Requesting and approving an exception in Container Vulnerability Response
-
- UpdatedAug 3, 2023
- 2 minutes to read
- Vancouver
- Security Operations
You can request to defer the remediation of a container vulnerable item (CVIT) for a specified period. For example, as a developer, you can request an exception if a patch is not available for a machine. Approvers who have access can approve requests from other users.
To request or approve an exception, see:
- Request an exception for a container vulnerable item
- Request an exception for container vulnerabilities using GRC: Policy and Compliance Management
Email notifications are sent at every stage of exception management, providing the status and other details of a request. For example, when an exception is requested, the requester receives an email confirming that the request is raised. The approver also receives an email stating that an exception has been requested. Starting from v2.5 of Container Vulnerability Response, you can configure the time frames for approving false positives and exceptions, along with email notifications for both the approver and requester after a set number of days. When a request is raised, the container vulnerable item changes to In-Review status and a state change record is created. If the approver doesn't respond within the configured time frame, the container vulnerable item or remediation task reverts to Open status. The previous state is stored in the backup_state field. For more information, see Configure approval rules for Exception Management.