NIST 800-53 r5 · Controls catalogue · Family SI
SI-2Flaw Remediation
Identify, report, and correct system flaws; Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation; Install security-relevant software and firmware updates within {{ insert: param, si-02_odp }} of the release of the updates; and Incorporate flaw remediation into the organizational configuration management process.
Last updated: 20 August 2026 13:14 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: partial · 3 mapping(s) from 1 framework(s): OWASP-Web 3 (partial)
Implementations targeting this control (10)
- aws-config-rds-automatic-minor-version-upgrade-enabled RDS instances have minor version auto-upgrade AWS::RDS::DBInstance partial protect enforce CIS v5 §2.2.2CIS v3 §2.3.2Hub RDS.13
- aws-config-cloudwatch-alarm-action-check Critical CloudWatch alarms have at least one action AWS::CloudWatch::Alarm partial detect enforce
- aws-config-autoscaling-group-elb-healthcheck-required Autoscaling Group Elb Healthcheck Required AWS::AutoScaling::AutoScalingGroup partial protect enforce
- aws-config-beanstalk-enhanced-health-reporting-enabled Beanstalk Enhanced Health Reporting Enabled AWS::ElasticBeanstalk::Environment partial protect enforce
- aws-config-dynamodb-throughput-limit-check Dynamodb Throughput Limit Check AWS::DynamoDB::Table partial protect enforce
- aws-config-ec2-managedinstance-patch-compliance-status-check Ec2 Managedinstance Patch Compliance Status Check AWS::EC2::Instance partial protect enforce
- aws-config-elastic-beanstalk-managed-updates-enabled Elastic Beanstalk Managed Updates Enabled AWS::ElasticBeanstalk::Environment partial protect enforce
- aws-config-lambda-dlq-check Lambda Dlq Check AWS::Lambda::Function partial protect enforce
- aws-config-rds-enhanced-monitoring-enabled Rds Enhanced Monitoring Enabled AWS::RDS::DBInstance partial detect enforce
- aws-config-redshift-cluster-maintenancesettings-check Redshift Cluster Maintenancesettings Check AWS::Redshift::Cluster partial protect enforce
ATT&CK techniques this control mitigates (84)
- T1003 OS Credential Dumping Credential Access
- T1003.001 LSASS Memory Credential Access
- T1027 Obfuscated Files or Information Stealth
- T1027.002 Software Packing Stealth
- T1027.007 Dynamic API Resolution Stealth
- T1027.008 Stripped Payloads Stealth
- T1027.009 Embedded Payloads Stealth
- T1047 Windows Management Instrumentation Execution
- T1055 Process Injection Stealth, Privilege Escalation
- T1055.001 Dynamic-link Library Injection Stealth, Privilege Escalation
- T1055.002 Portable Executable Injection Stealth, Privilege Escalation
- T1055.003 Thread Execution Hijacking Stealth, Privilege Escalation
- T1055.004 Asynchronous Procedure Call Stealth, Privilege Escalation
- T1055.005 Thread Local Storage Stealth, Privilege Escalation
- T1055.008 Ptrace System Calls Stealth, Privilege Escalation
- T1055.009 Proc Memory Stealth, Privilege Escalation
- T1055.011 Extra Window Memory Injection Stealth, Privilege Escalation
- T1055.012 Process Hollowing Stealth, Privilege Escalation
- T1055.013 Process Doppelgänging Stealth, Privilege Escalation
- T1055.014 VDSO Hijacking Stealth, Privilege Escalation
- T1059 Command and Scripting Interpreter Execution
- T1059.001 PowerShell Execution
- T1059.005 Visual Basic Execution
- T1059.006 Python Execution
- T1068 Exploitation for Privilege Escalation Privilege Escalation
- T1072 Software Deployment Tools Execution, Lateral Movement
- T1106 Native API Execution
- T1137 Office Application Startup Persistence
- T1137.003 Outlook Forms Persistence
- T1137.004 Outlook Home Page Persistence
- T1137.005 Outlook Rules Persistence
- T1189 Drive-by Compromise Initial Access
- T1190 Exploit Public-Facing Application Initial Access
- T1195 Supply Chain Compromise Initial Access
- T1195.001 Compromise Software Dependencies and Development Tools Initial Access
- T1195.002 Compromise Software Supply Chain Initial Access
- T1195.003 Compromise Hardware Supply Chain Initial Access
- T1203 Exploitation for Client Execution Execution
- T1204 User Execution Execution
- T1204.001 Malicious Link Execution
- T1204.003 Malicious Image Execution
- T1210 Exploitation of Remote Services Lateral Movement
- T1211 Exploitation for Stealth Stealth
- T1212 Exploitation for Credential Access Credential Access
- T1213.003 Code Repositories Collection
- T1213.005 Messaging Applications Collection
- T1221 Template Injection Stealth
- T1495 Firmware Corruption Impact
- T1525 Implant Internal Image Persistence
- T1542 Pre-OS Boot Stealth, Persistence
Weaknesses this control addresses (5)AI-assisted
CWEs ranked by how often they appear in real CVEs. The rationale describes how this control reduces exploitability of each weakness class.
