SI-02.3 ยท Time to Remediate Flaws and Benchmarks for Corrective Actions

Control Description

Measure the time between flaw identification and flaw remediation; and Establish the following benchmarks for taking corrective actions: {{ insert: param, si-02.03_odp }}.

Impact Baselines
Security baselines where this control applies
Not in any baseline
Control Properties
SP800-53-enhancement
organization
Enhancement
Control Statement
The control requirements

(a) Measure the time between flaw identification and flaw remediation; and

(b) Establish the following benchmarks for taking corrective actions: {{ insert: param, si-02.03_odp }}.

Supplemental Guidance

Organizations determine the time it takes on average to correct system flaws after such flaws have been identified and subsequently establish organizational benchmarks (i.e., time frames) for taking corrective actions. Benchmarks can be established by the type of flaw or the severity of the potential vulnerability if the flaw can be exploited.