1Overview
RA.L2-3.11.3 closes the Risk Assessment family by acting on what scanning finds. It requires that vulnerabilities be remediated in accordance with risk assessments, so that the weaknesses found are actually fixed, prioritized by the risk they pose. It is a one-point requirement and may be deferred on a plan of action.
Finding vulnerabilities matters only if they are then addressed. This control requires that identified vulnerabilities be remediated, and that the remediation be guided by risk, so the most dangerous weaknesses are addressed first rather than every finding being treated identically. It closes the loop that the scanning of the previous control opens: scanning finds the weaknesses, and remediation, prioritized by risk, resolves them. The two assessment objectives are the identification of vulnerabilities and their risk-based remediation.
Remediate vulnerabilities in accordance with risk assessments.
The requirement is to remediate vulnerabilities, guided by risk assessments. The assessment objectives make clear that vulnerabilities are first identified, then remediated in accordance with the organization's risk assessments, so that the response is prioritized by the risk each vulnerability presents. Remediation may mean patching, reconfiguring, or otherwise resolving the weakness, and tying it to risk ensures effort goes where the exposure is greatest.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.11.3 into two objectives: identify vulnerabilities and remediate them in accordance with risk assessments.
Vulnerabilities are identified. The weaknesses to be addressed are known.
Vulnerabilities are remediated in accordance with risk assessments. Weaknesses are fixed, prioritized by risk.
The two objectives are identification and risk-based remediation. The common failure is at objective [b], where vulnerabilities are identified and reported but not actually remediated, so scan findings accumulate unaddressed. The assessor looks for both identification and remediation guided by risk.
3Failure Patterns
The failures are about vulnerabilities found but not fixed.
Findings not remediated
Vulnerabilities identified by scanning but never remediated leave the weaknesses open despite being known. Remediation is what closes them.
No risk-based prioritization
Treating every finding identically, or addressing low-risk issues while high-risk ones wait, misuses limited effort. Remediation in accordance with risk assessments directs effort to the greatest exposure.
No remediation tracking
Without tracking which vulnerabilities are remediated and which remain, findings are lost and closure cannot be shown. Tracking remediation demonstrates the loop is closed.
4Ownership
This is an IT and security-owned control tied to the remediation process.
| Role | Responsibility for this control |
|---|---|
| IT and security | Remediates identified vulnerabilities, prioritized by risk. Owns the remediation evidence. |
| Security or compliance lead | Ties remediation priority to the risk assessments and tracks closure. |
| Program lead | Confirms findings are remediated, not just reported, and retains the records. |
5Tooling
The control is delivered by a remediation process that acts on findings by risk.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a] | Scanning and vulnerability sources | Identification of the vulnerabilities to address. |
| [b] | Risk-prioritized remediation and tracking | Fixing of weaknesses, worst first, with closure tracked. |
The caveat is that remediation has to actually happen and follow risk. Identifying vulnerabilities without resolving them, or resolving them without regard to risk, leaves the control unmet. The assessor examines both identification and risk-based remediation, so findings have to be tracked through to closure.
6Evidence
The satisfied version of 3.11.3 shows vulnerabilities remediated by risk.
| Evidence | What it demonstrates |
|---|---|
| Vulnerability findings | Objective [a]. Vulnerabilities are identified. |
| Remediation records | Objective [b]. Vulnerabilities remediated in accordance with risk. |
The evidence should show vulnerabilities identified and then remediated with priority guided by risk assessments. The findings together with the remediation records are the clearest demonstration of the control.
Finding a weakness is not the same as closing it
Scanning produces findings readily, but they matter only when fixed, so this control asks that vulnerabilities be remediated in accordance with risk, worst first. Building a remediation process that closes findings by risk is part of the onsite readiness work this practice does.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.11.3. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.11.3[a] and 3.11.3[b]. csrc.nist.gov
- 32 CFR 170.21, Plan of Action and Milestones Requirements, governing which requirements may remain open at a Level 2 assessment. ecfr.gov