TriageSLA

Vulnerability Exception Approval

Routes a request to accept a finding as a risk to a named approver, with the compensating control attached.

Part of Vulnerability SLA tracking

Tools

Tenable.io, Jira Service Management, Vanta

Outcomes

Every exception has a named approver • Expiry date set on approval • Accepted risk visible to auditors

Documentation

Instruction-ready detail below

When an owner asks to accept a finding, pull the asset owner and the compensating control from <in:jira>the exception request</in:jira>, set an expiry date, and <email>send</email> it to the named approver for a decision.

Instruction file

When an owner asks to accept a finding, pull the asset owner and the compensating control from <in:jira>the exception request</in:jira>, set an expiry date, and <email>send</email> it to the named approver for a decision.

Setup requirements

Tools

Tenable.io, Jira Service Management, Vanta

Trigger

When an owner asks for a finding to be accepted as a risk

Setup time

20 minutes

Download

Start with one instruction file.

Download the app and begin with drafts and checklists before you write anything back.

  • •Plain-language instructions
  • •Runs on your machine
  • •Works with your existing setup
  • •Reviewable activity history
Download