Deferring findings automatically without manual intervention using exception rules
Summarize
Summary of Deferring Findings Automatically Without Manual Intervention Using Exception Rules
The use of exception rules in Security Exposure Management Workspace allows for the automation of deferring findings, minimizing manual intervention. This process helps manage vulnerabilities or configuration items that cannot be immediately remediated or deferred.
Show less
Key Features
- Automated Deferral: Exception rules automatically defer findings for a specific period based on predefined conditions.
- Service Level Agreement Compliance: Automation reduces the risk of missing service level agreements.
- Priority Ordering: The system prioritizes rules, executing the highest priority rule first, preventing subsequent rules from applying to the same finding.
- Approval Process: Exception rules require a two-level approval process, enhancing workflow consistency and traceability.
- Execution on Existing Data: Option to run rules on existing findings from a specified date.
Key Outcomes
Implementing exception rules allows organizations to efficiently manage findings by automating the deferral process, ensuring timely handling of vulnerabilities while maintaining compliance with guidelines. Upon expiry, the rules cease to affect new or reopened findings, simplifying management further.
Exception rules for Security Exposure Management Workspace enable you to automate the deferral process for findings. Request an exception for the findings that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration items (CIs), or VIs. Defer the matching findings based on the rule when the system identifies them by automating the finding deferral process.
Use exception rules to automatically defer new and existing findings for a specific period if they match the approved rule condition. Automation minimizes the risk of missing service level agreements and makes it easier to manage multiple items, because you’re eliminating manual intervention.
Deferral rules support ordering, that is, the rule with the highest priority is run first. When a high-priority rule is applied on a finding, no subsequent rules are applied on it again even if the condition matches the Finding.
- Creating an exception rule
- Approving an exception rule request
- Activating an exception rule
- Deferring an exception rule
- Expiry of an exception rule
You can create an exception rule to automatically defer the findings that match the defined conditions for the specified period. After you create an exception rule, submit it for approval.
- Cancel
- Delete
You can defer findings that match the conditions defined in this exception rule, up to the "Deferred until" date that is defined for the rule. On this date, the remediation task that you created for the exception rule is closed and all the findings in this group move back to the Open state.
After the exception rule expires, it no longer runs on new or reopened findings.