Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search courses, individual lessons, wiki entries, books, podcasts, magazine articles, Daily Cyber News, and Darwin.

NIST SP 800-53 Learning Center

SI-2 — Flaw Remediation

Read the official control and assessment content, then use the separately labeled Bare Metal Cyber perspective to connect the requirement to implementation, evidence, and sustained operation.

7Enhancements
1Parameters
3Baseline memberships
3Assessment methods

SI — System and Information Integrity · NIST SP 800-53 Release 5.2.0

LowModerateHigh
Official NIST control content

Control statement

  1. a.Identify, report, and correct system flaws;
  2. b.Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation;
  3. c.Install security-relevant software and firmware updates within [Organization-defined: time period] of the release of the updates; and
  4. d.Incorporate flaw remediation into the organizational configuration management process.
Official NIST discussion

Discussion

The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing addresses both effectiveness of addressing security issues and for potential side effects on functionality, system and system component performance and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). In some situations, organizations may determine that the testing of software or firmware updates is not necessary or practical, such as when implementing simple malicious code signature updates. In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.

Official OSCAL parameters

Organization-defined parameters

These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.

time periodtime period within which to install security-relevant software updates after the release of the updates is defined;
Original Bare Metal Cyber perspective

From control text to operational evidence

Use Flaw Remediation as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.

Implementation workflow

  • Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
  • Resolve each organization-defined parameter before declaring the control implemented.
  • Document how the implementation satisfies every clause of the official control statement.
  • Collect evidence as a normal byproduct of operation rather than only before an assessment.
  • Review exceptions, changes, and monitoring results on a risk-based cadence.

Evidence examples

  • patch and remediation records
  • malware protection configuration
  • monitoring alerts and response records
  • integrity validation and exception reports

Common failure patterns

  • patch compliance hides unsupported assets
  • alerts generated without response ownership
  • exceptions never expire
  • integrity monitoring excludes critical configurations

Questions practitioners should ask

  • What risk decision is this control intended to support in this system?
  • Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
  • Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
  • What event or threshold requires the implementation to be reviewed or changed?
Official NIST SP 800-53A content

Assessment objectives and methods

Show the assessment objective
  1. SI-02a.
    1. SI-02a.[01]system flaws are identified;
    2. SI-02a.[02]system flaws are reported;
    3. SI-02a.[03]system flaws are corrected;
  2. SI-02b.
    1. SI-02b.[01]software updates related to flaw remediation are tested for effectiveness before installation;
    2. SI-02b.[02]software updates related to flaw remediation are tested for potential side effects before installation;
    3. SI-02b.[03]firmware updates related to flaw remediation are tested for effectiveness before installation;
    4. SI-02b.[04]firmware updates related to flaw remediation are tested for potential side effects before installation;
  3. SI-02c.
    1. SI-02c.[01]security-relevant software updates are installed within [Organization-defined: time period] of the release of the updates;
    2. SI-02c.[02]security-relevant firmware updates are installed within [Organization-defined: time period] of the release of the updates;
  4. SI-02d.flaw remediation is incorporated into the organizational configuration management process.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • procedures addressing configuration management
  • list of flaws and vulnerabilities potentially affecting the system
  • list of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws)
  • test results from the installation of software and firmware updates to correct system flaws
  • installation/change control records for security-relevant software and firmware updates
  • system security plan
  • privacy plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security and privacy responsibilities
  • organizational personnel responsible for installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation
  • organizational personnel with configuration management responsibilities

Test

  • Organizational processes for identifying, reporting, and correcting system flaws
  • organizational process for installing software and firmware updates
  • mechanisms supporting and/or implementing the reporting and correcting of system flaws
  • mechanisms supporting and/or implementing testing software and firmware updates
Official relationships

Related controls

These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.

MITRE D3FEND semantic mapping

Related defensive techniques

D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.

MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.

Official NIST enhancements

Control enhancements

Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.

Official NIST control enhancement

SI-2(1) — Central Management

Withdrawn

This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.

Official NIST control enhancement

SI-2(2) — Automated Flaw Remediation Status

ModerateHigh

Determine if system components have applicable security-relevant software and firmware updates installed using [Organization-defined: automated mechanisms] [Organization-defined: frequency].

Official discussion

Automated mechanisms can track and determine the status of known flaws for system components.

Organization-defined parameters (2)
automated mechanismsautomated mechanisms to determine if applicable security-relevant software and firmware updates are installed on system components are defined;
frequencythe frequency at which to determine if applicable security-relevant software and firmware updates are installed on system components is defined;
Assessment objectives and methods

system components have applicable security-relevant software and firmware updates installed [Organization-defined: frequency] using [Organization-defined: automated mechanisms].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • automated mechanisms supporting centralized management of flaw remediation
  • system design documentation
  • system configuration settings and associated documentation
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation

Test

  • Automated mechanisms used to determine the state of system components with regard to flaw remediation
Related controls
Official NIST control enhancement

SI-2(3) — Time to Remediate Flaws and Benchmarks for Corrective Actions

  1. (a)Measure the time between flaw identification and flaw remediation; and
  2. (b)Establish the following benchmarks for taking corrective actions: [Organization-defined: benchmarks].
Official discussion

Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.

