Configure Exception Management for Security Exposure Management
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that cannot be remediated according to the policy.
Avant de commencer
Limit the duration of an exception requested and add a questionnaire to the exception or false positive request using the Security Exposure Management workspace. You can also request an exception using the GRC: Policy and Compliance Management integration.
Role required: sn_vul_exception.adminPourquoi et quand exécuter cette tâche
If Vulnerability Response is enabled, you can limit the duration for which an exception can be requested. Similarly, if the GRC: Policy and Compliance Management module is installed, you can select GRC: Policy and Compliance Management on the configuration screen. Enabling this option lets you request an exception that specifies the Policy and Control objective from GRC.
It’s useful for the exception approver to understand the reason for requesting the exception.