Request exception form for risk reduction
The following table shows the fields that you must fill on the Request exception form for risk reduction requests.
| Field | Description |
|---|---|
| Reason | Reason for your exception request. Select Mitigating Control in Place for risk reduction request.To see how to add new reason choices, see Define policy reason mapping. |
| Request for Deferral | Deffer the record. This field is selected by default.Note: This field appears only when the Mitigating Control in Place option is selected in the Reason field. |
| Request for Risk Reduction | Enables you to request for the risk score reduction.Note: This check box appears only when the Mitigating Control in Place option is selected in the Reason field. |
| Current Risk Rating | Current severity of the risk.Note: This field appears only when the Request for Risk Reduction check box is selected. |
| Desired Risk Rating | New risk rating that you want to assign to the record.The highest risk score in this risk rating range is applied to the record when your request is approved. Note: This field appears only when the Request for Risk Reduction check box is selected. |
| Select Compensating Controls | Reason for your request to reduce the risk rating. |
| Until | Date on which the deferral or risk reduction request expires.When the exception request expires: - The record reverts to the Open state. - The compensating controls expire. - The calculated score will be in place of a reduced score. |
| Justification notes | Details that are related to the reason why this request is being made. |
Related topics
Request risk reduction for a vulnerable item or remediation task