We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

VR Exception rules taking excessive time on imports

Aaron Molenaar
Mega Guru

Hi all,

 

We have a non-ServiceNow GRC application that handles policy exceptions and garners business risk acceptance. When risk acceptance has been gained in the external system for exceptions to vulnerability or lifecycle policies (i.e. upgrading EOL systems), we started creating co-termed exception rules in VR that defer all vulnerable items that are related to the approved policy exception for the duration of the policy exception. This is usually an entire CI or multiple CIs, but occasionally only select software vulnerabilities on those CIs (i.e. EOL database software).

 

Using exception rules means that multiple (tens/hundreds/thousands) of VIT and corresponding VUL could be deferred without remediation owners and approvers needing to request/process numerous separate tasks, plus needed to repeat the deferral process on each new VIT imported in the system. Highly efficient and accurate.

 

However, with only about 2 dozen exception rules created, we've found that the exception rule processing time in our import processes has jumped to anywhere up to 15-30min PER PROCESS, just for the exception rule portion. Most of the exception rules contain only CI conditions in the form of "ConfigurationItem.Name <is one of> [List of CIs]".

 

Has anyone done anything similar with Exception Rules or used them extensively (lots of rules)? I've done some tuning on assignment rules for performance using scripted assignment rules to club together like conditions, but scripted rules aren't available (exposed?) in the Exception Rule UI.

 

Any thoughts, recommendations or similar experiences/solutions would be appreciated.

0 REPLIES 0