This control requires organizations to proactively identify and fix flaws (e.g., vulnerabilities, bugs, or misconfigurations) in their systems—before those flaws can be exploited. It also mandates timely reporting and tracking of these issues.
Read the full blog breakdown of 3.14.1