---
sourceDocument: Yokohama Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/security-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with an exception rule in Container Vulnerability Response

# Working with an exception rule in Container Vulnerability Response {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

You can request an exception for container vulnerable items (CVITs) that can't be remediated or deferred immediately. By automating the VI deferral process, you can defer the matching CVITs based on the rule when the system
identifies them.

You can perform the following tasks for an exception rule:

* [Create an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/GsdR0hRopovQDswqsCpqYw "Create a rule to automatically request an exception for a specific condition for a group of container vulnerable items (CVITs), such as a rule with a condition that is based on the vulnerability severity of these CVITs. With this rule, you can defer new and existing CVITs automatically if they match the approved rule condition.")
* [Approve an exception rule request in Container Vulnerability Response](https://www.servicenow.com/docs/NKLV_2DLlq8lJiUM8S_mMA "Assess exception rule requests from users so that you can approve or reject these requests.")
* [Activating an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/uu4j~XkEIusxPFEkKeZbKg "A rule is activated on its \"Valid from\" date. After activation, it automates the exception process for container vulnerable items (CVITs).")
* [Reopen an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/JhL_xoxXz_a84MB9KCDPtA "Reopen an exception rule that has been rejected, but you want to resubmit. Reopening the rule moves it to the Draft state.")
* [Update an approved exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/HLgzH0HbWVqlrfkRTZ3EPg "Cancel an approved rule to be able to update it. For example, before you can modify any dates or add a condition to an approved rule, you must cancel it so that the remediation task (VUL) is deleted, and the container vulnerable items (CVITs) move to the Open state.")
* [Delete an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/HurHuWClaehXg3bIAu_0Qg "Delete an exception rule that is not required anymore. For example, you can delete a rule if you don't want to defer a container vulnerable item (CVIT) during ingestion.")
* [Defer a container vulnerable item in Container Vulnerability Response](https://www.servicenow.com/docs/9lHMgwMnsoD3zU5OTVSlJg "If you determine that the issue associated with a container vulnerable item (CVIT) is of low risk and can be immediately deferred without further analysis, you can use the Defer feature.")

{#working-with-exception-rule-cvr__ul_xgp_frb_vmb}  
Note:  
Starting from v2.5 of Container Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the container vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the container vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see [Configure approval rules for Exception Management](https://www.servicenow.com/docs/GP7K5AWhrvro5tiHmbMA7A "Starting with Vulnerability Response v15.0, use the flow designer to approve exception requests for exception management, exception rules, and false positive management. If you are deploying Vulnerability Response (VR) for the first time, the flow designer is enabled by default.").
* **[Create an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/GsdR0hRopovQDswqsCpqYw)**   
  Create a rule to automatically request an exception for a specific condition for a group of container vulnerable items (CVITs), such as a rule with a condition that is based on the vulnerability severity of these CVITs. With this rule, you can defer new and existing CVITs automatically if they match the approved rule condition.
* **[Approve an exception rule request in Container Vulnerability Response](https://www.servicenow.com/docs/NKLV_2DLlq8lJiUM8S_mMA)**   
  Assess exception rule requests from users so that you can approve or reject these requests.
* **[Activating an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/uu4j~XkEIusxPFEkKeZbKg)**   
  A rule is activated on its "Valid from" date. After activation, it automates the exception process for container vulnerable items (CVITs).
* **[Reopen an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/JhL_xoxXz_a84MB9KCDPtA)**   
  Reopen an exception rule that has been rejected, but you want to resubmit. Reopening the rule moves it to the Draft state.
* **[Update an approved exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/HLgzH0HbWVqlrfkRTZ3EPg)**   
  Cancel an approved rule to be able to update it. For example, before you can modify any dates or add a condition to an approved rule, you must cancel it so that the remediation task (VUL) is deleted, and the container vulnerable items (CVITs) move to the Open state.
* **[Delete an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/HurHuWClaehXg3bIAu_0Qg)**   
  Delete an exception rule that is not required anymore. For example, you can delete a rule if you don't want to defer a container vulnerable item (CVIT) during ingestion.
* **[Request an extension for a deferred remediation task in Container Vulnerability Response](https://www.servicenow.com/docs/6ANGQHfh1BuP2pLRnWXNyQ)**   
  Request an extension for a deferred remediation task (VUL) before it reaches its deferred until due date. As a remediation owner, you're no longer required to wait until the deferred due date to make this request.
* **[Request an extension for an exception rule in Container Vulnerability Response](https://www.servicenow.com/docs/Ulrzz27J_qEYa8thZvd10w)**   
  Request an extension for a deferred exception rule before it reaches its deferred until due date. As a remediation owner, you're no longer required to wait until the deferred due date to make this request.

