id: "SI-02(03)" title: "Time to Remediate Flaws and Benchmarks for Corrective Actions" family: "SI" family_name: "System and Information Integrity" sort_id: "si-02.03" priority: "P1" implementation_level: "organization" parent: "SI-02" enhancement: True
Measure the time between flaw identification and flaw remediation; and
Establish the following benchmarks for taking corrective actions: {{ insert: param, si-02.03_odp }}.
Guidance
Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.
Assessment Objective: the time between flaw identification and flaw remediation is measured;
Assessment Objective: {{ insert: param, si-02.03_odp }} for taking corrective actions have been established.
System and information integrity policy
system and information integrity procedures
procedures addressing flaw remediation
system design documentation
system configuration settings and associated documentation
list of benchmarks for taking corrective action on identified flaws
records that provide timestamps of flaw identification and subsequent flaw remediation activities
system security plan
other relevant documents or records
System/network administrators
organizational personnel with information security responsibilities
organizational personnel installing, configuring, and/or maintaining the system
organizational personnel responsible for flaw remediation
Organizational processes for identifying, reporting, and correcting system flaws
mechanisms used to measure the time between flaw identification and flaw remediation