1. Feature Summary
Balbix Exception Management provides a structured, centralized capability for documenting and managing decisions not to remediate specific exposures—whether due to business constraints, technical limitations, or alternative risk mitigation. It allows organizations to clearly record these exceptions, define their scope, specify duration, and automatically adjust risk metrics and dashboards to reflect these decisions.
This feature is built to be:
Scalable – Create exceptions in bulk, across thousands of vulnerability instances.
Auditable – Track every exception with flexible filtering and sorting in Exception-focused views.
Policy-Aligned – Apply standard durations, rationales, and mitigation details.
Key Capabilities
Exception support for asset vulnerabilities and AppSec findings
Expiration control: by duration, date, or indefinite.
Role-based access to control who can create, view, and manage exceptions.
Auto-reflecting behavior in dashboards, SLA trackers, risk scores, projects, and exports.
This helps security and compliance teams reduce operational noise, document informed decisions, and streamline reporting.
2. Why Exception Management Matters
In most enterprises, it is not always possible—or even desirable—to fix every vulnerability immediately. Reasons include:
Application compatibility risks
Dependency on external vendors
Required downtime for patching
Presence of compensating controls
Vulnerabilities falling within acceptable SLA windows
Without a structured exception process, these exposures remain in dashboards and reports, leading to:
SLA violations that don’t reflect actual risk posture
Unproductive remediation queues
Frustrated stakeholders who cannot act on "unfixable" items
Balbix Exception Management helps by:
Enabling transparency: Clearly documents why certain vulnerabilities will not be remediated immediately.
Improving focus: Keeps remediation views centered on fixable, high-risk issues.
Supporting audit and compliance: Captures who decided to defer, for how long, and why.
Providing operational clarity: Prevents exception-eligible issues from skewing metrics, risk scores, and SLA charts.
Rather than treating exceptions as gaps in remediation, Balbix treats them as policy-driven decisions that should be recorded, reasoned, and operationalized just like any other part of a cybersecurity workflow.
3. Outcomes Enabled
Business Outcomes
Improved Risk Signal Quality: By removing risk-acknowledged exposures from prioritization dashboards, stakeholders can focus remediation on exposures that truly matter.
Enhanced Auditability: Every exception is logged and exportable, making it easy to respond to audit inquiries or compliance reviews.
Policy Consistency: Centralized configuration ensures that all exceptions follow standardized naming conventions, expiration logic, and evidence documentation guidelines.
Operational Outcomes
Faster Triage: Analysts save hours by bulk-creating exceptions for legacy apps, unsupported systems, or vendor-locked environments.
Cleaner Views: Dashboards and SLA trackers reflect the current state of "remediable" risk only, which improves focus.
Scalable Management: Teams can apply exceptions to thousands of instances in a few clicks.
4. Deep Dive into Feature Mechanics
a. Types of Exceptions Available
In the current version, Balbix supports one scoping model for exceptions:
Scope Type | Behavior |
Static: Selected Vulnerability Instances | This creates an exception for a fixed set of vulnerability instances. No new exposures will be added to this exception later. This is ideal for environments where the exposure footprint is stable or legacy. |
b. Exception Expiration Options
Exceptions in Balbix can be configured to expire in three ways:
Expiration Mode | Description |
After Specified Days | Users define the duration (e.g., 30, 90, 180 days). This is useful for temporary business-impacting issues. |
On Specific Date | Allows alignment with external timelines like vendor patch releases or internal maintenance windows. |
Never Expires | Intended for legacy systems where remediation is permanently deferred, and no risk elimination path exists. |
Upon expiration, the exception automatically transitions to the Inactive state. Associated vulnerabilities are re-introduced into dashboards, risk metrics, SLA tracking, and open remediation queues.
c. Lifecycle of an Exception
Stage | Description |
Active | Exceptions are valid and applied. Affects views, risk, and dashboards. |
Inactive | Exceptions can be either expired or deleted. Exposures are again included in dashboards and SLA calculations. |
Exception status is visible in the Exceptions Table, with detailed filtering and full edit/delete/export capabilities depending on user roles.
Post-Exception Exposure Scoring
When an exception is applied, Balbix recalculates the exposure score for each affected instance to reflect residual risk rather than simply suppressing it. Excepted instances are guaranteed to fall in the Low range. The score is determined by two factors: the inherent impact of compromise for the asset and vulnerability, and the strength of compensating controls or segmentation in place. This preserves prioritization integrity and removes the incentive to use exceptions as a blanket way to erase risk.
Score ranges
Excepted instances resolve to a Low score in the interval 1 to 29. A score of 1 is reserved for cases with effectively perfect risk reduction, for example an air-gapped asset or controls that render exploitation non-viable. Scores above this reflect residual risk when mitigations exist but are not absolute. Excepted instances never compute to Medium or High.
False positive handling
If an exception documents a validated false positive, the instance has no real exposure. Treat these as perfect risk reduction and assign a score of 1. False positives remain fully traceable for audit via exception records and exports, but they do not influence prioritization.
Why not force all excepted instances to 1
Earlier versions set the score to 1 for any exception. Product feedback showed that this incorrectly incentivized exceptioning over remediation and failed to credit real mitigations and segmentation. The current approach guarantees Low while still conveying differences in residual risk. This aligns with how exceptions are intended to adjust risk signals and dashboards without distorting overall posture.
d. Exception Management Page
The Exception Management interface is the centralized control plane for viewing and managing all exceptions across the Balbix platform.
Key Interface Components
Filters: Sort and filter exceptions by Reason, Expiration Date, Requested By, Exposure Score, etc.
Actions: Create, edit or delete exceptions. Export all instances with exceptions via the Asset Vulnerabilities or AppSec Findings tables.
Drilldowns: Click into any exception to see scope details (vulnerabilities, assets, exposure score) and mitigation comments.
RBAC Implications
Users only see exceptions within their authorized asset scope.
Admins have universal visibility and edit rights.
The table behaves similarly to Balbix ticket and project tables, maintaining consistency across modules.
e. Visibility in Tables and Filters
Balbix provides rich visibility and control over how exceptions appear in operational views:
Unique Vulnerabilities Table
Instance-Level Table
Column “Exception” provides binary status per instance.
Filters: Easily include or exclude exceptions via checkbox-style filters (e.g., “Only show non-excepted findings”).
These controls allow teams to:
Track exception impact.
Build dashboards that include or exclude exceptions.
Export exactly what’s needed for reporting or audit purposes.
5. Summary of Capabilities (with Contextual Explanation)
Capability | What It Enables |
Bulk Exception Creation | Users can select multiple vulnerabilities or findings and create a single exception, dramatically reducing manual effort. |
Configurable Expiration | Exceptions can be time-bound or indefinite, aligned to real-world remediation constraints or business decisions. |
Role-Based Access Control (RBAC) | Visibility and actionability are scoped based on the user’s role and asset access, ensuring compliance with enterprise governance. |
Filterable Views | Dashboards, tables, and exports can include or exclude exceptions, offering flexibility in how data is consumed and reported. |
Auto-Expiry Handling | System transitions expired exceptions automatically and reintroduces exposures into the risk flow, reducing manual tracking. |
See Also: