Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Security Deck
    • All guides
      • Overview
      • View control and violation rules
      • Performing security compliance checks
      • Managing exceptions to control rules
  • Pricing policy
  • Audit Trails events
  • Release notes

In this article:

  • Viewing a list of exceptions
  • Creating an exception
  • Deleting an exception
  1. Step-by-step guides
  2. Cloud Security Posture Management (CSPM)
  3. Managing exceptions to control rules

Managing exceptions to the CSPM module's security control rules

Written by
Yandex Cloud
Updated at February 26, 2026
  • Viewing a list of exceptions
  • Creating an exception
  • Deleting an exception

Note

This feature is at the Preview stage.

The CSPM module's security control rules are used in the Security Deck workspaces. If you have no workspaces yet, create one.

Exceptions to the CSPM module's security control rules allow you to flexibly configure when and for which objects the results of a rule check should be ignored.

Viewing a list of exceptionsViewing a list of exceptions

To view the list of exceptions from the CSPM module's security control rules applicable to the workspace:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select Control rules.

  3. At the top of the window, select the workspace for which you want to view the info on control rule exceptions.

  4. On the Security control rules page that opens, go to the Exceptions tab.

    The list of exceptions for the CSPM module rules is provided under Configuration control and contains the following fields:

    • Exception reason: User-specified exception reason when creating the exception.

    • Exception type: Action option for the exception you are creating:

      • Resource scanned: If the conditions specified in the exception are met, the resource will generate only rule compliance signals.
      • Do not scan resource: If the conditions specified in the exception are met, the resource will not generate any signals, neither on compliance nor on violation.
    • Rules: Number of rules for which compliance checking is excluded. To view a detailed list of excluded rules, click the line with the exception.

    • Created: Information about the user who created the exception, as well as the date and time of creation.

Creating an exceptionCreating an exception

To create a new exception for the CSPM module's security control rules:

Security Deck UI
  1. Go to Yandex Security Deck.

  2. In the left-hand panel, select Control rules.

  3. At the top of the window, select the workspace in which you want to create an exception from the control rules.

  4. On the Security control rules page that opens, go to the Exceptions tab.

  5. In the top-right corner, click Create exception and select Configuration controls. In the window that opens:

    1. Under Exception type, select an action option for the exception you are creating:

      • Resource has been checked manually: If the exception conditions are met, the resource will only generate signals about rule compliance.
      • Do not scan resource: If the exception conditions are met, the resource will generate no signals at all, neither about compliance nor violation.
    2. Under Scope of control, specify the resources you want to exclude when checking the CSPM module rules:

      • All resources: To exclude all resources controlled in the workspace.

      • Resources selected: To exclude only some resources. To select resources excluded from the check:

        • Click Select resources.
        • In the window that opens, select the resources to exclude from the rule and click Apply.
    3. Under Excepted rules, select the CSPM module rules for which the selected resources should not be checked:

      • All rules: To exclude the selected resources from the check for compliance with all the CSPM module rules.

      • Selected rules: To exclude checks for compliance with a given set of rules. To select rules whose compliance checks will be disabled based on the exception you are creating:

        • Click Select rules.
        • In the window that opens, select the rules you want to exclude from compliance checks. If required, use the filter or search at the top of the window.
        • Click Save selection.
    4. Under Reason for exclusion, give in any format the reason why you are creating an exception.

    5. Click Create exception.

After the next infrastructure check is completed, the new exception will be displayed on the Security control rules page, on the Exceptions tab, under Configuration control. The frequency of checks is 8 hours.

Deleting an exceptionDeleting an exception

To delete an exception for the CSPM module's security control rules:

Security Deck UI
  1. Go to Yandex Security Deck.
  2. In the left-hand panel, select Control rules.
  3. At the top of the window, select the workspace in which you want to delete an exception from the control rules.
  4. On the Security control rules page that opens, go to the Exceptions tab.
  5. Under Configuration control, in the row with the exception you want to delete, click and select Delete.

This exception will be deleted from the environment, and the limitations it placed on rule compliance checks will be canceled after the next infrastructure scan is completed. The frequency of checks is 8 hours.

See alsoSee also

  • Viewing CSPM security control rules and related violations
  • Cloud Security Posture Management (CSPM)
  • Security Deck workspaces

Was the article helpful?

Previous
Performing security compliance checks
Next
Overview
© 2026 Direct Cursus Technology L.L.C.