Workaround
What is Workaround?
A temporary alternative process or procedure used to maintain operations when normal systems or processes are unavailable.
Frameworks that govern workaround
What the standards actually require on workaround
Requirements naming workaround across 6 standards, quoted from the control text.
FIRST CSIRT Services Framework v2.1 Service Area 3 - Vulnerability Management. SCOPE: discovery + tracking + remediation + disclosure of vulnerabilities affecting the constituency.
FIRST-CSIRTF-SA3-VulnMgmt · Service Area 3 - Vulnerability Management and Coordinated Disclosure →The organisation selects a remediation strategy from full fix, configuration mitigation, workaround, or deprecation based on severity, complexity, and customer needs.
30111-6.5 · Remediation Strategy Selection →Including remediation guidance including patches, workarounds, and mitigation steps
29147-7.8 · Remediation information →Reduce the likelihood and impact of incidents by identifying actual and potential causes of incidents and managing workarounds and known errors.
SM-PRB-1 · Problem Management →Execute Containment + Eradication + Recovery per NIST SP 800-61 Rev 2 Section 3.3. Containment Strategy (Section 3.3.1) must be chosen based on (a) potential damage to and theft of resources, (b) need for evidence preservation, (c) service availability require...
NISTSP61-5 · Containment, Eradication, and Recovery →Implement long term containment for systems that cannot be immediately rebuilt, including hardening, monitoring uplift, and temporary workarounds maintained until eradication.
PICERL-C-03 · Containment: Long Term Containment →Questions people ask about workaround
What is Workaround?
Why is Workaround important for compliance?
Which compliance frameworks address Workaround?
Where can I learn more about Workaround?
See how Workaround applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.