Configuration Compliance Exception Management overview
Summarize
Summary of Configuration Compliance Exception Management overview
Configuration Compliance Exception Management allows your organization to request, review, approve, or reject exceptions when it cannot comply with published vulnerability management or security policies, standards, or guidelines. This process specifically addresses remediation tasks that cannot be resolved according to policy, enabling controlled risk acceptance and deferral of remediation efforts.
Show less
Exception management is supported in both the Vulnerability Manager Workspace and the IT Remediation Workspace. Note that terminology has changed starting with Configuration Compliance v14.9 to better align with remediation processes.
Exception Life Cycle
- Requesting an Exception: As the remediation owner, you can request an exception for a remediation task if it cannot be immediately remediated. The task remains "In review" until approval. Exception requests can be initiated from the IT Remediation Workspace.
- Approving an Exception: Exception requests are reviewed and risk-assessed by approvers. Approval workflows can include one or two levels; if no first-level approver exists, requests cannot be made. Approvals and rejections are managed via the Vulnerability Manager Workspace. Post-approval, remediation tasks move to a "Deferred" state. Rejection returns the task to its previous state with comments logged.
- Tracking Exceptions: Exception request status is tracked through the State Change Approvals tab on the remediation task. Note that individual test result statuses within a remediation task cannot be tracked once an action is taken.
- Expiry of Exceptions: When an exception expires, the remediation task automatically reverts to the "Open" state, requiring remediation or a new exception request.
Key Considerations for ServiceNow Customers
- Exception management helps you formally document and approve risk acceptance when immediate remediation is not feasible, maintaining compliance visibility.
- Use the IT Remediation Workspace to request exceptions and the Vulnerability Manager Workspace to approve or reject them, streamlining workflow integration.
- Ensure proper approvers are configured to enable exception requests; otherwise, remediation tasks cannot be deferred.
- Starting with Configuration Compliance v13.0, the flow designer is the default for exception workflows, enhancing customization and automation capabilities.
- Monitor exception expiry closely to avoid unintentional reopening of remediation tasks and maintain compliance posture.
When your organization can't comply with a published vulnerability management or security policy, standard, or guideline, you can request an exception. Exception management entails requesting, reviewing, approving, or rejecting exceptions for a remediation task that cannot be remediated according to the policy.
| Terminology prior to v14.9 | Terminology v14.9 onwards |
|---|---|
| Test Result Group | Remediation Task |
| Group Rules | Remediation Task Rules |
| Policy | Test group |
Some vulnerabilities might not have an existing patch, fix, or solution. When an exception is approved, it also means that you're accepting a risk because you're acknowledging and agreeing to the consequences of not remediating the configuration-related vulnerability.
Life cycle of an exception
An exception is a request to defer the remediation of a remediation task for a specified period.
- Requesting an exception
- Approving an exception request
- Tracking an exception request
- Expiry of an exception request
As the remediation owner, you can ask for an exemption for a remediation task using the exception management process. During the approval process, the remediation task remains in In review state. After the exception approver approves this request, the remediation task moves to a Deferred state.
Starting from Configuration Compliance v13.0, if you are deploying the CC application for the first time, the flow designer for exception management is enabled by default. If you are already using the workflow, you can update to the flow designer. In both cases, you cannot change it back to workflow.
- Reopen
- Delete
After raising the exception, you can track its status by using the State Change Approvals tab of the remediation task. If an action is taken on a remediation task, you can't track the status of the individual test results in that remediation task.
When an exception request for a remediation task expires, the remediation task reverts to its Open state.