CMMC 2.0
System and Information Integrity

CMMC 2.0 SI.L2-3.14.1: Flaw Remediation

Identify system flaws, report them, and correct them within a timely period.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 84 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 10 controls

  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.3.2.1 11.3.2.1 External scans after significant change
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 2.2.1 2.2.1 System configuration standards maintained
  • 6.2.1 6.2.1 Secure development of bespoke and custom software
  • 6.2.4 6.2.4 Engineering techniques against common software attacks
  • 6.4.1 6.4.1 Public web application review or automated protection
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches

CIS Controls v8 · 7 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities

SOC 2 · 6 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.3 CC7.3 Evaluating security events to identify incidents
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure

NIST SP 800-53 Rev 5 · 5 controls

ACSC Essential Eight · 4 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)

ISO/IEC 42001:2023 · 4 controls

  • 10.2 Nonconformity and corrective action
  • 6.1.3 AI risk treatment
  • 8.3 AI risk treatment
  • 9.1 Monitoring, measurement, analysis and evaluation
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk

NIST SP 800-218 · 4 controls

FedRAMP High · 3 controls

  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

FedRAMP Moderate · 3 controls

  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

ISO 27001:2022 · 3 controls

  • 5.36 Compliance with policies, rules and standards for information security
  • 8.25 Secure development life cycle
  • 8.8 Management of technical vulnerabilities
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 2 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities

ISO 27002:2022 · 2 controls

  • 8.26 Application security requirements
  • 8.8 Management of technical vulnerabilities

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

UK Cyber Essentials · 2 controls

  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • CPS230-P25 Information and Technology Capability and Asset Health
  • AUCDR-IS-4 Formal vulnerability management program
  • CFTC-SS-21 Remediation of Vulnerabilities and Deficiencies

CMMC 2.0 Level 1 · 1 control

HIPAA Security Rule · 1 control

ISO 27701:2019 · 1 control

  • 6.9.6 Technical vulnerability management

NIST SP 800-172 · 1 control

  • 3.14.7e Verify Correctness of Security Functions

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in System and Information Integrity

You are reading one control. How much of CMMC 2.0 have you already done?

CMMC 2.0 SI.L2-3.14.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CMMC 2.0 your existing evidence covers. Hold FedRAMP Moderate and 108 of 110 CMMC 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 1 were rejected on the FedRAMP Moderate pair alone.

Query this from an agent

The graph holds this control, the 84 it maps to, and the evidence behind each claim, over MCP and REST.