1Overview
SI.L2-3.14.1 opens the System and Information Integrity family with the flaw remediation requirement. It requires that system flaws be identified, reported, and corrected in a timely manner, so that vulnerabilities in the system are found, communicated, and fixed within defined time frames rather than lingering. It is a five-point requirement that cannot be deferred on a plan of action.
System flaws, the vulnerabilities that patches and fixes address, are discovered continuously, and the window between a flaw becoming known and being corrected is when it is most exploitable. This control requires managing that window across three actions, each bounded by time: flaws are identified within a specified time, reported within a specified time, and corrected within a specified time. The timeliness is the point, so the organization defines how quickly each step must happen and then meets those time frames. Its five-point weight reflects that unpatched flaws are among the most common paths to compromise. It has six assessment objectives, pairing a specified time frame with performance for each of identify, report, and correct.
Identify, report, and correct system flaws in a timely manner.
The requirement names three actions, identify, report, and correct, all in a timely manner, and the six assessment objectives make the timeliness explicit by pairing a specified time frame with performance for each. The time to identify flaws is specified and flaws are identified within it; the time to report is specified and flaws are reported within it; the time to correct is specified and flaws are corrected within it. Defining the time frames and meeting them is what makes flaw remediation timely rather than open-ended.
2The Assessment Objectives
NIST SP 800-171A decomposes 3.14.1 into six objectives: a specified time and performance for each of identify, report, and correct.
The time within which to identify system flaws is specified. How quickly flaws must be identified is set.
System flaws are identified within the specified time frame. Flaws are found on schedule.
The time within which to report system flaws is specified. How quickly flaws must be reported is set.
System flaws are reported within the specified time frame. Flaws are communicated on schedule.
The time within which to correct system flaws is specified. How quickly flaws must be corrected is set.
System flaws are corrected within the specified time frame. Flaws are fixed on schedule.
The six objectives pair a specified time with performance for identify, report, and correct. The common gaps are at objectives [e] and [f], correction, where flaws are found and reported but not fixed within the time frame, so patches lag. The assessor looks for specified times and performance within them across all three actions.
3Failure Patterns
The failures are about flaws that are not remediated in time.
No specified time frames
Without specifying how quickly flaws must be identified, reported, and corrected, timeliness has no standard. Specifying the time frames sets the bar.
Patches lag correction targets
Flaws found and reported but corrected slowly leave known vulnerabilities open. Correcting within the specified time closes them promptly.
Identification without a schedule
Finding flaws only sporadically, with no specified time to identify, lets vulnerabilities go unnoticed for long stretches. A specified identification time frame drives regular discovery.
4Ownership
This is an IT and security-owned control tied to patch and vulnerability management.
| Role | Responsibility for this control |
|---|---|
| IT and security | Identifies, reports, and corrects flaws within the specified time frames. Owns the flaw remediation evidence. |
| Security or compliance lead | Specifies the time frames and confirms performance against them. |
| Program lead | Reviews remediation timeliness and retains the records. |
5Tooling
The control is delivered by patch and vulnerability management within defined time frames.
| Objectives | Tooling | What it provides |
|---|---|---|
| [a], [c], [e] | Defined time frames | Specified times to identify, report, and correct. |
| [b], [d] | Vulnerability scanning and flaw reporting | Flaws identified and reported within time. |
| [f] | Patch management | Flaws corrected within time. |
The caveat is that both the time frames and the performance have to be present across all three actions. Defined times with slow correction, or fast correction without defined times, leave objectives unmet. The assessor examines all six, so the specified times and performance within them have to hold.
6Evidence
The satisfied version of 3.14.1 shows flaws remediated within defined time frames.
| Evidence | What it demonstrates |
|---|---|
| Defined remediation time frames | Objectives [a], [c], [e]. Specified times to identify, report, correct. |
| Flaw and patch records | Objectives [b], [d], [f]. Flaws identified, reported, and corrected within time. |
The evidence should show specified time frames and records of flaws identified, reported, and corrected within them. The defined time frames together with the flaw and patch records are the clearest demonstration, and because this control cannot sit on a plan of action, the timely remediation has to be real at the time of assessment.
A known flaw left open is an open door
The window between a flaw becoming known and being fixed is when it is most exploitable, so this five-point control asks that flaws be identified, reported, and corrected within defined time frames. Building timely flaw remediation is part of the onsite readiness work this practice does, and it is one of the controls that must be met rather than deferred.
Start CMMC Readiness or call 802-335-26627Sources
- NIST Special Publication 800-171 Rev 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, requirement 3.14.1. csrc.nist.gov
- NIST Special Publication 800-171A, Assessing Security Requirements for Controlled Unclassified Information, assessment objectives 3.14.1[a] through 3.14.1[f]. csrc.nist.gov
- 32 CFR 170.24, CMMC Scoring Methodology, listing SI.L2-3.14.1 among the five-point basic security requirements. ecfr.gov