Flaw Remediation
✓ LOW ✓ MODERATE ✓ HIGHRequirements NIST SOURCE
Requirement Context
This element is part of SI-2 — Flaw Remediation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SI-2 — Flaw Remediation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SI-2 — Flaw Remediation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Requirement Context
This element is part of SI-2 — Flaw Remediation. See the Assessment section below for the related SP 800-53A examine/interview/test procedures. No engineering interpretation has been authored for this control yet.
Discussion (NIST Supplemental Guidance)
The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing addresses both effectiveness of addressing security issues and for potential side effects on functionality, system and system component performance and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). In some situations, organizations may determine that the testing of software or firmware updates is not necessary or practical, such as when implementing simple malicious code signature updates. In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment, and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.
Enhancements NIST SOURCE
SI-2(1) Central Management WITHDRAWN
Withdrawn. Incorporated into PL-9.
SI-2(2) Automated Flaw Remediation Status LOW ✓ MODERATE ✓ HIGH
Determine if system components have applicable security-relevant software and firmware updates installed using [automated mechanisms][frequency].
Discussion
Automated mechanisms can track and determine the status of known flaws for system components.
SI-2(3) Time to Remediate Flaws and Benchmarks for Corrective Actions LOW MODERATE HIGH
- (a) Measure the time between flaw identification and flaw remediation; and
- (b) Establish the following benchmarks for taking corrective actions: [benchmarks].
Discussion
Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.
SI-2(4) Automated Patch Management Tools LOW MODERATE HIGH
Employ automated patch management tools to facilitate flaw remediation to the following system components: [components].
Discussion
Using automated tools to support patch management helps to ensure the timeliness and completeness of system patching operations.
SI-2(5) Automatic Software and Firmware Updates LOW MODERATE HIGH
Install [security-relevant software and firmware updates] automatically to [system components].
Discussion
Due to system integrity and availability concerns, organizations consider the methodology used to carry out automatic updates. Organizations balance the need to ensure that the updates are installed as soon as possible with the need to maintain configuration management and control with any mission or operational impacts that automatic updates might impose (i.e., implementing a staggered deployment strategy).
SI-2(6) Removal of Previous Versions of Software and Firmware LOW MODERATE HIGH
Remove previous versions of [software and firmware components] after updated versions have been installed.
Discussion
Previous versions of software or firmware components that are not removed from the system after updates have been installed may be exploited by adversaries. Some products may automatically remove previous versions of software and firmware from the system.
SI-2(7) Root Cause Analysis LOW MODERATE HIGH
- a. Conduct root cause analysis to identify underlying causes of issues or failures.
- b. Develop actions to address the root cause of the issue or failure.
- c. Implement the actions and monitor the implementation for effectiveness.
Discussion
Root cause analysis includes a wide range of approaches, tools, and techniques to systematically identify the underlying cause of issues or failures to systems and systems components (hardware, software, and firmware). Organizations consider the severity of the incident to determine what root cause analysis method is used and how quickly implementation of the remediation actions. The root cause analysis includes a timeline, missed warning signs, key decisions, gaps, mitigations, and verification of effectiveness. The actions identified to address the source of the issue are implemented and integrated into applicable organizational policy, procedures, and control implementation.
Implementation Guidance
Original engineering commentary written for this explorer — not NIST source text and not authoritative guidance.
No engineering interpretation has been authored for SI-2 yet. This section is architected to receive it — see the Requirements and Assessment sections above for the authoritative NIST source content in the meantime.
Assessment
Assessment Objectives
- time period within which to install security-relevant software updates after the release of the updates is defined;
- system flaws are identified;
- system flaws are reported;
- system flaws are corrected;
- software updates related to flaw remediation are tested for effectiveness before installation;
- software updates related to flaw remediation are tested for potential side effects before installation;
- firmware updates related to flaw remediation are tested for effectiveness before installation;
- firmware updates related to flaw remediation are tested for potential side effects before installation;
- security-relevant software updates are installed within <SI-02_ODP time period> of the release of the updates;
- security-relevant firmware updates are installed within <SI-02_ODP time period> of the release of the updates;
- flaw remediation is incorporated into the organizational configuration management process.
Examine
[SELECT FROM: System and information integrity policy; system and information integrity procedures; procedures addressing flaw remediation; procedures addressing configuration management; list of flaws and vulnerabilities potentially affecting the system; list of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws); test results from the installation of software and firmware updates to correct system flaws; installation/change control records for security-relevant software and firmware updates; system security plan; privacy plan; other relevant documents or records].
Interview
[SELECT FROM: System/network administrators; organizational personnel with information security and privacy responsibilities; organizational personnel responsible for installing, configuring, and/or maintaining the system; organizational personnel responsible for flaw remediation; organizational personnel with configuration management responsibilities].
Test
[SELECT FROM: Organizational processes for identifying, reporting, and correcting system flaws; organizational process for installing software and firmware updates; mechanisms supporting and/or implementing the reporting and correcting of system flaws; mechanisms supporting and/or implementing testing software and firmware updates].
Overlays
STIGs & CCIs
No STIG checks or CCI mappings are currently loaded for SI-2. This section is architected to display, per product: STIG ID, Finding ID, Severity, Title, Description, Check, Fix, CCI, and NIST control mapping — but nothing is populated here until a real DISA STIG/CCI dataset is ingested.
Learn more about STIG/CCI integration →Evidence
Categorized from the SP 800-53A "Examine"/"Test" artifact list above by keyword — not an authoritative NIST evidence list.
Policy
- System and information integrity policy
- system security plan
- privacy plan
Configuration
- procedures addressing configuration management
Testing
- Organizational processes for identifying, reporting, and correcting system flaws
- organizational process for installing software and firmware updates
- mechanisms supporting and/or implementing the reporting and correcting of system flaws
- mechanisms supporting and/or implementing testing software and firmware updates
Other Records
- system and information integrity procedures
- procedures addressing flaw remediation
- list of flaws and vulnerabilities potentially affecting the system
- list of recent security flaw remediation actions performed on the system (e.g., list of installed patches, service packs, hot fixes, and other software updates to correct system flaws)
- test results from the installation of software and firmware updates to correct system flaws
- installation/change control records for security-relevant software and firmware updates
- other relevant documents or records