NIST SP 800-53 Rev 5
SI - System and Information Integrity

NIST SP 800-53 Rev 5 NIST800-SI-2: SI-2 Flaw Remediation

a. Identify, report, and correct system flaws; b. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and d. Incorporate flaw remediation into the organizational configuration management process.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 162 controls across 73 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 13 controls

  • CIS-12.1 Ensure Network Infrastructure is Up-to-Date
  • CIS-16.1 Establish and Maintain a Secure Application Development Process
  • CIS-16.2 Establish and Maintain a Process to Accept and Address Software Vulnerabilities
  • CIS-16.3 Perform Root Cause Analysis on Security Vulnerabilities
  • CIS-16.5 Use Up-to-Date and Trusted Third-Party Software Components
  • CIS-16.6 Establish and Maintain a Severity Rating System and Process for Application Vulnerabilities
  • CIS-18.3 Remediate Penetration Test Findings
  • CIS-7.1 Establish and Maintain a Vulnerability Management Process
  • CIS-7.2 Establish and Maintain a Remediation Process
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management
  • CIS-7.7 Remediate Detected Vulnerabilities
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

PCI DSS 4.0 · 10 controls

  • 11.3.1.1 11.3.1.1 Lower-risk vulnerabilities handled per risk analysis
  • 11.3.1.3 11.3.1.3 Internal scans after significant change
  • 11.4.4 11.4.4 Correct exploitable findings from penetration tests
  • 12.3.4 12.3.4 Annual review of hardware and software technologies
  • 12.6.1 12.6.1 Formal security awareness program
  • 5.2.3.1 5.2.3.1 Targeted risk analysis sets evaluation frequency
  • 6.2.3 6.2.3 Code review before release
  • 6.2.3.1 6.2.3.1 Manual code review independence and approval
  • 6.3.1 6.3.1 Vulnerability identification and risk ranking
  • 6.3.3 6.3.3 Timely installation of security patches

ACSC Essential Eight · 6 controls

  • E8-PATCHAPP-ML1 Patch Applications (ML1)
  • E8-PATCHAPP-ML2 Patch Applications (ML2)
  • E8-PATCHAPP-ML3 Patch Applications (ML3)
  • E8-PATCHOS-ML1 Patch Operating Systems (ML1)
  • E8-PATCHOS-ML2 Patch Operating Systems (ML2)
  • E8-PATCHOS-ML3 Patch Operating Systems (ML3)

NIST SP 800-218 · 6 controls

  • NIST-CSF-ID.IM-02 Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
  • NIST-CSF-ID.IM-03 Improvements are identified from execution of operational processes, procedures, and activities
  • NIST-CSF-ID.RA-01 Vulnerabilities in assets are identified, validated, and recorded
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

SOC 2 · 5 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC7.5 CC7.5 Recovering from security incidents
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • SEC04-BP04 Initiate remediation for non-compliant resources
  • SEC06-BP01 Perform vulnerability management
  • SEC06-BP05 Automate compute protection
  • SEC11-BP02 Automate testing throughout the development and release lifecycle

FedRAMP High · 4 controls

  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

FedRAMP Moderate · 4 controls

  • SA-22 Unsupported System Components (SA-22)
  • SI-2 Flaw Remediation
  • SI-2(2) Automated Flaw Remediation Status
  • SI-2(3) Flaw Remediation | Time to Remediate Flaws and Benchmarks for Corrective Actions (SI-2(3))

ISO 27701:2019 · 4 controls

  • 5.8 Improvement
  • 5.8.1 Nonconformity and corrective action
  • 5.8.2 Continual improvement
  • 6.9.6 Technical vulnerability management

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • SBD-DEV-07 Dependency Management and SBOM
  • ANSSI-HYG-34 Define an Update Policy for Information System Components
  • ANSSI-HYG-35 Anticipate the End of Maintenance of Software and Systems
  • ASD37-02 Patch applications (Essential)
  • ASD37-19 Patch operating systems (Essential)
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • PV-5 Perform vulnerability assessments

C5 (Germany) · 2 controls

  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-22 Testing and Documentation of known Vulnerabilities

CMMC 2.0 · 2 controls

EU AI Act · 2 controls

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

NIS2 Directive · 2 controls

  • Art.21.2.e Security in acquisition, development and maintenance, including vulnerability handling and disclosure
  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-171 · 2 controls

UK Cyber Essentials · 2 controls

  • CE-SU.2 Automatic Updates Enabled Where Possible
  • CE-SU.3 Critical and High Updates within 14 Days
  • AUCDR-IS-4 Formal vulnerability management program
  • AESCSF-TVM-3 Patch and remediation management

BSI IT-Grundschutz · 1 control

  • BSI-14 Vulnerability scanning and management
  • CPG-5.A Vulnerability Disclosure Program

CMMC 2.0 Level 1 · 1 control

ETSI EN 303 645 · 1 control

  • EN303645-5.3 Keep software updated
  • CAT-D3-3 Corrective controls
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO 22301:2019 · 1 control

  • 10.2 Continual improvement

ISO 27001:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO 27002:2022 · 1 control

  • 8.8 Management of technical vulnerabilities

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27043:2015 · 1 control

  • ISO27043-25 Technical vulnerability management

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations

ISO/IEC 42001:2023 · 1 control

  • 10.2 Nonconformity and corrective action

ISO/SAE 21434 · 1 control

  • ISO21434-25 Technical vulnerability management
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-160 · 1 control

NIST SP 800-190 · 1 control

  • SI-2 SI-2 Flaw Remediation
  • SI-2 SI-2 Flaw Remediation
  • SI-2 SI-2 Flaw Remediation

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NZISM-5 Network Security, System Hardening, and Application Security
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture

OWASP SAMM · 1 control

  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SOCI-S30CU Vulnerability assessments
  • SCA-S26 Licensing Framework
  • IM8-SEC.4 Vulnerability Management

South Korea ISMS-P · 1 control

  • ISMSP-SYS-04 Vulnerability Management
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • UKOPRES-4 Incident Management, Lessons Learned, Comms
  • 2(e) Sec. 2(e) (now 2(c)) Manage agency use of open source software

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in SI - System and Information Integrity

You are reading one control. How much of NIST SP 800-53 Rev 5 have you already done?

NIST SP 800-53 Rev 5 NIST800-SI-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST SP 800-53 Rev 5 your existing evidence covers. Hold ISO 27001:2022 and 163 of 1014 NIST SP 800-53 Rev 5 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 342 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 162 it maps to, and the evidence behind each claim, over MCP and REST.