Vulnerability Exception Approval
Routes a request to accept a finding as a risk to a named approver, with the compensating control attached.
Part of Vulnerability SLA tracking
Tools
Tenable.io, Jira Service Management, Vanta
Outcomes
Every exception has a named approver • Expiry date set on approval • Accepted risk visible to auditors
Documentation
Instruction-ready detail below
When an owner asks to accept a finding, pull the asset owner and the compensating control from <in:jira>the exception request</in:jira>, set an expiry date, and <email>send</email> it to the named approver for a decision.