# SI-02 Flaw Remediation

NIST SP 800-53 control. Family: SI System and Information Integrity. Function: corrective. Baselines: low, moderate, high. Mapping licence: CC BY-SA 4.0.

Statement: a. Identify, report, and correct system flaws; b. Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; c. Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates; and d. Incorporate flaw remediation into the organizational configuration management process.
Guidance: The need to remediate system flaws applies to all types of software and firmware. Organizations identify systems affected by software flaws, including potential vulnerabilities resulting from those flaws, and report this information to designated organizational personnel with information security and privacy responsibilities. Organizations consider establishing a controlled patching environment for mission-critical systems. Security-relevant updates include patches, service packs, and malicious code signatures. Organizations also address flaws discovered during assessments, continuous monitoring, incident response activities, and system error handling. By incorporating flaw remediation into configuration management processes, required remediation actions can be tracked and verified. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of risk factors, including the security category of the system, the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw), the organizational risk tolerance, the mission supported by the system, or the threat environment. Some types of flaw remediation may require more testing than other types. Organizations determine the type of testing needed for the specific type of flaw remediation activity under consideration and the types of changes that are to be configuration-managed. Flaw remediation testing analyzes both the effectiveness of addressing security issues and any potential side-effects on functionality, system and system component performance, and operations. When implementing remediation activities, organizations consider the order and timing of updates to validate correct execution within the system environment and to support system and component availability needs (i.e., implementing a staggered deployment strategy). Organizations verify that software and firmware updates come from authorized sources prior to downloading.In testing decisions, organizations consider whether security-relevant software or firmware updates are obtained from authorized sources with appropriate digital signatures.

## Enhancements (6)
- SI-02(02) Automated Flaw Remediation Status. Baselines: moderate, high
- SI-02(03) Time to Remediate Flaws and Benchmarks for Corrective Actions
- SI-02(04) Automated Patch Management Tools
- SI-02(05) Automatic Software and Firmware Updates
- SI-02(06) Removal of Previous Versions of Software and Firmware
- SI-02(07) Root Cause Analysis
Withdrawn by NIST: SI-02(01) (now in PL-09).
Each enhancement's statement: /api/v1/controls/SI-02?fields=enhancements

## Patterns that use it (12)
- Critical (2): SP-012 Secure Software Development Lifecycle; SP-038 Vulnerability Management and Patching
- Important (9): SP-001 Client Module; SP-002 Server Module; SP-011 Cloud Computing Pattern; SP-023 Industrial Control Systems; SP-026 PCI Full Environment; SP-028 Secure DevOps Pipeline Pattern; SP-043 Security Metrics and Measurement; SP-046 External Attack Surface Management; SP-054 CBDC and Digital Currency Infrastructure (draft)
- Standard (1): SP-050 Mobile Security Architecture (draft)

