Skip to content

Vulnerability Deviation

Quick Summary

Used to formally deviate from standard remediation SLAs on one or more issue tickets. Follows FedRAMP's deviation process with a built-in approval workflow, supporting false positives, operational requirements, and risk adjustments.

The Vulnerability Deviation ticket type is used when an organization needs to formally apply a deviation to one or more issue tickets rather than remediate within the prescribed SLA. Every deviation ticket is associated with at least one parent issue (and can span multiple), creating a traceable link between the finding and the justification for not remediating it on the standard timeline.

Deviation Types

The available deviation types follow FedRAMP's deviation process:

  • False Positive - the finding does not represent an actual vulnerability
  • Operational Requirement - remediation would break a required business function
  • Risk Adjustment - the risk is accepted with compensating controls or other justification
  • Operational Requirement + Risk Adjustment - a combination of both

The fields in the Vulnerability Deviation tab align with FedRAMP's Vulnerability Deviation Request template, capturing the rationale, supporting evidence, and relevant metadata in a format that maps directly to what an authorizing official expects to review.

Approval Workflow

A finalized OR RA deviation showing the four-stage workflow chevron, requested risk rating, adjusted CVSS score, rationale, evidence description, and justification

A key distinction from issue tickets is that deviation tickets carry an approval workflow. The ticket moves through workflow stages, and its status follows the stage:

Workflow stage Status Meaning
New Pending / DR Pending Deviation request submitted, awaiting review
In Review Pending / DR Pending Under evaluation by the Deviation Approvers CAB
Approval Approved / DR Approved or Rejected Deviation granted, or denied (standard remediation SLA applies)
Finalized Closed Deviation lifecycle complete

Deviations also govern compliance-scan exemptions: where a resource is tagged so an automated check reports it as skipped, the deviation is the record of the accepted risk behind that suppression. See Compliance Exemptions for the tagging mechanics.

Approval is by the Deviation Approvers CAB (membership granted by the Approver - Deviations role); the assigned agent tracks the deviation but does not approve it. Where the customer organization has a designated end user with the Deviation Approver role, the request is additionally forwarded to them for organizational sign-off. On approval, the adjusted rating, flags, and status propagate automatically to every covered issue and each issue's remediation clock is re-baselined at the approved tier. See the Vulnerability Detection & Response policy for the full process, including the 192-day accepted-vulnerability boundary.