Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Request exception form fields for policy exceptions

The following table shows the fields that you must fill on the Request exception form for policy exceptions.

FieldDescription
PolicyVulnerability Management policy that you’re requesting an exception for.
Control objectiveControl objectives associated with the policy that you selected. If a policy isn’t selected, all the control objectives are listed.
Valid fromDate when the exception starts. The default value is the current date. This date can't be in the past.
Valid untilDate that the policy exception expires and the state of the vulnerable item or group changes from Deferred to Open.Note: The number of days that the policy exception is valid can't exceed the value in the Maximum exception duration (days) field that you set for the policy. For more information, see Create a policy.
ReasonReason for requesting an exception.
JustificationDetails related to the reason this exception is being requested. This field must be filled in by the remediation owner.

Related topics

Request an exception using GRC: Policy and Compliance Management in the IT Remediation Workspace