TLS configurations are consistently reviewed and weak protocols or ciphers are disabled
The process facet scans public endpoints for weak TLS protocols and expiring certificates on a recurring schedule and fixes what the scan flags.
Scanning public endpoints for weak TLS protocols and expiring certificates on schedule is a configuration-drift check A.8.9 expects for network-facing services.