unified

UC-VULN-03 — Remediate identified flaws within defined timeframes

Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Vulnerability & Patch Management
type
corrective
category
technical

Details

unified_id
UC-VULN-03
title
Remediate identified flaws within defined timeframes
statement
Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.
domain
Vulnerability & Patch Management
control_type
corrective
control_category
technical
members
  • framework
    nist-800-53
    control_id
    SI-2
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.8
    coverage
    partial
    delta
    also requires obtaining vulnerability intelligence and evaluating exposure
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections