Configure Exception Management for Security Exposure Management
When your organization can't comply with a vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions to a finding or remediation task (RT) that can't be remediated according to the policy.
Before you begin
Use the Security Exposure Management workspace to limit the duration of an exception request and add a questionnaire to the exception or false positive request. You can also request an exception using the GRC: Policy and Compliance Management integration.
Role required: sn_vul_exception.admin
About this task
If Vulnerability Response is enabled, you can limit the duration for which an exception can be requested. Similarly, if the GRC: Policy and Compliance Management module is installed, you can select GRC: Policy and Compliance Management on the configuration screen. Enabling this option enables you to request an exception that specifies the Policy and Control objective from GRC.
The exception approver requires the reason for the exception request.