Security Exception and Risk Acceptance Form
Purpose
Use this form when a required cybersecurity control cannot be implemented, must be delayed, or when leadership knowingly accepts a cybersecurity risk.
Exception Information
Exception ID: ____________________
Date requested: ____________________
Requester: ____________________
Department: ____________________
System, process, vendor, or asset affected: ____________________
Requirement Being Excepted
Policy, standard, or control requirement:
Example:
“MFA is required for all administrator accounts.”
Reason for the Exception
Explain why the requirement cannot currently be met:
Examples:
-
Legacy system does not support MFA.
-
Required patch causes application compatibility problems.
-
Vendor does not currently support the required security control.
-
Business-critical system cannot be replaced before a planned project.
Risk Created
Describe what could happen because the normal control is not being used:
Risk Rating
Likelihood:
- Low / Medium / High
Impact:
- Low / Medium / High
Overall risk:
- Low / Medium / High / Critical
Temporary or Compensating Controls
What will reduce the risk while the exception exists?
Examples:
- Restrict access by IP address
- Require VPN access
- Increase logging
- Review activity manually
- Use stronger password controls
- Limit user permissions
- Increase backup frequency
- Require additional approval
Exception Owner
Person accountable for the risk:
Expiry or Review Date
Exception start date: ____________________
Review date: ____________________
Expiry date: ____________________
Exceptions should not remain permanent without review.
Permanent Resolution
What must happen to remove the exception?
Owner: ____________________
Target date: ____________________
Approval
Requested by: ____________________
Technical review: ____________________
Risk owner: ____________________
Leadership approval: ____________________
Approval date: ____________________
Closure
Exception resolved:
- Yes / No
Resolution evidence: ____________________
Closure date: ____________________
Practical Rule
Every security exception should have a reason, a risk owner, temporary protection, and an expiry or review date.