Field notes
Building endpoint exclusions that survive an audit
Endpoint products scan files and processes aggressively by design. Line-of-business applications in South African firms—especially older accounting or manufacturing packages—often need carefully scoped exclusions. The problem is not the exclusion itself; it is the missing record of why it exists.
Keep a register with path or process, owning department, ticket or change reference, review date, and expiry. Review dates matter: temporary exclusions granted during a year-end close should not linger into the next financial year without a fresh decision.
Prefer process-based exclusions over broad folder trees when the vendor supports it. Wide folder exclusions can hide malware dropped into the same directory. When a vendor forces path exclusions, narrow them to the install directory and note the product version tested.
During Policy Alignment Review engagements, we compare the live exclusion list to written change records. Gaps usually appear where a former contractor left, or where a weekend outage forced an undocumented change. Closing those gaps is often a half-day of disciplined cleanup rather than a full redesign.
If your auditor asks for evidence, export the console exclusion list and attach the register side by side. Matching names and dates tell a stronger story than screenshots alone.