Skip to main content

πŸ’Ό SI-2 FLAW REMEDIATION

Description​

The organization: SI-2a. Identifies, reports, and corrects information system flaws; SI-2b. Tests software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; SI-2c. Installs security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and SI-2d. Incorporates flaw remediation into the organizational configuration management process.

Similar​

  • Internal
    • ID: dec-c-a8b77d4f

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό ID.RA-1: Asset vulnerabilities are identified and documented1415
πŸ’Ό NIST CSF v1.1 β†’ πŸ’Ό PR.IP-12: A vulnerability management plan is developed and implemented78

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό SI-2 (1) CENTRAL MANAGEMENT
πŸ’Ό SI-2 (2) AUTOMATED FLAW REMEDIATION STATUS
πŸ’Ό SI-2 (3) TIME TO REMEDIATE FLAWS _ BENCHMARKS FOR CORRECTIVE ACTIONS
πŸ’Ό SI-2 (4) AUTOMATED PATCH MANAGEMENT TOOLS
πŸ’Ό SI-2 (5) AUTOMATIC SOFTWARE _ FIRMWARE UPDATES
πŸ’Ό SI-2 (6) REMOVAL OF PREVIOUS VERSIONS OF SOFTWARE _ FIRMWARE

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS RDS Instance Auto Minor Version Upgrade is not enabled 🟠🟒1🟠 x1, 🟒 x6

Internal Rules​

RulePoliciesFlags
βœ‰οΈ dec-x-215302da1