## Clauses by framework (77 frameworks)
- iso_27001_2022: A.6.8, A.8.8, A.8.32
- iso_27002_2022: 8.8
- cobit_2019: DSS03
- pci_dss_v4: 6.3, 6.3.3, 11.3
- nist_csf_2: ID.IM-01, ID.IM-02, ID.IM-03, ID.RA-01, ID.RA-08, PR.PS-02. OSA's own, not in NIST's crosswalk: ID.RA-01, ID.RA-08
- cis_controls_v8: CIS 7, CIS 7.1, CIS 7.2, CIS 7.3, CIS 7.4, CIS 7.7, CIS 12.1, CIS 14.7, CIS 16.2, CIS 18.3
- soc2_tsc: CC9.2-POF13
- finos_ccc: CCC-C10
- iso_42001_2023: A.6.2.6
- asd_e8: E8-2, E8-2 ML1, E8-2 ML2, E8-2 ML3, E8-6, E8-6 ML1, E8-6 ML2, E8-6 ML3
- nis2: Art. 21(2)(e), Art. 21(2)(g)
- apra_cps_234: Para 19-20, Para 22-23
- mas_trm: 7
- bsi_grundschutz: OPS.1.1.3, SYS.1.1, SYS.2.1
- anssi: Hygiene.18, Hygiene.33, Hygiene.34, SecNumCloud.13.6
- osfi_b13: B-13.2.4
- finma_circular: IV.A(36), IV.B.c(56), IV.B.d(59), IV.C(64)
- gdpr: Art.32(1)(b), Art.32(1)(d)
- dora: Art.7(2), Art.9(4)(e)
- bio2: 8.8
- rbi_csf: Annex1.7, ITGRCA.13
- fisc: FISC.O12, FISC.T7
- lgpd_bcb: BCB.Art.3, BCB.Art.6, LGPD.Art.46
- hkma_tme1: TME1.5.4, TME1.7.4
- mlps_2: 8.1.4.4, 8.1.10.3, 8.1.10.4
- dnb_good_practice: DNB.19.2
- cra: CRA.I.2a, CRA.I.2c, CRA.II.2, CRA.II.7, CRA.II.8, CRA.Info.8c
- swift_cscf: SWIFT.2.2, SWIFT.2.7
- cbb_tm: TM-5, TM-11
- cbuae: CR-7
- nca_ecc: 2-3, 2-10
- qatar_nia: OS
- sama_csf: 3.5
- uae_ia: T7
- bog_cisd: CISD-VI
- bom_ctrm: 3.6
- cbe_csf: CTO-9
- cbn_csf: Part2.3, Part3.3
- popia: s19
- sa_js2: JS2-7.2, JS2-8.5
- bot_cyber: Ch3.2, Ch10.1
- cpmi_pfmi: CG.LE, CG.PR, PFMI.P17
- eba_ict: 3.4.4, 3.5(b)
- ecb_croe: CROE.2.3.4, CROE.2.8.1, CROE.2.8.2
- ffiec_is: II.A.2, II.C.11
- iosco_cyber: PROT-6, SA-3
- nydfs_500: 500.5, 500.8
- sebi_cscrf: PR.IP
- cmmc_2: SI
- nerc_cip: CIP-007-6
- nrc_73_54: RG5.71-A-SI
- tsa_psd: SD-2 Sec D
- doe_c2m2: THREAT
- api_1164: Sec 7
- iaea_nss: Sec 5.4
- pci_pts: F
- fips_140: FIPS 140-3 §7.12
- cbest: CBEST.6
- tiber_eu: TIBER.REM
- isae_3402: Clause 4
- fca_sysc_13: SYSC 13.7.1, SYSC 13.7.2, SYSC 13.7.4
- fda_cyber: 524B-2, MON-2, PU-1, PU-2, PU-3, SBOM-2, SBOM-3, VR-2
- hitrust_csf: 09.c, 10.e
- iso_27799: 12.5, 18.4, H.3
- lloyds_ms: MS8.4, MS8.11
- naic_ds: 4B
- nhs_dspt: NDG-8.1, NDG-8.2, NDG-9.9
- solvency_ii: DR.266, EIOPA-ICT-4.8
- owasp_masvs_v2: MASVS-CODE-1, MASVS-CODE-2, MASVS-CODE-3
- csa_ccm_v4: AIS-07, IVS-04, TVM-03, TVM-04, UEM-07
- csa_aicm: I&S-04, TVM-03, TVM-04, UEM-07
- ccss_v9: 2.01.1
- mica: Art.62(5)
- basel_sco60: SCO60.51, SCO60.65
- bssc: GSP-08, NOS-03, NOS-10
- sec_custody_digital: SEC-CD-07
- dpdpa: Act.8(5), Rules.Sch1.B.7
OSA's mapping for iso_27001_2022 and nist_csf_2 takes NIST's published crosswalk as its base. A clause not marked as OSA's own is in that crosswalk.

## More
- This control as JSON, with guidance and ATT&CK techniques: /api/v1/controls/SI-02
- Clauses only: /api/v1/controls/SI-02?fields=mappings
- Page for people: /controls/si-02/
- Found an error? Open an issue at https://github.com/opensecurityarchitecture/osa-data/issues with the id, what OSA says and what the source says.
