Under active development Content is continuously updated and improved

SI-2(6)Flaw Remediation | Removal of Previous Versions of Software and Firmware

IL5
IL6

>Control Description

Remove previous versions of organization-defined software and firmware components after updated versions have been installed.

>DoD Impact Level Requirements

No specific parameter values or requirements for this impact level.

>Discussion

Previous versions of software or firmware components that are not removed from the system after updates have been installed may be exploited by adversaries. Some products may automatically remove previous versions of software and firmware from the system.

>Assessment Interview Topics

Questions assessors commonly ask

Process & Governance:

  • What policies and procedures govern removal of previous versions of software and firmware?
  • Who is responsible for monitoring system and information integrity?
  • How frequently are integrity monitoring processes reviewed and updated?
  • What is your patch management process and timeline?

Technical Implementation:

  • What technical controls detect and respond to removal of previous versions of software and firmware issues?
  • How are integrity violations identified and reported?
  • What automated tools support system and information integrity monitoring?
  • How do you ensure timely installation of security-relevant patches?

Evidence & Documentation:

  • Can you provide recent integrity monitoring reports or alerts?
  • What logs demonstrate that SI-2(6) is actively implemented?
  • Where is evidence of integrity monitoring maintained and for how long?
  • Can you show recent patch installation records?

Ask AI

Configure your API key to use AI features.