unified
UC-VULN-03 — Remediate identified flaws within defined timeframes
Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Vulnerability & Patch Management
- type
- corrective
- category
- technical
Details
- unified_id
- UC-VULN-03
- title
- Remediate identified flaws within defined timeframes
- statement
- Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.
- domain
- Vulnerability & Patch Management
- control_type
- corrective
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- SI-2
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.8
- coverage
- partial
- delta
- also requires obtaining vulnerability intelligence and evaluating exposure
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-VULN-03 — Remediate identified flaws within defined timeframes mitigates Vulnerabilities introduced during software development
- strength
- related
- rationale
- Flaw remediation corrects identified software vulnerabilities, including dev-introduced ones, once discovered.
- UC-VULN-03 — Remediate identified flaws within defined timeframes mitigates Zero-day exploitation
- strength
- related
- rationale
- Time-bound patch deployment shrinks the exposure window once a patch ships for a formerly-unknown vulnerability.
- UC-VULN-03 — Remediate identified flaws within defined timeframes maps_to SI-2 — Flaw Remediation
- framework
- nist-800-53
- control_id
- SI-2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-VULN-03 — Remediate identified flaws within defined timeframes
- UC-VULN-03 — Remediate identified flaws within defined timeframes maps_to A.8.8 — Management of technical vulnerabilities
- framework
- iso-27001
- control_id
- A.8.8
- coverage
- partial
- delta
- also requires obtaining vulnerability intelligence and evaluating exposure
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-VULN-03 — Remediate identified flaws within defined timeframes mitigates Exploitation of known, unpatched vulnerabilities
- strength
- primary
- rationale
- Installing security updates within risk-based timeframes and verifying by rescan directly defends against exploitation of known unpatched flaws.
- SOC 2 Type II Interim Testing tests UC-VULN-03 — Remediate identified flaws within defined timeframes
- Vulnerability & Patch Management Cycle operates UC-VULN-03 — Remediate identified flaws within defined timeframes