Security Exception and Risk Acceptance Form

Purpose

Use this form when a required cybersecurity control cannot be implemented, must be delayed, or when leadership knowingly accepts a cybersecurity risk.

Exception Information

Exception ID: ____________________

Date requested: ____________________

Requester: ____________________

Department: ____________________

System, process, vendor, or asset affected: ____________________

Requirement Being Excepted

Policy, standard, or control requirement:


Example:

“MFA is required for all administrator accounts.”

Reason for the Exception

Explain why the requirement cannot currently be met:


Examples:

  • Legacy system does not support MFA.

  • Required patch causes application compatibility problems.

  • Vendor does not currently support the required security control.

  • Business-critical system cannot be replaced before a planned project.

Risk Created

Describe what could happen because the normal control is not being used:


Risk Rating

Likelihood:

  • Low / Medium / High

Impact:

  • Low / Medium / High

Overall risk:

  • Low / Medium / High / Critical

Temporary or Compensating Controls

What will reduce the risk while the exception exists?


Examples:

  • Restrict access by IP address
  • Require VPN access
  • Increase logging
  • Review activity manually
  • Use stronger password controls
  • Limit user permissions
  • Increase backup frequency
  • Require additional approval

Exception Owner

Person accountable for the risk:


Expiry or Review Date

Exception start date: ____________________

Review date: ____________________

Expiry date: ____________________

Exceptions should not remain permanent without review.

Permanent Resolution

What must happen to remove the exception?


Owner: ____________________

Target date: ____________________

Approval

Requested by: ____________________

Technical review: ____________________

Risk owner: ____________________

Leadership approval: ____________________

Approval date: ____________________

Closure

Exception resolved:

  • Yes / No

Resolution evidence: ____________________

Closure date: ____________________

Practical Rule

Every security exception should have a reason, a risk owner, temporary protection, and an expiry or review date.