mean that some cybersecurity risks need to be resolved before other cybersecurity risks, based on their likelihood and consequence.
You should consider the period of time that a cybersecurity risk has remained unresolved and ensure that no cybersecurity risk remains unresolved indefinitely.