Vulnerability Deviation¶
Quick Summary
Used to formally deviate from standard remediation SLAs on one or more issue tickets. Follows FedRAMP's deviation process with a built-in approval workflow, supporting false positives, operational requirements, and risk adjustments.
The Vulnerability Deviation ticket type is used when an organization needs to formally apply a deviation to one or more issue tickets rather than remediate within the prescribed SLA. Every deviation ticket is associated with at least one parent issue (and can span multiple), creating a traceable link between the finding and the justification for not remediating it on the standard timeline.
Deviation Types¶
The available deviation types follow FedRAMP's deviation process:
- False Positive - the finding does not represent an actual vulnerability
- Operational Requirement - remediation would break a required business function
- Risk Adjustment - the risk is accepted with compensating controls or other justification
- Operational Requirement + Risk Adjustment - a combination of both
The fields in the Vulnerability Deviation tab align with FedRAMP's Vulnerability Deviation Request template, capturing the rationale, supporting evidence, and relevant metadata in a format that maps directly to what an authorizing official expects to review.
Approval Workflow¶
A key distinction from issue tickets is that deviation tickets carry an approval workflow. The ticket moves through workflow stages, and its status follows the stage:
| Workflow stage | Status | Meaning |
|---|---|---|
| New | Pending / DR Pending | Deviation request submitted, awaiting review |
| In Review | Pending / DR Pending | Under evaluation by the Deviation Approvers CAB |
| Approval | Approved / DR Approved or Rejected | Deviation granted, or denied (standard remediation SLA applies) |
| Finalized | Closed | Deviation lifecycle complete |
Approval is by the Deviation Approvers CAB (membership granted by the Approver - Deviations role); the assigned agent tracks the deviation but does not approve it. Where the customer organization has a designated end user with the Deviation Approver role, the request is additionally forwarded to them for organizational sign-off. On approval, the adjusted rating, flags, and status propagate automatically to every covered issue and each issue's remediation clock is re-baselined at the approved tier. See the Vulnerability Detection & Response policy for the full process, including the 192-day accepted-vulnerability boundary.
