Adding SCAP rule exceptions
Rule exception are similar to deviations, but on a device level, not for a group. An exception is a rule, for which it does not matter, if it succeeds or fails on the target, that is, it's real result does not impact the device compliance. This means, that its scan results are included in the device compliance, the rule appears in the list of executed rules, but its result is always displayed as successful.
Some rules that are included in the benchmarks can be specified as exceptions, because, for example, they are not applicable to a specific operating systems, or a specific rule currently is not applicable for your internal regulations, and so on.
These exceptions can be modified at any moment and can also have a deadline. This means that for example a rule is considered an exception until December 31st, because until then a specific requirement is not applied in your organization, but from the 1st of January onwards it will be. Once the expiration date is reached, the exception is automatically removed and the rule result included in the global compliance.
To specify a rule exception proceed as follows:
- Click Edit > Add SCAP Rule Exception
.
The Select an SCAP Rule dialog box appears. - Select the rule to specify as exception.
- (Optional) Click the calendar
icon, if the rule exception is to expire at a specific date. If the exception is unlimited, do not modify this box.
- Click OK to add it to the list of exceptions and close the window.
The exception is immediately added to the list. Rerun the scan on the device to create an up-to-date result.