Skip to content
ControlVerdict
SI.L2-3.14.1addresses
SI.L2-3.14.1Flaw Remediation [CUI Data]
Identify, report, and correct system flaws in a timely manner.
  • [a]

    the time within which to identify system flaws is specified;
  • [b]

    system flaws are identified within the specified time frame;
  • [c]

    the time within which to report system flaws is specified;
  • [d]

    system flaws are reported within the specified time frame;
  • [e]

    the time within which to correct system flaws is specified; and
  • [f]

    system flaws are corrected within the specified time frame.

View full control

Written SLAs by severity, with scans that open tickets and a POA&M for the misses

ControlVerdict Corpus@cv-corpusOSCJul 31, 2026
Community is just starting — add yours. Only 2 verdicts so far.Last verdict Aug 2, 2026

Implementation

AO coverage. Addresses all six Flaw Remediation objectives: the time frames for identifying, reporting, and correcting flaws are each specified, and each is met in practice.

Time to identify, specified [a]. Authenticated vulnerability scans run weekly against every in-scope asset, with agent-based inventory refreshing daily and internet-facing appliances scanned every 72 hours. The standard states the identification window as 7 days from vendor disclosure for scanned assets, and 72 hours for anything appearing on the CISA Known Exploited Vulnerabilities list.

Identifying within it [b]. Scan coverage is reconciled against the asset inventory monthly; an asset in the inventory with no scan result in the last 14 days opens a ticket against the platform team, because unscanned assets are the way this objective quietly fails. Advisory-driven discovery is handled through the security alerts practice and feeds the same queue.

Time to report, specified and met [c][d]. Findings are reported into the ticket queue within 2 business days of the scan, automatically, so reporting does not depend on an analyst having time. A monthly summary goes to the CISO and IT lead: new findings by severity, SLA attainment, and open POA&M items. Anything on the KEV list is reported same-day to the on-call channel rather than waiting for the batch.

Time to correct, specified [e]. Critical: 7 days for internet-facing, 14 days internal. High: 30 days. Medium: 90 days. Low: next quarterly maintenance cycle. KEV-listed and internet-facing: 72 hours under emergency change. The values live in the configuration standard with their rationale so an assessor compares a document to a report rather than taking someone's word for the numbers.

Correcting within it [f]. Windows endpoints and servers patch through staged rings — pilot, broad, then critical infrastructure — with a deadline that enforces reboot rather than deferring indefinitely. Linux build servers patch on a weekly window with automated reboot for kernel updates. Appliance firmware is a change ticket with a named owner. A finding that cannot be fixed inside the SLA does not simply age: it moves to the POA&M with a compensating control, a target date, and an approver, and it appears in the monthly report until closed.

Maintenance. Monthly SLA attainment report by severity, trended so a slipping category is visible before an assessment. Quarterly review of the SLA values themselves against contract requirements. Annual review of which assets are exempt from automated patching and why.

Accepted gap. The lab CNC controller's firmware is only patchable during the annual plant shutdown because the vendor requires an on-site engineer. It is on an isolated VLAN with no route to the enclave, monitored at its single upstream interface, and carries a standing POA&M entry with the vendor's statement attached.

What the evidence looks like

  • Configuration standard stating the identify, report, and correct time frames with rationale
  • Scan schedule and a coverage reconciliation report against the asset inventory
  • Sample tickets showing the SLA clock, including one closed inside a 7-day critical window
  • Monthly SLA attainment report and the current POA&M register
  • Update ring configuration showing enforced deadlines and reboot behavior

Environment

~300-staff supplier. Windows fleet managed by Intune, a handful of Linux build servers, four internet-facing appliances, and one lab CNC controller.

Tools

2 ratings on this revision

  • AlignedControlVerdict Assessor@cv-assessorAug 2, 2026

    Across the finish line

    Scanning plus remediation with ticket linkage is the usual pass pattern for this practice when the SLA is actually enforced.

  • BarelyControlVerdict Consultant@cv-consultantConsultantAug 2, 2026

    Across the finish line

    Flaw remediation SLA and scanning cadence are stated.

    Gaps

    Want clearer ownership when a finding sits past the SLA — who escalates, and what evidence shows that path was used.

Was this example useful?

Quick reaction — no account needed. For reasoning that moves the community meter, cast a full verdict below.

Discussion(0)

No discussion on this example yet

Verdicts capture a conclusion. Use a thread when the interesting part is the argument.

Sign in to start a thread.