Organization-defined parameters (1)
benchmarksthe benchmarks for taking corrective actions are defined;
Assessment objectives and methods
  1. SI-02(03)(a)the time between flaw identification and flaw remediation is measured;
  2. SI-02(03)(b)[Organization-defined: benchmarks] for taking corrective actions have been established.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • system design documentation
  • system configuration settings and associated documentation
  • list of benchmarks for taking corrective action on identified flaws
  • records that provide timestamps of flaw identification and subsequent flaw remediation activities
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation

Test

  • Organizational processes for identifying, reporting, and correcting system flaws
  • mechanisms used to measure the time between flaw identification and flaw remediation
Official NIST control enhancement

SI-2(4) — Automated Patch Management Tools

Employ automated patch management tools to facilitate flaw remediation to the following system components: [Organization-defined: components].

Official discussion

Using automated tools to support patch management helps to ensure the timeliness and completeness of system patching operations.

Organization-defined parameters (1)
componentsthe system components requiring automated patch management tools to facilitate flaw remediation are defined;
Assessment objectives and methods

automated patch management tools are employed to facilitate flaw remediation to [Organization-defined: components].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • mechanisms supporting flaw remediation and automatic software/firmware updates
  • system design documentation
  • system configuration settings and associated documentation
  • list of system flaws
  • records of recent security-relevant software and firmware updates that are automatically installed to system components
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation

Test

  • Automated patch management tools
  • mechanisms implementing automatic software/firmware updates
  • mechanisms facilitating flaw remediation to system components
Official NIST control enhancement

SI-2(5) — Automatic Software and Firmware Updates

Install [Organization-defined: security-relevant software and firmware updates] automatically to [Organization-defined: system components].

Official discussion

Due to system integrity and availability concerns, organizations consider the methodology used to carry out automatic updates. Organizations balance the need to ensure that the updates are installed as soon as possible with the need to maintain configuration management and control with any mission or operational impacts that automatic updates might impose (i.e., implementing a staggered deployment strategy).

Organization-defined parameters (2)
security-relevant software and firmware updatessecurity-relevant software and firmware updates to be automatically installed to system components are defined;
system componentssystem components requiring security-relevant software updates to be automatically installed are defined;
Assessment objectives and methods

[Organization-defined: security-relevant software and firmware updates] are installed automatically to [Organization-defined: system components].

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • mechanisms supporting flaw remediation and automatic software/firmware updates
  • system design documentation
  • system configuration settings and associated documentation
  • records of recent security-relevant software and firmware updates automatically installed to system components
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation

Test

  • Mechanisms implementing automatic software/firmware updates
Official NIST control enhancement

SI-2(6) — Removal of Previous Versions of Software and Firmware

Remove previous versions of [Organization-defined: software and firmware components] after updated versions have been installed.

Official discussion

Previous versions of software or firmware components that are not removed from the system after updates have been installed may be exploited by adversaries. Some products may automatically remove previous versions of software and firmware from the system.

Organization-defined parameters (1)
software and firmware componentssoftware and firmware components to be removed after updated versions have been installed are defined;
Assessment objectives and methods

previous versions of [Organization-defined: software and firmware components] are removed after updated versions have been installed.

Examine

  • System and information integrity policy
  • system and information integrity procedures
  • procedures addressing flaw remediation
  • mechanisms supporting flaw remediation
  • system design documentation
  • system configuration settings and associated documentation
  • records of software and firmware component removals after updated versions are installed
  • system audit records
  • system security plan
  • other relevant documents or records

Interview

  • System/network administrators
  • organizational personnel with information security responsibilities
  • organizational personnel installing, configuring, and/or maintaining the system
  • organizational personnel responsible for flaw remediation

Test

  • Mechanisms supporting and/or implementing the removal of previous versions of software/firmware
Official NIST control enhancement

SI-2(7) — Root Cause Analysis

  1. a.Conduct root cause analysis to identify underlying causes of issues or failures.
  2. b.Develop actions to address the root cause of the issue or failure.
  3. c.Implement the actions and monitor the implementation for effectiveness.
Official discussion

Root cause analysis includes a wide range of approaches, tools, and techniques to systematically identify the underlying cause of issues or failures to systems and systems components (hardware, software, and firmware). Organizations consider the severity of the incident to determine what root cause analysis method is used and how quickly implementation of the remediation actions. The root cause analysis includes a timeline, missed warning signs, key decisions, gaps, mitigations, and verification of effectiveness. The actions identified to address the source of the issue are implemented and integrated into applicable organizational policy, procedures, and control implementation.

Assessment objectives and methods

Determine if:

  1. SI-02(07)a.Root cause analysis is conducted to identify underlying causes of issues or failures
  2. SI-02(07)b.Actions to address the root cause of the issue of failure are developed
  3. SI-02(07)c.
    1. The actions (defined in [SI-02(07)b.](#si-2.7_smt.b)) are implemented
    2. The implementation of actions is monitored for effectiveness.

Examine

  • System and information integrity policy;
  • system and information integrity procedures;
  • procedures addressing flaw remediation;
  • procedures addressing root cause analysis/process improvement;
  • system design documentation;
  • system configuration settings and associated documentation;
  • system audit records;
  • system security and privacy plan;
  • other relevant documents or records

Interview

  • System/network administrators;
  • organizational personnel with information security and privacy responsibilities;
  • organizational personnel responsible for installing, configuring, and/or maintaining the system;
  • organizational personnel responsible for flaw remediation;
  • organizational personnel with configuration management responsibilities

Test

  • Organizational processes for identifying, reporting, and correcting system flaws;
  • organizational process for installing software and firmware updates;
  • mechanisms supporting and/or implementing the reporting and correcting of system flaws;
  • mechanisms supporting and/or implementing testing software and firmware updates
Related controls
Source record

Authoritative sources