Skip to content

Vulnerability Deviation

Quick Summary

Used to formally deviate from standard remediation SLAs on one or more issue tickets. Follows FedRAMP's deviation process with a built-in approval workflow, supporting false positives, operational requirements, and risk adjustments.

The Vulnerability Deviation ticket type is used when an organization needs to formally apply a deviation to one or more issue tickets rather than remediate within the prescribed SLA. Every deviation ticket is associated with at least one parent issue (and can span multiple), creating a traceable link between the finding and the justification for not remediating it on the standard timeline.

Deviation Types

The available deviation types follow FedRAMP's deviation process:

  • False Positive - the finding does not represent an actual vulnerability
  • Operational Requirement - remediation would break a required business function
  • Risk Adjustment - the risk is accepted with compensating controls or other justification
  • Operational Requirement + Risk Adjustment - a combination of both

The fields in the Vulnerability Deviation tab align with FedRAMP's Vulnerability Deviation Request template, capturing the rationale, supporting evidence, and relevant metadata in a format that maps directly to what an authorizing official expects to review.

Approval Workflow

A finalized OR RA deviation showing the four-stage workflow chevron, requested risk rating, adjusted CVSS score, rationale, evidence description, and justification

A key distinction from issue tickets is that deviation tickets carry an approval workflow. The ticket moves through workflow stages, and its status follows the stage:

Workflow stage Status Meaning
New Pending / DR Pending Deviation request submitted, awaiting review
In Review Pending / DR Pending Under evaluation by the Deviation Approvers CAB
Approval Approved / DR Approved or Rejected Deviation granted, or denied (standard remediation SLA applies)
Finalized Closed Deviation lifecycle complete

Approval is by the Deviation Approvers CAB (membership granted by the Approver - Deviations role); the assigned agent tracks the deviation but does not approve it. Where the customer organization has a designated end user with the Deviation Approver role, the request is additionally forwarded to them for organizational sign-off. On approval, the adjusted rating, flags, and status propagate automatically to every covered issue and each issue's remediation clock is re-baselined at the approved tier. See the Vulnerability Detection & Response policy for the full process, including the 192-day accepted-vulnerability boundary.