Under active development Content is continuously updated and improved

SI-2(6)Flaw Remediation

Operational

>Control Description

FLAW REMEDIATION | REMOVAL OF PREVIOUS VERSIONS OF SOFTWARE / FIRMWARE The organization removes organization-defined software and firmware components after updated versions have been installed.

>Supplemental Guidance

Previous versions of software and/or firmware components that are not removed from the information system after updates have been installed may be exploited by adversaries. Some information technology products may remove older versions of software and/or firmware automatically from the information system.

>Tailoring Guidance

This security control/enhancement specifies the use of an automated mechanism. While there are obvious benefits to the use of such mechanisms, in most cases the use of manual mechanisms will suffice.

Ask AI

Configure your API key to use AI features.