| CWE | Name | CVEs | Why this control addresses it |
|---|---|---|---|
CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | 700+ | Flaw remediation replaces broken or risky cryptographic algorithms once safer implementations are released by vendors. |
CWE-326 | Inadequate Encryption Strength | 500+ | Prompt patching corrects inadequate encryption strength when vendors release updates that increase key sizes or algorithm security. |
CWE-328 | Use of Weak Hash | 90 | Security updates supplant weak hashing algorithms with stronger alternatives before attackers can exploit the original weakness. |
CWE-1104 | Use of Unmaintained Third Party Components | 26 | Timely identification and installation of updates directly prevents use of unmaintained third-party components whose known flaws remain exploitable. |
CWE-477 | Use of Obsolete Function | 16 | Software and firmware updates replace obsolete functions whose retained presence leaves systems exposed to publicly known weaknesses. |
Top CVEs where this control is the strongest mitigation
| CVE | Risk | CVSS | EPSS | Match |
|---|---|---|---|---|
CVE-2026-59847 UPD | 4.6 | 5.9 | 0.0031 | partial |
CVE-2024-20353 KEV UPD | 8.8 | 8.6 | 0.7069 | good |
CVE-2024-50320 | 7.6 | 7.5 | 0.3965 | good |
CVE-2024-36288 UPD | 7.4 | 9.8 | 0.0075 | good |
CVE-2025-21850 UPD | 7.3 | 9.8 | 0.0040 | good |
CVE-2021-42143 UPD | 7.0 | 9.1 | 0.0081 | good |
CVE-2026-24803 UPD | 7.0 | 9.2 | 0.0028 | good |
CVE-2026-24804 UPD | 7.0 | 9.2 | 0.0027 | good |
CVE-2026-24816 UPD | 7.0 | 10.0 | 0.0027 | good |
CVE-2026-31448 UPD | 7.0 | 9.4 | 0.0044 | good |
CVE-2026-4890 UPD | 6.6 | 7.5 | 0.0724 | good |
CVE-2024-1931 UPD | 6.3 | 7.5 | 0.0252 | good |
CVE-2025-20136 UPD | 6.3 | 8.6 | 0.0061 | good |
CVE-2025-20217 UPD | 6.3 | 8.6 | 0.0068 | good |
CVE-2025-20243 UPD | 6.3 | 8.6 | 0.0058 | good |
CVE-2026-42899 UPD | 6.3 | 7.5 | 0.0243 | good |
CVE-2023-45232 UPD | 6.2 | 7.5 | 0.0210 | good |
CVE-2023-45233 UPD | 6.2 | 7.5 | 0.0210 | good |
CVE-2025-20253 UPD | 6.2 | 8.6 | 0.0045 | good |
CVE-2024-24746 UPD | 6.1 | 7.5 | 0.0146 | good |
CVE-2024-30251 UPD | 6.1 | 7.5 | 0.0109 | good |
CVE-2024-45506 UPD | 6.1 | 7.5 | 0.0120 | good |
CVE-2024-50319 | 6.1 | 7.5 | 0.0116 | good |
CVE-2024-50321 | 6.1 | 7.5 | 0.0116 | good |
CVE-2025-5399 UPD | 6.1 | 7.5 | 0.0129 | good |