📔 Definition:
An exemption is a temporary request or not to respect a security control.
Creation of an exemption
Exemptions > Add a register > Add an exemption
Creation fields
Name: Name of your exemption.
Perimeter: on which perimeter your exemption applies.
Date: Start and end date.
Status: the status of a derogation may be :
Requested - not yet reviewed/ granted
Rejected - rejected as is, can be resubmitted after modification
Granted - effective (deadline potentially exceeded)
Closed - closed explicitly.
Owner: Applicant for exemption.
🔎The owner may be someone who does not have a Tenacy account. To do this, select "external".
Approver: Person making the decision on the exemption.
Criticality: It is possible to have a simple scale or a AICP scale.
If you want to change the default setting, go to ⚙️Wheel > Preferences > Incident.impact_mode
Attach an exemption to a control
You can link your exemption to the controls of your policies that are affected by those exemptions.
In your exemption > "Controls" tab > Select the control to add.





