CMMC Level 1 · Assessment ObjectiveSEC / OBJSI.L1-b.1.xii(c)

System and Information Integrity · SI.L1-b.1.xii(c)

The time within which to report system flaws is specified

An assessment objective under requirement SI.L1-b.1.xii, Flaw Remediation, in the System and Information Integrity domain.

Objective Statement

the time within which to report system flaws is specified
Source · NIST SP 800-171A

Objective identity

Framework
Cybersecurity Maturity Model Certification · Level 1
Domain
System and Information Integrity (SI)
Objective ID
SI.L1-b.1.xii(c)

Assessment Procedures

The official government assessment method for this objective, from NIST SP 800-171A. An assessor examines artifacts, interviews people, and tests mechanisms to determine the result.

Examine

  • System and information integrity policy
  • procedures addressing flaw remediation and malicious code protection
  • system security plan
  • list of identified system flaws and vulnerabilities
  • malicious code protection mechanisms and configuration
  • scan results and logs
  • other relevant documents or records

Interview

  • Personnel with flaw remediation and malicious code protection responsibilities
  • system or network administrators
  • personnel with information security responsibilities

Test

  • Organizational processes for identifying, reporting, and correcting system flaws
  • mechanisms supporting or implementing malicious code protection and periodic/real-time scanning

Source Authority

Primary Authority
NIST SP 800-171A
Requirement Authority
FAR 52.204-21(b)(1)
Framework Version
CMMC Assessment Guide, Level 1 v2.13 (September 2024)
Effective Date
2024-12-16
Last Verified
2026-08

Build the Record Behind This

AssessrLog logs the determination for this objective with its evidence and source record, so your Level 1 self-assessment stays traceable and ready to affirm. The MET, NOT MET, or N/A call is always yours to make.