Configuration Compliance Exception Management overview
Summarize
Summary of Configuration Compliance Exception Management overview
Configuration Compliance Exception Management enables your organization to request, review, approve, or reject exceptions when remediation tasks cannot comply with published vulnerability management or security policies. This process acknowledges accepted risks when remediation cannot be performed due to the lack of available patches or solutions. Exception management is supported in both the Vulnerability Manager Workspace and IT Remediation Workspace of ServiceNow.
Show less
Key Processes
- Requesting an Exception: Remediation owners can request exceptions for remediation tasks that cannot be immediately addressed. During review, the task remains in an "In review" state and moves to "Deferred" once approved. Exception requests are initiated from the IT Remediation Workspace.
- Approving an Exception: Exception requests undergo risk assessment and approval, potentially involving a two-level approval workflow. Without a first-level approver configured, exception requests cannot be made. Approvals and rejections are managed in the Vulnerability Manager Workspace. Comments on rejections are recorded in the remediation task’s work notes, and rejected tasks revert to their prior state.
- Tracking Exceptions: The status of exception requests can be monitored via the State Change Approvals tab within the remediation task. However, individual test results within the remediation task are not tracked separately once an action is taken.
- Exception Expiry: Upon expiration of an approved exception, the remediation task returns to the "Open" state, requiring remediation action to resume.
Important Details
- Terminology updates from Configuration Compliance v14.9 renamed key elements to better align with remediation tasks (e.g., "Test Result Group" is now "Remediation Task Group").
- Starting with Configuration Compliance v13.0, exception management utilizes Flow Designer by default, replacing previous workflow methods.
- Exception approval workflows require configured approvers; otherwise, exceptions cannot be requested.
Practical Benefits for ServiceNow Customers
This feature helps your organization manage exceptions to compliance policies effectively, ensuring that unavoidable risks are formally documented and tracked. It streamlines exception workflows, maintains clear visibility into exception statuses, and ensures that remediation tasks proceed appropriately after exceptions expire. By integrating exception management into your vulnerability and IT remediation workspaces, you can maintain stronger security governance while accommodating real-world constraints.
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions for a remediation task that cannot be remediated according to the policy.
| Terminology prior to v14.9 | Terminology v14.9 onwards |
|---|---|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the configuration-related vulnerability.
Life cycle of an exception
An exception is a request to defer the remediation of a remediation task for a specified period.
- Requesting an exception
- Approving an exception request
- Tracking an exception request
- Expiry of an exception request
As the remediation owner, you can ask for an exemption for a remediation task using the exception management process. During the approval process, the remediation task remains in In review state. After the exception approver approves this request, the remediation task moves to a Deferred state.
Starting from Configuration Compliance v13.0, if you are deploying the CC application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update to the flow designer. In both cases, you cannot change it back to workflow.
- Reopen
- Delete
After raising the exception, you can track its status by using the State Change Approvals tab of the remediation task. If an action is taken on a remediation task, you can't track the status of the individual test results in that remediation task.
When an exception request for a remediation task expires, the remediation task reverts to its Open state.