Frameworks / NIST SP 800-53 Rev 5 / NIST800-SI-2 NIST SP 800-53 Rev 5
SI - System and Information Integrity
NIST SP 800-53 Rev 5 NIST800-SI-2: SI-2 Flaw Remediation a. Identify, report, and correct system flaws; b. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and d. Incorporate flaw remediation into the organizational configuration management process.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 162 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CIS-12.1 Ensure Network Infrastructure is Up-to-Date CIS-16.1 Establish and Maintain a Secure Application Development Process CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities CIS-18.3 Remediate Penetration Test Findings CIS-7.1 Establish and Maintain a Vulnerability Management Process CIS-7.2 Establish and Maintain a Remediation Process CIS-7.3 Perform Automated Operating System Patch Management CIS-7.4 Perform Automated Application Patch Management CIS-7.7 Remediate Detected Vulnerabilities CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis 11.3.1.3 11.3.1.3 Internal scans after significant change 11.4.4 11.4.4 Correct exploitable findings from penetration tests 12.3.4 12.3.4 Annual review of hardware and software technologies 12.6.1 12.6.1 Formal security awareness program 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency 6.2.3 6.2.3 Code review before release 6.2.3.1 6.2.3.1 Manual code review independence and approval 6.3.1 6.3.1 Vulnerability identification and risk ranking 6.3.3 6.3.3 Timely installation of security patches E8-PATCHAPP-ML1 Patch Applications (ML1) E8-PATCHAPP-ML2 Patch Applications (ML2) E8-PATCHAPP-ML3 Patch Applications (ML3) E8-PATCHOS-ML1 Patch Operating Systems (ML1) E8-PATCHOS-ML2 Patch Operating Systems (ML2) E8-PATCHOS-ML3 Patch Operating Systems (ML3) NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11) SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities SOC2-CC7.5 CC7.5 Recovering from security incidents SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure SEC04-BP04 Initiate remediation for non-compliant resources SEC06-BP01 Perform vulnerability management SEC06-BP05 Automate compute protection SEC11-BP02 Automate testing throughout the development and release lifecycle SA-22 Unsupported System Components (SA-22) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) SA-22 Unsupported System Components (SA-22) SI-2 Flaw Remediation SI-2(2) Automated Flaw Remediation Status SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3)) 5.8 Improvement 5.8.1 Nonconformity and corrective action 5.8.2 Continual improvement 6.9.6 Technical vulnerability management 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring CISABD-2 Embrace Radical Transparency and Accountability CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes SBD-DEV-07 Dependency Management and SBOM ANSSI-HYG-34 Define an Update Policy for Information System Components ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems ASD37-02 Patch applications (Essential) ASD37-19 Patch operating systems (Essential) ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities PV-5 Perform vulnerability assessments C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept C5-OPS-22 Testing and Documentation of known Vulnerabilities 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure Art.21.2.g Basic cyber hygiene practices and cybersecurity training CE-SU.2 Automatic Updates Enabled Where Possible CE-SU.3 Critical and High Updates within 14 Days AUCDR-IS-4 Formal vulnerability management program AESCSF-TVM-3 Patch and remediation management BSI-14 Vulnerability scanning and management CPG-5.A Vulnerability Disclosure Program EN303645-5.3 Keep software updated CAT-D3-3 Corrective controls FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) 10.2 Continual improvement 8.8 Management of technical vulnerabilities 8.8 Management of technical vulnerabilities 27011-8.5 Vulnerability and malware management ISO27043-25 Technical vulnerability management 29134-9.2 Report findings and recommendations 10.2 Nonconformity and corrective action ISO21434-25 Technical vulnerability management NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) SI-2 SI-2 Flaw Remediation SI-2 SI-2 Flaw Remediation SI-2 SI-2 Flaw Remediation NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model NZISM-5 Network Security, System Hardening, and Application Security ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PTESPHASE-4 Vulnerability Analysis RMI-DD-4 Due Diligence Reporting SAEIGHT-1 Child Labour and Young Worker Protection SHAREASSESS-4 Vulnerability Management, Patching, Application Security SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SSAE18-CC7.4 CC7.4 - Incident Response SOCI-S30CU Vulnerability assessments SCA-S26 Licensing Framework IM8-SEC.4 Vulnerability Management ISMSP-SYS-04 Vulnerability Management TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator UKOPRES-4 Incident Management, Lessons Learned, Comms 2(e) Sec. 2(e) (now 2(c)) Manage agency use of open source software VES-3 Penetration Testing Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in SI - System and Information Integrity You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done? NIST SP 800-53 Rev 5 NIST800-SI-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.
Query this from an agent The graph holds this control, the 162 it maps to, and the evidence behind each claim, over MCP and REST.