Configuration Compliance Exception Management overview
Summarize
Summary of Configuration Compliance Exception Management overview
Configuration Compliance Exception Management allows organizations to request exceptions when they cannot comply with vulnerability management or security policies. This process includes requesting, reviewing, approving, or rejecting exceptions for remediation tasks that can't be addressed according to established guidelines. Exception management is supported within the Vulnerability Manager Workspace and IT Remediation Workspace.
Show less
With version 14.9, terminology changes include:
- Test Result Group to Remediation Task Group
- Rules to Remediation Task Rules
- Policy Test group to Policy Test Group
When an exception is approved, it indicates an acceptance of risk due to the non-remediation of configuration vulnerabilities.
Key Features
The exception management lifecycle includes:
- Requesting an Exception: Remediation owners can request exemptions for remediation tasks, which remain in the 'In review' state until approved, moving to 'Deferred' once approved.
- Approving an Exception Request: Remediation tasks are assessed for risk and may require a two-level approval workflow. The request can be approved or rejected from the Vulnerability Manager Workspace.
- Tracking an Exception Request: The status of the exception can be monitored through the State Change Approvals tab of the remediation task.
- Expiry of an Exception Request: Once an exception period expires, the remediation task returns to its 'Open' state.
Key Outcomes
ServiceNow customers can expect to effectively manage compliance exceptions, allowing for flexibility in remediation strategies while acknowledging risks. The process ensures clear communication of approval statuses and consequences, enhancing risk management and compliance oversight within the organization.
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions for a remediation task that cannot be remediated according to the policy.
| Terminology prior to v14.9 | Terminology v14.9 onwards |
|---|---|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the configuration-related vulnerability.
Life cycle of an exception
An exception is a request to defer the remediation of a remediation task for a specified period.
- Requesting an exception
- Approving an exception request
- Tracking an exception request
- Expiry of an exception request
As the remediation owner, you can ask for an exemption for a remediation task using the exception management process. During the approval process, the remediation task remains in In review state. After the exception approver approves this request, the remediation task moves to a Deferred state.
Remediation tasks that can't be remediated immediately are reviewed, assessed for risk, and approved for deferral until they can be remediated. Approving an exception request can be a two-level workflow. If only the first-level approver is present, the exception can be requested and approved. However, if there's no first-level approver, an exception can't be requested. See Add an exception approver for Configuration Compliance for more information.
Starting from Configuration Compliance v13.0, if you are deploying the CC application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update to the flow designer. In both cases, you cannot change it back to workflow.
- Reopen
- Delete
After raising the exception, you can track its status by using the State Change Approvals tab of the remediation task. If an action is taken on a remediation task, you can't track the status of the individual test results in that remediation task.
When an exception request for a remediation task expires, the remediation task reverts to its Open state.