1. Feature Summary
Balbix Exception Management provides a structured, centralized capability for documenting and managing decisions not to remediate specific exposures—whether due to business constraints, technical limitations, or alternative risk mitigation. It allows organizations to clearly record these exceptions, define their scope, specify duration, attach evidence, and automatically adjust risk metrics and dashboards to reflect these decisions.
This feature is built to be:
Scalable – Create exceptions in bulk, even across millions of vulnerability instances.
Flexible – Support both static (fixed) and continuous (auto-updating) exceptions.
Auditable – Track every change, approval, and deletion with rich logs and exports.
Policy-Aligned – Apply standard durations, rationales, and mitigation details.
Key Capabilities
Exception support for asset vulnerabilities, AppSec findings, user risks, and control gaps.
Multiple scope options: static or dynamic based on unique vulnerabilities or filter criteria.
Expiration control: by duration, date, or indefinite.
Role-based access to control who can create, view, and manage exceptions.
Auto-reflecting behavior in dashboards, SLA trackers, risk scores, projects, and exports.
This helps security and compliance teams reduce operational noise, document informed decisions, and streamline reporting.
2. Why Exception Management Matters
In most enterprises, it is not always possible—or even desirable—to fix every vulnerability immediately. Reasons include:
Application compatibility risks
Dependency on external vendors
Required downtime for patching
Presence of compensating controls
Vulnerabilities falling within acceptable SLA windows
Without a structured exception process, these exposures remain in dashboards and reports, leading to:
SLA violations that don’t reflect actual risk posture
Unproductive remediation queues
Frustrated stakeholders who cannot act on "unfixable" items
Balbix Exception Management helps by:
Enabling transparency: Clearly documents why certain vulnerabilities will not be remediated immediately.
Improving focus: Keeps remediation views centered on fixable, high-risk issues.
Supporting audit and compliance: Captures who decided to defer, for how long, and why—along with supporting evidence.
Providing operational clarity: Prevents exception-eligible issues from skewing metrics, risk scores, and SLA charts.
Rather than treating exceptions as gaps in remediation, Balbix treats them as policy-driven decisions that should be recorded, reasoned, and operationalized just like any other part of a cybersecurity workflow.
3. Outcomes Enabled
Business Outcomes
Improved Risk Signal Quality: By removing risk-acknowledged exposures from prioritization dashboards, stakeholders can focus remediation on exposures that truly matter.
Enhanced Auditability: Every exception is logged and exportable, making it easy to respond to audit inquiries or compliance reviews.
Policy Consistency: Centralized configuration ensures that all exceptions follow standardized naming conventions, expiration logic, and evidence documentation guidelines.
Operational Outcomes
Faster Triage: Analysts save hours by bulk-creating exceptions for legacy apps, unsupported systems, or vendor-locked environments.
Cleaner Views: Dashboards and SLA trackers reflect the current state of "remediable" risk only, which improves focus.
Scalable Management: Teams can apply exceptions to thousands or even millions of instances in a few clicks, with automatic inclusion of future instances via continuous scope.
4. Deep Dive into Feature Mechanics
a. Types of Exceptions Available
Balbix supports three scoping models for exceptions, each suited to different operational needs:
Scope Type | Behavior |
Static: Selected Vulnerability Instances | This creates an exception for a fixed set of vulnerability instances. No new exposures will be added to this exception later. This is ideal for environments where the exposure footprint is stable or legacy. |
Continuous: Selected Unique Vulnerabilities | This option automatically includes any future instances of the same vulnerability (e.g., CVE-2023-5436) across the same asset scope. This reduces repetitive exception creation and ensures newly discovered matches are handled automatically. |
Continuous: Matching Filter Criteria | This captures any future findings that match a saved filter, such as OS version, software name, or other exposure traits. It is ideal for managing exceptions dynamically based on patterns, not specific IDs. |
These options offer flexibility between precision and automation, allowing security teams to match the exception model to their environment.
b. Exception Expiration Options
Exceptions in Balbix can be configured to expire in three ways:
Expiration Mode | Description |
After Specified Days | Users define the duration (e.g., 30, 90, 180 days). This is useful for temporary business-impacting issues. |
On Specific Date | Allows alignment with external timelines like vendor patch releases or internal maintenance windows. |
Never Expires | Intended for legacy systems where remediation is permanently deferred, and no risk elimination path exists. |
Upon expiration, the exception automatically transitions to the Inactive state. Associated vulnerabilities are re-introduced into dashboards, risk metrics, SLA tracking, and open remediation queues.
c. Lifecycle of an Exception
Stage | Description |
Active | Exceptions are valid and applied. Affects views, risk, and dashboards. |
Pending | Placeholder for future phases (e.g., when approval workflows are implemented). Currently not used in Phase 1. |
Inactive | Exceptions are expired, denied, or deleted. Exposures are again included in dashboards and SLA calculations. |
Exception status is visible in the Exceptions Table, with detailed filtering and full edit/delete/export capabilities depending on user roles.
d. Exception Management Page
The Exception Management interface is the centralized control plane for viewing and managing all exceptions across the Balbix platform.
Key Interface Components
Tabs: Switch between Active, Inactive, and (future) Pending exceptions.
Filters: Sort and filter exceptions by Reason, Expiration Date, Requested By, Exposure Score, etc.
Actions: Create, edit, delete, or export exceptions.
Drilldowns: Click into any exception to see scope details (vulnerabilities, assets, exposure score), mitigation comments, and any attached files.
RBAC Implications
Users only see exceptions within their authorized asset scope.
Admins have universal visibility and edit rights.
The table behaves similarly to Balbix ticket and project tables, maintaining consistency across modules.
e. Visibility in Tables and Filters
Balbix provides rich visibility and control over how exceptions appear in operational views:
Unique Vulnerabilities Table:
A column named Exception Instance Count shows how many instances are covered by exceptions.
Instance-Level Table:
Column Has Exception provides binary status per instance.
Filters: Easily include or exclude exceptions via checkbox-style filters (e.g., “Only show non-excepted findings”).
These controls allow teams to:
Track exception impact.
Build dashboards that include or exclude exceptions.
Export exactly what’s needed for reporting or audit purposes.
5. Summary of Capabilities (with Contextual Explanation)
Capability | What It Enables |
Bulk Exception Creation | Users can select multiple vulnerabilities or findings and create a single exception, dramatically reducing manual effort. |
Static and Continuous Scope Options | Organizations can choose how exceptions behave over time—either fixed at creation or dynamically including new matches. |
Configurable Expiration | Exceptions can be time-bound or indefinite, aligned to real-world remediation constraints or business decisions. |
Role-Based Access Control (RBAC) | Visibility and actionability are scoped based on the user’s role and asset access, ensuring compliance with enterprise governance. |
File Attachments | Evidence (e.g., patch testing results, compensating controls) can be attached, with support for large documents (up to 1GB total). |
Export Support | Complete exception metadata can be exported for reporting, audit, and collaboration across teams. |
Audit Logs | Every exception event—create, edit, delete, export—is logged with timestamps and user IDs for traceability. |
Filterable Views | Dashboards, tables, and exports can include or exclude exceptions, offering flexibility in how data is consumed and reported. |
Auto-Expiry Handling | System transitions expired exceptions automatically and reintroduces exposures into the risk flow, reducing manual tracking. |
See Also: