Exception rules overview
Summarize
Summary of Exception Rules Overview
Exception rules for Vulnerability Response automate the deferral process for vulnerable items (VIs) that cannot be remediated or deferred immediately. These rules allow you to request exceptions by identifying impacted vulnerabilities, configuration items (CIs), or VIs, enabling automated deferral based on established conditions.
Show less
Key Features
- Automation: Automatically defer new and existing VIs for a specified period, reducing the risk of missed service level agreements.
- Priority Ordering: Rules are executed based on priority, with the highest priority rule applied first, preventing subsequent rules from affecting the same VI.
- Lifecycle Management: The lifecycle includes creating, approving, activating, deferring, and expiring exception rules.
- Approval Process: Exception rule approval involves a two-level process, and if approved, generates a remediation task (RT).
- Execution on Existing Data: An option to run the rule on existing data is available starting from the "Valid from" date.
Key Outcomes
By implementing exception rules, organizations can effectively manage VIs, ensuring compliance with service level agreements while reducing manual workload. After an exception rule is activated, it will continue to apply until its expiry, at which point it will cease to affect new or reopened VIs. VIs in the deferral group will revert to an Open state when the remediation task is closed.
Exception rules for Vulnerability Response enable you to automate the deferral process for vulnerable items (VIs). Request an exception for the vulnerable items (VIs) that can't be remediated or deferred immediately, by identifying the impacted vulnerabilities, configuration items (CIs), or VIs. Defer the matching VIs based on the rule when the system identifies them by automating the VI deferral process.
Use exception rules to automatically defer new and existing VIs for a specific period if they match the approved rule condition. Automation minimizes the risk of missing service level agreements and makes it easier to manage multiple items, because you are eliminating manual intervention.
- You can only create rules if you select Vulnerability Response in the Exception Management configuration. For details, see Configure Exception Management for Vulnerability Response.
- When VIs are deferred by an exception rule, they are copied to the deferral vulnerability group (VG) that is created. The VIs continue to be part of the VGs they were part of earlier.
- Creating an exception rule
- Approving an exception rule request
- Activating an exception rule
- Deferring an exception rule
- Expiry of an exception rule
You can create an exception rule to automatically defer the VIs that match the defined conditions for the specified period. After you create an exception rule, submit it for approval.
Approving an exception rule request is a two-level process. If only the first-level approver is present, the exception rule can be assessed and approved by a single approval. However, if there's no first-level approver, an exception rule approval can't be approved. After the rule is approved, a remediation task (RT) is created. See Approve an exception rule request for more information.
Starting from Vulnerability Response v15.0, if you are deploying the VR application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update to the flow designer. In both cases, you cannot change it back to workflow. To configure approval rules for exception management and false positive, see Configure approval rules for Exception Management.
- Cancel
- Delete
You can defer VIs that match the conditions defined in this exception rule, up to the "Deferred until" date that is defined for the rule. On this date, the remediation task that you created for the exception rule is closed and all the VIs in this group move back to the Open state. Group rules are applied on them again to allocate them to the required RTs.
After the exception rule expires, it no longer runs on new or reopened VIs. The associated RT remains in the Deferred state until the "Deferred until" date.