Direct implementation supportHigh confidence
Why: Remediating in accordance with risk is the practice's defining move: findings ranked by known-exploited status, exposure, and asset criticality rather than raw scanner severity, with remediation windows by severity that the organization holds itself to and measures.
What this does not claim: Supports implementation without satisfying the requirement alone: 'in accordance with risk assessments' ties remediation to 3.11.1's organizational assessment, which the practice consumes rather than produces. Exception handling must also hold up — an unremediated finding without a recorded decision and compensating control is precisely where this requirement fails under assessment.
Practice-side activities- Set remediation windows by severity and track mean time to remediate against them
- Rank findings by exploitability, exposure, and asset criticality
- Maintain the exception register with compensating controls and expiry dates
Evidence this produces- Mean-time-to-remediate reporting by severity
- Remediation records showing closure within the agreed windows
- The exception register with owners and expiry dates
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportModerate confidence
Why: The practice's patch-or-compensate decision is remediation under production constraints: vendor-approved patches validated on a bench and applied inside agreed maintenance windows with rollback ready, and documented compensating controls — isolation, tighter access — with expiry dates when patching must wait.
What this does not claim: May partially address the requirement, and only inside the CUI boundary; the requirement does not contemplate control-system patch constraints, so an assessor will probe whether a compensating control genuinely reduces the risk the missing patch leaves open. A declined patch is defensible only while its written decision, mitigation, and re-evaluation date stay current — an expired compensating control is just an unremediated finding with paperwork.
Practice-side activities- Validate patches on a bench or non-critical unit before production
- Schedule remediation inside approved maintenance windows with the process owner present and rollback tested
- Log every patch-or-compensate decision with a named approver and an expiry for the compensating path
Evidence this produces- The patch-or-compensate decision log
- Compensating-control records with expiry and re-evaluation dates
- The high-risk-findings-addressed metric
Where this holds: Production environments where maintenance windows and vendor certification govern change; the deliberate-decline path is the norm here, not the exception.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06