Requesting and approving an exception in Application Vulnerability Response
You can request to defer the remediation of an application vulnerable item and a remediation task for a specified period.
For example, as a developer, you can request an exception if a patch is not available for a machine. Approvers who have access can approve requests from other users.
You can also create exception rules and request an exception extension for an exception rule. By default, two-levels of approval is required for deferrals, exception rules, and exception extension requests.
To request or approve an exception, see:
- Request an exception for an application vulnerable item
- Request an exception for application vulnerabilities using GRC: Policy and Compliance Management
- Approve exception rules and exception rule extension requests in Application Vulnerability Response
- Request an extension for an exception rule in Application Vulnerability Response
Note:
Email notifications are sent at every stage of exception management, providing the status and other details of a request. For example, when an exception is requested, the requester receives an email confirming that the request is raised. The approver also receives an email stating that an exception has been requested.
Starting from v21.0 of Application Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the application vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the application vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see Configure approval rules for Exception Management.
- Request an exception for an application vulnerable item
Request an exception for an application vulnerable item that cannot be remediated immediately. For example, as a developer, you can request an exception if a patch is not available for a machine. - Request an exception for application vulnerabilities using GRC: Policy and Compliance Management
Request policy exceptions using the GRC policy exception management capability in the Policy and Compliance Management application from within Application Vulnerability Response. - Request an exception for an application remediation task
Request an exception to defer a application remediation task for a specified period if it can’t be resolved immediately. - Approve exception rules and exception rule extension requests in Application Vulnerability Response
Approve exception requests for application vulnerable items that can't be remediated immediately. You must assess these requests for risk and then approve them for deferral until they can be remediated. - Define policy reason mapping
You can define the reason choices to be available to any user who requests an exception. - Request an extension for an exception rule in Application Vulnerability Response
Request an extension for a deferred exception rule before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request. - Request an extension for a deferred remediation task in Application Vulnerability Response
Request an extension for a deferred remediation task (VUL) before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request. - Request an extension for a deferred application vulnerable item in Application Vulnerability Response
Request an extension for a deferred application vulnerable item before it reaches its deferred until due date. As a remediation owner, you’re no longer required to wait until the deferred due date to make this request.
Parent Topic:Exception Management in Application Vulnerability Response