PlumbTrackLive demoGRC Risk System

← internal audit

Audit — SI-2 — Flaw Remediation

Framework: NIST SP 800-53 Rev.5 SI-2 · Mark each check Pass / Fail / N/A; a Fail is a finding to remediate. · open the item

0 pass · 0 finding(s) · 0 N/A · 0 of 7 checked
Examine Does a documented flaw remediation / patch management policy exist that defines maximum remediation timeframes by vulnerability severity (e.g., critical/high patched within a stated number of days), consistent with CIS Control 7 Continuous Vulnerability Management?
Examine For a sample of security-relevant software and firmware updates, examine deployment records and confirm each was installed within the policy-defined timeframe from release or advisory date.
Test Run or review a recent authenticated vulnerability scan of a sample of production hosts and confirm no missing critical/high patches remain open past their remediation SLA.
Interview How does the team identify and report newly disclosed flaws affecting in-scope systems (e.g., vendor advisories, automated scanners, the CISA Known Exploited Vulnerabilities catalog)?
Examine Examine change/test records to confirm updates are tested for effectiveness and potential side effects in a non-production or pilot environment before organization-wide installation.
Examine Examine change management tickets to confirm flaw remediation actions are processed through the configuration/change control workflow (approval, back-out plan, verification) rather than applied ad hoc.
Examine Examine remediation metrics/reports to confirm the organization measures and tracks mean time to remediate (time from flaw identification to correction) against its stated targets.