Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Security Exception, Waiver & SoD Toolkit — Guide

Security Exception & Segregation of Duties Pack

Every organisation has gaps it cannot close today: a server that cannot be patched, a supplier that cannot use multi-factor sign-in, an administrator who both makes changes and approves them. The danger is the gap nobody wrote down, nobody owns and nobody revisits. This pack gives you the documents to record each gap, decide who may accept it, and make sure it ends.

Is this for you?

This pack is for you if:

  • people ask you to “sign off” a gap and there is no rule for who may;
  • old exceptions sit in email threads with no end date;
  • your team is too small to keep every duty separate, and an auditor has noticed.

Why exceptions and duty conflicts belong together

A segregation of duties (SoD) conflict is one person holding two roles that should be kept apart, such as raising a payment and approving it. If you can separate the roles, do. If you cannot, you are accepting a known gap in a control, and that is an exception.

Both need the same things: a named owner, a compensating control, and an end or review date. So this pack runs them through one standard, one approval route and one register.

Start with these three

  1. Security Exception & Waiver Standard — when an exception may be granted, who approves it and how long it may last.
  2. Request & Approval Form — asks for enough up front that an approver can decide without a meeting.
  3. Security Exception Register — every live exception, with owner, compensating control and expiry date.

Each exception is scored for impact and likelihood, 1 to 4 each, after compensating controls. The score sets who approves and how long it may run:

ScoreBandWho approvesLongest it may run
1–3LowControl owner365 days
4–6MediumHead of Information Security180 days
8–9HighHead of Information Security and the accountable executive90 days
12–16CriticalExecutive management30 days

A four-week plan

WhenWhat to doYou’re done when
Week 1Name your approvers in the Standard. List every exception you already know about.Management has agreed who approves what.
Week 2Put each known exception through the form, score it and register it with an expiry date.Nothing lives only in an email.
Week 3Check who holds which duties in your core systems against the conflict matrix. Separate what you can; record the rest as exceptions.Every High conflict is removed or recorded.
Week 4Hold the first monthly register review and run the dashboard.Management has seen the four numbers below.

Four numbers to report

NumberTarget
Open exceptions by bandTrend down; no unexplained rise in High or Critical
Expired exceptions (past expiry, neither closed nor renewed)Zero High or Critical; below 5% of all open
Chronic exceptions (renewed more than the band allows)Zero; each one reported by name
Unmitigated SoD conflicts (High, with no compensating control reviewed last quarter)Zero

Everything in the pack

DocumentWhat it doesFormat
Security Exception & Waiver StandardThe rules management approvesWord
Exception Lifecycle ProcedureOne exception’s path from request to closureWord
Request & Approval FormEverything an approver needs, on one formWord
Risk Scoring & Expiry ModelTurns “how risky is this?” into a repeatable scoreWord
Security Exception RegisterThe record of every live exceptionExcel
Segregation of Duties Conflict MatrixThe duty combinations that break most often, ready-madeExcel
Conflict Review ProcedureWhat to do when you are too small to separate rolesWord
Responsibility MatrixWho requests, assesses, approves and monitorsExcel
Ageing & Expiry DashboardWhere expired and repeatedly renewed exceptions pile upExcel

Adapting it

  • Small organisation: you will not separate every duty, and that is acceptable if each conflict is recorded and checked. An external reviewer can stand in for internal audit. Review High conflicts quarterly and Medium ones every six months.
  • Regulated entity (NIS2, DORA): DORA’s technical standards expect your policies to record exceptions and set out how duties are separated. The register and conflict matrix are that record; take the dashboard to your management body.
  • IT run by an outside provider: make the provider raise exceptions through your form, and include its administrators in the conflict matrix.

Where it maps

  • ISO/IEC 27001:2022 — Annex A 5.36 and 5.3.
  • NIST CSF 2.0 — GV.PO-02 and PR.AA-05.
  • NIS2 — Article 21(2)(a) and (i).
  • DORA — Article 6(4); Delegated Regulation (EU) 2024/1774, Article 2(2)(c) and (g), and Article 21(b).