Skip to content

Remediation Plan

What is Remediation Plan?

A documented plan of action for addressing identified compliance gaps, audit findings, or security vulnerabilities. Remediation plans include specific actions, owners, timelines, and priorities for closing each identified gap.

Compliance

Each of these is named in at least one of the same controls as remediation plan. The number is how many controls name both.

What the standards actually require on remediation plan

Requirements naming remediation plan across 6 standards, quoted from the control text.

The entity agrees and finalises a Remediation Plan for the findings, in close consultation with the supervisor/authority, and tracks remediation to completion.

TIBER-3.6 · Remediation Plan

Plan and implement risk responses for vulnerabilities, including remediation, mitigation, or acceptance with rationale.

SP800-218-RV.2.2 · Develop and Implement Remediation Plans

The entity must maintain the capabilities needed to execute the business continuity plan including access to people, resources and technology, must monitor compliance with its tolerance levels, and must report any failure to meet a tolerance level to the Board...

CPS230-P41 · BCP Execution Capability and Tolerance Breach Reporting

Article 37 establishes a cross-border VERIFICATION REGIME for NCCS compliance: independent verification of high-impact entity compliance with Article 30 minimum controls + critical-impact entity compliance with Article 32 advanced controls.

NCCS-Art.37_38_39 · Cross-border verification and mutual recognition (NCCS Articles 37-39)
FedRAMP Rev 51 control

The FedRAMP AUTHORIZATION BOUNDARY is the precise definition of the cloud system + all of its components subject to FedRAMP authorization.

FedRAMP-Boundary · Authorization Boundary, SSP, SAR, POA&M documentation

Incident response for FTI breaches requires specific procedures beyond NIST 800-53 IR family. Reporting Timelines: (1) Within 24 hours of incident discovery (suspected or actual unauthorised disclosure inspection use or access of FTI) report to (a) IRS Office...

IRSPub1075-IncidentResponse-FTIBreach-24Hour-TIGTA-OfficeOfSafeguards-Notification-Containment · IRS Pub 1075 Section 9.3.8 + Incident Response + FTI Breach + 24-Hour Notification + TIGTA Treasury Inspector General for Tax Administration + IRS Office of Safeguards + Containment + Investigation

Questions people ask about remediation plan

What is Remediation Plan?
A documented plan of action for addressing identified compliance gaps, audit findings, or security vulnerabilities. Remediation plans include specific actions, owners, timelines, and priorities for closing each identified gap.
Why is Remediation Plan important for compliance?
Remediation Plan is a key concept in Compliance. Understanding remediation plan helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Remediation Plan?
Remediation Plan appears in the requirement text of ECB TIBER-EU Framework, NIST SP 800-218, APRA CPS 230 Operational Risk Management, EU Network Code on Cybersecurity for the Electricity Sector, FedRAMP Rev 5. Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Remediation Plan?
Explore our compliance framework pages to see how remediation plan applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Remediation Plan applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.