Remediation Plan
What is Remediation Plan?
A documented plan of action for addressing identified compliance gaps, audit findings, or security vulnerabilities. Remediation plans include specific actions, owners, timelines, and priorities for closing each identified gap.
Terms that appear alongside remediation plan
Each of these is named in at least one of the same controls as remediation plan. The number is how many controls name both.
- cyber incident 3 shared controls
- lessons learned 3 shared controls
- cybersecurity 3 shared controls
- compliance 3 shared controls
- insider threat 2 shared controls
- impact assessment 2 shared controls
- incident reporting 2 shared controls
- data breach notification 2 shared controls
Frameworks that govern remediation plan
What the standards actually require on remediation plan
Requirements naming remediation plan across 6 standards, quoted from the control text.
The entity agrees and finalises a Remediation Plan for the findings, in close consultation with the supervisor/authority, and tracks remediation to completion.
TIBER-3.6 · Remediation Plan →Plan and implement risk responses for vulnerabilities, including remediation, mitigation, or acceptance with rationale.
SP800-218-RV.2.2 · Develop and Implement Remediation Plans →The entity must maintain the capabilities needed to execute the business continuity plan including access to people, resources and technology, must monitor compliance with its tolerance levels, and must report any failure to meet a tolerance level to the Board...
CPS230-P41 · BCP Execution Capability and Tolerance Breach Reporting →Article 37 establishes a cross-border VERIFICATION REGIME for NCCS compliance: independent verification of high-impact entity compliance with Article 30 minimum controls + critical-impact entity compliance with Article 32 advanced controls.
NCCS-Art.37_38_39 · Cross-border verification and mutual recognition (NCCS Articles 37-39) →The FedRAMP AUTHORIZATION BOUNDARY is the precise definition of the cloud system + all of its components subject to FedRAMP authorization.
FedRAMP-Boundary · Authorization Boundary, SSP, SAR, POA&M documentation →Incident response for FTI breaches requires specific procedures beyond NIST 800-53 IR family. Reporting Timelines: (1) Within 24 hours of incident discovery (suspected or actual unauthorised disclosure inspection use or access of FTI) report to (a) IRS Office...
IRSPub1075-IncidentResponse-FTIBreach-24Hour-TIGTA-OfficeOfSafeguards-Notification-Containment · IRS Pub 1075 Section 9.3.8 + Incident Response + FTI Breach + 24-Hour Notification + TIGTA Treasury Inspector General for Tax Administration + IRS Office of Safeguards + Containment + Investigation →Questions people ask about remediation plan
What is Remediation Plan?
Why is Remediation Plan important for compliance?
Which compliance frameworks address Remediation Plan?
Where can I learn more about Remediation Plan?
See how Remediation Plan applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.