Direct implementation supportHigh confidence
Why: The practice's scan-prioritize-remediate cycle — authenticated scanning across the inventory, ranking by exploitability and asset criticality, remediation held to defined windows — is the substance of this requirement, which in Rev. 3 includes remediation directly rather than in a separate item.
What this does not claim: Supports implementation of the requirement; it does not satisfy it on its own. Rev. 3's scanning frequencies and remediation response times are organization-defined parameters — the practice's fourteen- and thirty-day windows are a defensible starting point, not the defined values an assessor will test against until the organization adopts and records them. The requirement also expects the set of vulnerabilities scanned for to be kept current, which depends on feed and scanner maintenance beyond the remediation cycle itself.
Practice-side activities- Run authenticated scans on a schedule reconciled against the asset inventory
- Adopt and record severity-based remediation windows as the organization's defined response times
- Track remediation aging with owners and dated decisions for anything past its window
Evidence this produces- Scan schedules and coverage reconciliation reports
- The recorded response-time parameters with remediation metrics held against them
- Aging reports showing findings past window, each with a decision
Where this holds: Holds for IT estates the scanner can reach with credentials; weakens for unscannable or fragile assets, which need documented alternative monitoring.
Review status: Technical review complete · Reviewed by inDirectIT practitioner review — CUI security and NIST SP 800-171 engineering · updated 2026-08-06
Partial implementation supportModerate confidence
Why: The practice runs the same monitor-and-remediate cycle for the OT estate, adjusted to production reality: vulnerability identification through passive discovery and vendor advisories, patching inside maintenance windows, and compensating measures where patching would threaten operations.
What this does not claim: May partially address the requirement for the OT portion of an assessed boundary. Active scanning can crash fragile controllers, so the practice often substitutes passive discovery and advisory monitoring — a legitimate method, but one an assessor will expect to see documented as the organization's defined approach rather than assumed. Where a vulnerability cannot be remediated within the defined response times, the compensating measure and its formal acceptance must be recorded, or the gap between the parameter and the plant's reality becomes the finding.
Practice-side activities- Maintain OT vulnerability visibility through passive discovery and vendor advisory tracking
- Schedule remediation into maintenance windows with production and safety sign-off
- Document compensating measures and their acceptance where patching is deferred
Evidence this produces- OT vulnerability tracking records tied to the validated asset list
- Maintenance-window remediation records
- Documented compensating measures with acceptance and review dates
Where this holds: Holds for OT environments where active scanning is constrained; the documented-method and compensating-measure records are what carry the relationship.
Review status: Pending NIST SME review · Reviewed by Brilliant at the Basics editorial — practitioner-authored; NIST SME review pending · updated 2026-08-06