Vulnerability Assessment is another critical control to keep an organization's IT infrastructure free from known vulnerabilities.
All IT systems and applications need to assess for any known vulnerabilities, the impact of any observed vulnerabilities, and the risk of not mitigating those vulnerabilities. This is an ongoing security control performed before commissioning till decommissioning of any IT asset.