Skip to main content

💼 SI-2 FLAW REMEDIATION

  • ID: /frameworks/nist-sp-800-53-r4/si/02

Description

The organization: SI-2a. Identifies, reports, and corrects information system flaws; SI-2b. Tests software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; SI-2c. Installs security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and SI-2d. Incorporates flaw remediation into the organizational configuration management process.

Similar

  • Internal
    • ID: dec-c-a8b77d4f

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 NIST CSF v1.1 → 💼 ID.RA-1: Asset vulnerabilities are identified and documented1316no data
💼 NIST CSF v1.1 → 💼 PR.IP-12: A vulnerability management plan is developed and implemented79no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 SI-2 (1) CENTRAL MANAGEMENTno data
💼 SI-2 (2) AUTOMATED FLAW REMEDIATION STATUSno data
💼 SI-2 (3) TIME TO REMEDIATE FLAWS _ BENCHMARKS FOR CORRECTIVE ACTIONSno data
💼 SI-2 (4) AUTOMATED PATCH MANAGEMENT TOOLSno data
💼 SI-2 (5) AUTOMATIC SOFTWARE _ FIRMWARE UPDATESno data
💼 SI-2 (6) REMOVAL OF PREVIOUS VERSIONS OF SOFTWARE _ FIRMWAREno data

Policies (2)

PolicyLogic CountFlagsCompliance
🛡️ AWS DMS Replication Instance Auto Minor Version Upgrade is not enabled🟢1🟢 x6no data
🛡️ AWS RDS Instance Auto Minor Version Upgrade is not enabled🟠🟢1🟠 x1, 🟢 x6no data

Internal Rules

RulePoliciesFlags
✉️ dec-x-0d66ed991
✉️ dec-x-215302da1