Control statement
- a.Identify, report, and correct system flaws;
- b.Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation;
- c.Install security-relevant software and firmware updates within [Organization-defined: time period] of the release of the updates; and
- d.Incorporate flaw remediation into the organizational configuration management process.
Discussion
The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing addresses both effectiveness of addressing security issues and for potential side effects on functionality, system and system component performance and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). In some situations, organizations may determine that the testing of software or firmware updates is not necessary or practical, such as when implementing simple malicious code signature updates. In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.
Organization-defined parameters
These values must be resolved through the organization’s tailoring and governance process. Bracketed parameter references in the control text identify where a decision is required.
From control text to operational evidence
Use Flaw Remediation as a testable risk decision. Translate the official statement into accountable people, repeatable processes, configured technology, and evidence that demonstrates the outcome over time. In this family, pay particular attention to flaw remediation, malicious-code protection, monitoring, integrity, and trustworthy information handling.
Implementation workflow
- Define the control boundary, responsible owner, inherited portions, and systems or processes in scope.
- Resolve each organization-defined parameter before declaring the control implemented.
- Document how the implementation satisfies every clause of the official control statement.
- Collect evidence as a normal byproduct of operation rather than only before an assessment.
- Review exceptions, changes, and monitoring results on a risk-based cadence.
Evidence examples
- patch and remediation records
- malware protection configuration
- monitoring alerts and response records
- integrity validation and exception reports
Common failure patterns
- patch compliance hides unsupported assets
- alerts generated without response ownership
- exceptions never expire
- integrity monitoring excludes critical configurations
Questions practitioners should ask
- What risk decision is this control intended to support in this system?
- Which parts are implemented locally, inherited, shared, or not applicable—and what evidence supports that decision?
- Do the documented narrative, deployed configuration, operating process, and collected evidence agree?
- What event or threshold requires the implementation to be reviewed or changed?
Assessment objectives and methods
Show the assessment objective
- SI-02a.
- SI-02a.[01]system flaws are identified;
- SI-02a.[02]system flaws are reported;
- SI-02a.[03]system flaws are corrected;
- SI-02b.
- SI-02b.[01]software updates related to flaw remediation are tested for effectiveness before installation;
- SI-02b.[02]software updates related to flaw remediation are tested for potential side effects before installation;
- SI-02b.[03]firmware updates related to flaw remediation are tested for effectiveness before installation;
- SI-02b.[04]firmware updates related to flaw remediation are tested for potential side effects before installation;
- SI-02c.
- SI-02c.[01]security-relevant software updates are installed within [Organization-defined: time period] of the release of the updates;
- SI-02c.[02]security-relevant firmware updates are installed within [Organization-defined: time period] of the release of the updates;
- SI-02d.flaw remediation is incorporated into the organizational configuration management process.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- procedures addressing configuration management
- list of flaws and vulnerabilities potentially affecting the system
- list of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws)
- test results from the installation of software and firmware updates to correct system flaws
- installation/change control records for security-relevant software and firmware updates
- system security plan
- privacy plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security and privacy responsibilities
- organizational personnel responsible for installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
- organizational personnel with configuration management responsibilities
Test
- Organizational processes for identifying, reporting, and correcting system flaws
- organizational process for installing software and firmware updates
- mechanisms supporting and/or implementing the reporting and correcting of system flaws
- mechanisms supporting and/or implementing testing software and firmware updates
Related controls
These relationships come from the official OSCAL catalog. They indicate useful dependencies or context, not automatic inheritance or equivalence.
Related defensive techniques
D3FEND maps this base control or one of its enhancements to the following defensive techniques. The ontology relation label is preserved and does not by itself prove implementation or effectiveness.
MITRE D3FEND™ and the D3FEND logo are trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.
Control enhancements
Enhancements add specificity, strength, or scope to the base control. Baseline badges show explicit selections in the official SP 800-53B OSCAL profiles.
SI-2(1) — Central Management
This enhancement is marked withdrawn in the official OSCAL catalog. Related-control metadata below may identify where its intent was incorporated.
SI-2(2) — Automated Flaw Remediation Status
Determine if system components have applicable security-relevant software and firmware updates installed using [Organization-defined: automated mechanisms] [Organization-defined: frequency].
Official discussion
Automated mechanisms can track and determine the status of known flaws for system components.
Organization-defined parameters (2)
Assessment objectives and methods
system components have applicable security-relevant software and firmware updates installed [Organization-defined: frequency] using [Organization-defined: automated mechanisms].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- automated mechanisms supporting centralized management of flaw remediation
- system design documentation
- system configuration settings and associated documentation
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
Test
- Automated mechanisms used to determine the state of system components with regard to flaw remediation
Related controls
SI-2(3) — Time to Remediate Flaws and Benchmarks for Corrective Actions
- (a)Measure the time between flaw identification and flaw remediation; and
- (b)Establish the following benchmarks for taking corrective actions: [Organization-defined: benchmarks].
Official discussion
Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.
