---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configuration Compliance Exception Management overview

# Configuration Compliance Exception Management overview {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 min. de leitura

When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or
rejecting exceptions for a remediation task that cannot be remediated according to the policy.  
Importante:  
Exception management is supported in the [Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/zeZkjDsRw1xDAOP6Dba6ug "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.") and [IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/3WMd_BeUdKt3RI4fFzX3mA "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace.").  
Nota:  
Starting with v14.9 of Configuration Compliance, the following terms have been renamed:{#cc-ex-mgmt__entry__2}

| Terminology prior to v14.9 | Terminology v14.9 onwards |
|-|-|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
[Tabela 1. Changes in terminology]

Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the
configuration-related vulnerability.

## Life cycle of an exception {#cc-ex-mgmt__section_ems_dy3_flb}

An exception is a request to defer the remediation of a remediation task for a specified period.  
The life cycle of an exception is as follows:

* Requesting an exception
* Approving an exception request
* Tracking an exception request
* Expiry of an exception request
{#cc-ex-mgmt__ul_mhc_1nn_2nb} Requesting an exception

As the remediation owner, you can ask for an exemption for a remediation task using the exception management process. During the approval process, the remediation task remains in In review state. After the
exception approver approves this request, the remediation task moves to a Deferred state.  
Importante:  
You can request an exception from the IT Remediation Workspace. For more information, see [Request an exception in the IT Remediation Workspace](https://servicenow-prod.fluidtopics.net/3WMd_BeUdKt3RI4fFzX3mA "Request an exception for the host vulnerable item (VIT), application vulnerable item (AVIT), container vulnerable item (CVIT) and remediation task (VUL, AVUL, CVUL, or CRG) from the IT Remediation Workspace."). Approving an exception request  
Remediation tasks that can't be remediated immediately are reviewed, assessed for risk, and approved for deferral until they can be remediated. Approving an exception request can be a two-level workflow. If only the first-level approver is present, the exception can be requested and approved. However, if there's no first-level approver, an exception can't be requested. See [Add an exception approver for Configuration Compliance](https://servicenow-prod.fluidtopics.net/pIG7jlR8Af79OyubciIZzQ "Add users to the approver groups so that you can request an exception for a remediation task in Configuration Compliance.") for more information.  
Importante:  
You can approve or reject an exception request from the Vulnerability Manager Workspace. For more information, see [Request exceptions for remediation tasks and records in the Vulnerability Manager Workspace](https://servicenow-prod.fluidtopics.net/zeZkjDsRw1xDAOP6Dba6ug "From the Vulnerability Manager Workspace, vulnerability managers and analysts can request exceptions and false positives for a remediation task (VUL, AVUL, CVUL or CRG) and record (VIT, CVIT, AVIT or CTR). You can also split a remediation task and create change requests.").  
Nota:  
Starting from Configuration Compliance v13.0, if you are deploying the CC application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update to
the flow designer. In both cases, you cannot change it back to workflow.  
Once an exception request for a remediation task is approved, you can perform the following actions:

* Reopen
* Delete

{#cc-ex-mgmt__ul_h32_y22_4lb}  
Nota:  
Rejection comments are shown in the Work notes for a remediation task. If an exception request is rejected, this remediation task reverts to its previous state. Tracking an exception request

After raising the exception, you can track its status by using the State Change Approvals tab of the remediation task. If an action is taken on a remediation task, you can't track the status of the
individual test results in that remediation task.
Expiry of an exception request

When an exception request for a remediation task expires, the remediation task reverts to its Open state.
Figura 1. Exception management approval process prior to CC v13.0

