## Purpose

Use this form when a required cybersecurity control cannot be implemented, must be delayed, or when leadership knowingly accepts a cybersecurity risk.

## Exception Information

Exception ID: ____________________

Date requested: ____________________

Requester: ____________________

Department: ____________________

System, process, vendor, or asset affected: ____________________

## Requirement Being Excepted

Policy, standard, or control requirement:

---

Example:

“MFA is required for all administrator accounts.”

## Reason for the Exception

Explain why the requirement cannot currently be met:

---

Examples:

- Legacy system does not support MFA.

- Required patch causes application compatibility problems.

- Vendor does not currently support the required security control.

- Business-critical system cannot be replaced before a planned project.

## Risk Created

Describe what could happen because the normal control is not being used:

---

## Risk Rating

**Likelihood:**

- Low / Medium / High

**Impact:**

- Low / Medium / High

**Overall risk:**

- Low / Medium / High / Critical

## Temporary or Compensating Controls

What will reduce the risk while the exception exists?

---

**Examples:**

- Restrict access by IP address
- Require VPN access
- Increase logging
- Review activity manually
- Use stronger password controls
- Limit user permissions
- Increase backup frequency
- Require additional approval

## Exception Owner

Person accountable for the risk:

---

## Expiry or Review Date

Exception start date: ____________________

Review date: ____________________

Expiry date: ____________________

Exceptions should not remain permanent without review.

## Permanent Resolution

What must happen to remove the exception?

---

Owner: ____________________

Target date: ____________________

## Approval

Requested by: ____________________

Technical review: ____________________

Risk owner: ____________________

Leadership approval: ____________________

Approval date: ____________________

## Closure

**Exception resolved:** 

- Yes / No

Resolution evidence: ____________________

Closure date: ____________________

## Practical Rule

Every security exception should have a reason, a risk owner, temporary protection, and an expiry or review date.
