SI-02 Flaw Remediation

System and Information Integrity

Low Moderate High

Description

The organization identifies, reports, and corrects information system flaws.\n

Supplemental Guidance

The organization identifies information systems containing software affected by recently announced software flaws (and potential vulnerabilities resulting from those flaws). The organization (or the software developer/vendor in the case of software developed and maintained by a vendor/contractor) promptly installs newly released security relevant patches, service packs, and hot fixes, and tests patches, service packs, and hot fixes for effectiveness and potential side effects on the organization’s information systems before installation. Flaws discovered during security assessments, continuous monitoring, incident response activities, or information system error handling are also addressed expeditiously. Flaw remediation is incorporated into configuration management as an emergency change. NIST Special Publication 800-40, provides guidance on security patch installation and patch management. Related security controls: CA-2, CA-4, CA-7, CM-3, IR-4, SI-11.\n

Enhancements

\n

Compliance Mappings

ISO 27002:2022

8.78.8

COBIT 2019

DSS05.07MEA01.01

CIS Controls v8

10.212.11818.377.17.37.4

NIST CSF 2.0

ID.RA-01ID.RA-08PR.PS-02

SOC 2 TSC

CC3.2-POF7CC3.2-POF9CC3.4-POF6CC8.1-POF14CC8.1-POF16CC9.2-POF13

ISO 17799 (legacy)

10.10.512.4.112.5.112.5.212.6.1

COBIT 4.1 (legacy)

None.