Security Requirements for 03.14.01 Flaw Remediation

Organizations identify systems that are affected by announced software and firmware flaws, including potential vulnerabilities that result from those flaws, and report this information to designated personnel with information security responsibilities. Security-relevant updates include patches, service packs, hot fixes, and anti-virus signatures. Organizations address the flaws discovered during security assessments, continuous monitoring, incident response activities, and system error handling. Organizations can take advantage of available resources (e.g., CWE or CVE databases) when remediating system flaws. Organization-defined time periods for updating security-relevant software and firmware may vary based on a variety of factors, including the criticality of the update (i.e., severity of the vulnerability related to the discovered flaw). Some types of flaw remediation may require more testing than other types.

View CPRT 03.14.01
  1. 03.14.01.a

    Identify, report, and correct system flaws.

  1. 03.14.01.b

    Install security-relevant software and firmware updates within [Assignment: organization-defined time period] of the release of the updates.