Skip to content

Remediation

What is Remediation?

The process of correcting identified deficiencies, vulnerabilities, or non-conformities to bring systems or processes into compliance.

Audit and Assurance

Each of these is named in at least one of the same controls as remediation. The number is how many controls name both.

What the standards actually require on remediation

Requirements naming remediation across 6 standards, quoted from the control text.

Operate a defined process for fixing vulnerabilities found in applications, using automated remediation where the vulnerability class allows.

CCM-AIS-07 · Application Vulnerability Remediation

The organisation selects a remediation strategy from full fix, configuration mitigation, workaround, or deprecation based on severity, complexity, and customer needs.

30111-6.5 · Remediation Strategy Selection
CIS Controls v85 controls

Establish and maintain a risk-based remediation strategy documented in a remediation process, with monthly, or more frequent, reviews.

CIS-7.2 · Establish and Maintain a Remediation Process

Address CAT III (Category III, low severity) STIG findings, which degrade measures to protect against loss.

STIG-SEV-CAT3 · Category III (low severity) finding remediation

To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.

ISM-1732 · To the extent possible, all intrusion remediation activities are conducted in a coordinate

Worker grievance + remediation + worker voice are cross-cutting requirements applying across all 10 principles. Compliance Benchmarks include: ANONYMOUS + multiple-channel grievance mechanisms (worker hotlines + grievance committees + worker-representative-led...

FLA-Grievance · Worker Grievance, Remediation and Worker Voice (FLA Cross-Cutting)

Questions people ask about remediation

What is Remediation?
The process of correcting identified deficiencies, vulnerabilities, or non-conformities to bring systems or processes into compliance.
Why is Remediation important for compliance?
Remediation is a key concept in Audit and Assurance. Understanding remediation helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Remediation?
Remediation appears in the requirement text of Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, ISO/IEC 30111:2019, CIS Controls v8, DISA Security Technical Implementation Guides (STIGs), Australian Information Security Manual. Across these standards we have identified 31 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Remediation?
Explore our compliance framework pages to see how remediation applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Remediation applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.