Note:
This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.
If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the KB2556844 and documentation before proceeding.
If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.
Exception Management enables organizations to efficiently handle and document vulnerability exceptions. It provides a controlled process for requesting, reviewing, and approving exceptions to vulnerable findings, ensuring transparency and compliance. By automating workflows and capturing exception justifications, it helps reduce operational bottlenecks while maintaining risk visibility and audit readiness.
- Manual and Automated Exception Request and Approval Workflow - Streamline the process of submitting, reviewing, and approving exception requests with customizable workflows that ensure accountability and speed up decision making.
- Comprehensive Exception Tracking and Audit Trails - Maintain full visibility into all exceptions with detailed records of approvals, justifications, and timelines to support compliance and audit readiness.
Fixed:
- Expired False Positives or Exceptions reopen the original remediation task as expected instead of creating a duplicate remediation task.
- Canceling a policy exception reverts the associated vulnerable item back to its original state as expected.
- Fixed issues in the GRC exception flow so manually reopening a vulnerable item automatically cancels the related policy exception, and canceling an approved exception returns the item to an open state as expected.
- False Positive requests are no longer automatically rejected and the Reopen action works for users configured with a non-English language.
- Enhancements to the compensating controls (Mitigating Control in Place) workflow allows the risk rating to be increased, not just reduced.
- Custom exception rule scripts configured in feature settings no longer fail due to a platform scoped-script evaluation restriction.
- No additional system requirements. This update is fully compatible with existing Exception Management and Compensating Controls configurations