Create, delete, and cancel an exception rule for Application Vulnerability Response
Create a rule to request an exception automatically for application vulnerable items (AVI)s that meet specific conditions.
Avant de commencer
As an example, you might create a rule with a condition that is based on a specific known or critical vulnerability that you know you cannot fix immediately. With this rule, you can defer new and existing AVIs automatically if they match the approved rule condition.
- The exception rule is applied from the Valid from until the Valid to date that you enter on the rule record.
- The remediation task (AVUL) is created after the rule is approved for matching AVIs in the Deferred state.
- The grouping method for this AVUL is known as Exception Rules.
- You can't close, reopen, or delete this AVUL. New and reopened AVIs are deferred and added to this AVUL from the Valid from date until the group expires on the Valid to date.
Email notifications are sent at every stage of the exception rule workflow. These emails provide the status and other details of a request. For example, when an exception rule is requested, the requester receives an email that confirms that the request is submitted.
If the rule is rejected, you can reopen it in the Draft state, update it, and then resubmit it for approval.
Roles required: App SEC Manger sn_vul.app_sec_manager and Security Champion sn_vul.app_security_champion.