Organization-defined parameters (1)
Assessment objectives and methods
- SI-02(03)(a)the time between flaw identification and flaw remediation is measured;
- SI-02(03)(b)[Organization-defined: benchmarks] for taking corrective actions have been established.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- system design documentation
- system configuration settings and associated documentation
- list of benchmarks for taking corrective action on identified flaws
- records that provide timestamps of flaw identification and subsequent flaw remediation activities
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
Test
- Organizational processes for identifying, reporting, and correcting system flaws
- mechanisms used to measure the time between flaw identification and flaw remediation
SI-2(4) — Automated Patch Management Tools
Employ automated patch management tools to facilitate flaw remediation to the following system components: [Organization-defined: components].
Official discussion
Using automated tools to support patch management helps to ensure the timeliness and completeness of system patching operations.
Organization-defined parameters (1)
Assessment objectives and methods
automated patch management tools are employed to facilitate flaw remediation to [Organization-defined: components].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- mechanisms supporting flaw remediation and automatic software/firmware updates
- system design documentation
- system configuration settings and associated documentation
- list of system flaws
- records of recent security-relevant software and firmware updates that are automatically installed to system components
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
Test
- Automated patch management tools
- mechanisms implementing automatic software/firmware updates
- mechanisms facilitating flaw remediation to system components
SI-2(5) — Automatic Software and Firmware Updates
Install [Organization-defined: security-relevant software and firmware updates] automatically to [Organization-defined: system components].
Official discussion
Due to system integrity and availability concerns, organizations consider the methodology used to carry out automatic updates. Organizations balance the need to ensure that the updates are installed as soon as possible with the need to maintain configuration management and control with any mission or operational impacts that automatic updates might impose (i.e., implementing a staggered deployment strategy).
Organization-defined parameters (2)
Assessment objectives and methods
[Organization-defined: security-relevant software and firmware updates] are installed automatically to [Organization-defined: system components].
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- mechanisms supporting flaw remediation and automatic software/firmware updates
- system design documentation
- system configuration settings and associated documentation
- records of recent security-relevant software and firmware updates automatically installed to system components
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
Test
- Mechanisms implementing automatic software/firmware updates
SI-2(6) — Removal of Previous Versions of Software and Firmware
Remove previous versions of [Organization-defined: software and firmware components] after updated versions have been installed.
Official discussion
Previous versions of software or firmware components that are not removed from the system after updates have been installed may be exploited by adversaries. Some products may automatically remove previous versions of software and firmware from the system.
Organization-defined parameters (1)
Assessment objectives and methods
previous versions of [Organization-defined: software and firmware components] are removed after updated versions have been installed.
Examine
- System and information integrity policy
- system and information integrity procedures
- procedures addressing flaw remediation
- mechanisms supporting flaw remediation
- system design documentation
- system configuration settings and associated documentation
- records of software and firmware component removals after updated versions are installed
- system audit records
- system security plan
- other relevant documents or records
Interview
- System/network administrators
- organizational personnel with information security responsibilities
- organizational personnel installing, configuring, and/or maintaining the system
- organizational personnel responsible for flaw remediation
Test
- Mechanisms supporting and/or implementing the removal of previous versions of software/firmware
SI-2(7) — Root Cause Analysis
- a.Conduct root cause analysis to identify underlying causes of issues or failures.
- b.Develop actions to address the root cause of the issue or failure.
- c.Implement the actions and monitor the implementation for effectiveness.
Official discussion
Root cause analysis includes a wide range of approaches, tools, and techniques to systematically identify the underlying cause of issues or failures to systems and systems components (hardware, software, and firmware). Organizations consider the severity of the incident to determine what root cause analysis method is used and how quickly implementation of the remediation actions. The root cause analysis includes a timeline, missed warning signs, key decisions, gaps, mitigations, and verification of effectiveness. The actions identified to address the source of the issue are implemented and integrated into applicable organizational policy, procedures, and control implementation.
Assessment objectives and methods
Determine if:
- SI-02(07)a.Root cause analysis is conducted to identify underlying causes of issues or failures
- SI-02(07)b.Actions to address the root cause of the issue of failure are developed
- SI-02(07)c.
- The actions (defined in [SI-02(07)b.](#si-2.7_smt.b)) are implemented
- The implementation of actions is monitored for effectiveness.
Examine
- System and information integrity policy;
- system and information integrity procedures;
- procedures addressing flaw remediation;
- procedures addressing root cause analysis/process improvement;
- system design documentation;
- system configuration settings and associated documentation;
- system audit records;
- system security and privacy plan;
- other relevant documents or records
Interview
- System/network administrators;
- organizational personnel with information security and privacy responsibilities;
- organizational personnel responsible for installing, configuring, and/or maintaining the system;
- organizational personnel responsible for flaw remediation;
- organizational personnel with configuration management responsibilities
Test
- Organizational processes for identifying, reporting, and correcting system flaws;
- organizational process for installing software and firmware updates;
- mechanisms supporting and/or implementing the reporting and correcting of system flaws;
- mechanisms supporting and/or implementing testing software and firmware updates
Related controls
Authoritative sources
Bare Metal Cyber is an independent educational publisher and is not affiliated with or endorsed by NIST. Official control requirements and interpretations remain with NIST and the responsible authorizing organization.