id: "SI-02(03)" title: "Time to Remediate Flaws and Benchmarks for Corrective Actions" family: "SI" family_name: "System and Information Integrity" sort_id: "si-02.03" priority: "P1" implementation_level: "organization" parent: "SI-02" enhancement: True


Measure the time between flaw identification and flaw remediation; and

Establish the following benchmarks for taking corrective actions: {{ insert: param, si-02.03_odp }}.

Guidance

Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.

Assessment Objective: the time between flaw identification and flaw remediation is measured;

Assessment Objective: {{ insert: param, si-02.03_odp }} for taking corrective actions have been established.

System and information integrity policy

system and information integrity procedures

procedures addressing flaw remediation

system design documentation

system configuration settings and associated documentation

list of benchmarks for taking corrective action on identified flaws

records that provide timestamps of flaw identification and subsequent flaw remediation activities

system security plan

other relevant documents or records

System/network administrators

organizational personnel with information security responsibilities

organizational personnel installing, configuring, and/or maintaining the system

organizational personnel responsible for flaw remediation

Organizational processes for identifying, reporting, and correcting system flaws

mechanisms used to measure the time between flaw identification and flaw remediation