Request bulk exception in the Security Exposure Management Workspace
Request an exception for multiple findings concurrently using the bulk edit feature instead of manually selecting each record.
Before you begin
Role required:
- sn_vul.vulnerability_analyst, sn_vul.vulnerability_admin, or sn_vul.remediation_owner for host vulnerable items (VITs)
- sn_vul.app_sec_manager, sn_vul.app_security_champion for application vulnerable items (AVITs)
- sn_vul_container.vulnerability_analyst, sn_vul_container.vulnerability_admin, or sn_vul_container.remediation_owner for container vulnerable items (CVITs)
- sn_vulc.admin, sn_vulc.remediation_owner for configuration test results (CTRs)
About this task
When you request an exception for one or more records from the Bulk edit modal, a remediation task is created with the selected records. The remediation task is created only when Deferred or Closed-false positive state is
selected.
Note:
The Application Vulnerable Items (AVITs) from the scanners with the Manage exceptions in ServiceNow parameter set to false aren't updated.
- If you select AVITs from various scanners, some with the Manage exceptions in ServiceNow parameter set to true and other set to false, the AVITs linked to the scanners with he Manage exceptions in ServiceNow parameter set to false aren't updated.
- If you select AVITs from only the scanners with the Manage exceptions in ServiceNow parameter set to false, the Defer option does not appear in the State field in the Bulk Edit modal.
Procedure
Result
In the Security Exposure Management Workspace, on the List page, navigate to , open the corresponding state change approval record (VCA#) and check the status of your request in the Approval state column:
| Approval state | Result |
|---|---|
| Approved | The state of the Remediation task transitions to Deferred with the given Reason as sub-state. The state and reason are rolled down to the records.The state of the Remediation task transitions to Deferred with the given Reason as sub-state. The state and reason are rolled down to the records. When risk reduction is also requested, a separate change approval is created for the risk reduction request. If that approval is also approved, the risk rating of the records is updated to the desired risk rating that was selected during the bulk edit request. |
| Rejected | The state of the Remediation Task and its records doesn’t change. |
In the Activity stream of a record or remediation task, you can view the entire workflow of your request.