{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Vulnerability & Patch Management","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-03","description":"Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.","details":{"control_category":"technical","control_type":"corrective","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"SI-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.8.8","coverage":"partial","delta":"also requires obtaining vulnerability intelligence and evaluating exposure","framework":"iso-27001","relationship":"intersects_with"}],"statement":"Identify, evaluate, and install security-relevant software and firmware updates within documented, risk-based timeframes (for example, critical flaws within 15 days and high-severity within 30). Test patches for effectiveness and side effects before production deployment, use central patch-management tooling to measure coverage, and verify remediation by rescan or configuration check. Document time-bound compensating measures or formal risk acceptance for any flaw that cannot be corrected on schedule.","title":"Remediate identified flaws within defined timeframes","unified_id":"UC-VULN-03"},"id":"uc:UC-VULN-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-VULN-03","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-VULN-03 — Remediate identified flaws within defined timeframes","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:389425c3f4a9e7ee08bec7c6ad3babae3d52ab6aebb3136e8d09f6c366d76336","properties":{"rationale":"Flaw remediation corrects identified software vulnerabilities, including dev-introduced ones, once discovered.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:40118493df14de997232c3400b3ca70d2ce29fbc04338b5b6ae4187f2f9d60f7","properties":{"rationale":"Time-bound patch deployment shrinks the exposure window once a patch ships for a formerly-unknown vulnerability.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:63808bb943daff1d4f3ec9ae4b9571ed86af959b5bee19a49c2c9642fa7a3f87","properties":{"control_id":"SI-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-2-eaa8cf3f.json","targetId":"ctrl:nist-800-53:SI-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:89899f98f598ac17ff4ed15a4c21727527654588c4314ad6d0cb2adf918e2450","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","targetId":"uc:UC-VULN-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2a3c3598fb3e37e3c2d2c40ee861e78f371b126f8f59b460f207cc49b1ad9fa","properties":{"control_id":"A.8.8","coverage":"partial","delta":"also requires obtaining vulnerability intelligence and evaluating exposure","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-8-d3706b09.json","targetId":"ctrl:iso-27001:A.8.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b83edced3e8642f58674a51b396c4f76804639292b0c3a41a85663d6a1de33bd","properties":{"rationale":"Installing security updates within risk-based timeframes and verifying by rescan directly defends against exploitation of known unpatched flaws.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb60de4c19632a04d480e688f0efc2e08157bab063aff8a80cbbbf15a99a287b","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","targetId":"uc:UC-VULN-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3852077b3eba8bcf14d8814eb2ca7fb83cad6909b66ab96fad2ba309c288a08","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","targetId":"uc:UC-VULN-03","type":"operates"}],"schemaVersion":1}
