Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Exception Ageing & Expiry Dashboard

Shows management the accumulation of deviations over time and the exposure concentrated in expired or repeatedly renewed exceptions.

Available soon

Format
Excel
Size
204 KB
Length
11 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Register Data
  • Metric Definitions
  • Dashboard
  • Trend
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Register Data sheet: in the Security Exception Register, copy the whole register table's data rows (sheet Register, columns A to AP, from row 4 down). Paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order, headings on row 3.
2Do not paste over the grey calculated columns to the right of column AP. If the register has more rows than this table, drag the table's bottom-right corner down first so the calculated columns extend.
3Dates must be real dates, not text. After pasting, check that First start date, Expiry date and Closed date are right-aligned; left-aligned dates are text and are not counted.
4Dashboard sheet: enter the report date — normally the last day of the month being reported. The previous month end is worked out for you. Every figure is recalculated at the report date, not at the register's own as-at date.
5Dashboard sheet: type this month's and last month's 'Unmitigated SoD conflicts' figures from the Summary sheet of the Segregation of Duties Conflict Matrix.
6Read the results. Every figure has a status in words beside it; the colour only repeats what the word says. Add a line of commentary to any figure that moved.
7Name every chronic exception to management (the Dashboard lists up to 10). Each needs a decision: fix it, retire the system, or renew it at the next approval level up (EX-08).
8Every quarter (EX-12), complete 'What to say to management' on the Dashboard and take it, with the Trend sheet, to [[e.g. Executive Committee or its risk committee]]. Keep a copy of the workbook for each report as the record.
9Trend sheet: shows the open exceptions by band for the twelve month ends up to the report date. Use it to show direction; one month on its own rarely tells management much.
10Printing: the Register Data sheet prints only its first rows, so that empty input rows do not print as blank pages. To print all your data, clear or reset the print area on that sheet (Page Layout → Print Area).
11Delete the EXAMPLE rows on the Register Data sheet before you paste your own data, replace the EXAMPLE figures in the yellow cells on the Dashboard, then check that the Dashboard recalculates.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Paste all 42 register columns, A to AP: Example | Exception ID | Exception type | Title | Policy or standard clause not met | System or asset | Requester | Risk owner | Control owner | Impact (1–4) | Likelihood without compensating control (1–4) | Compensating control | Compensating control last tested | Compensating control effective | Likelihood with compensating control | Score | Band | Approver required | Request complete date | Decision | Decided by | Decision date | Decision time (working days) | Decided on time | First start date | Expiry date | Maximum allowed expiry | Expiry check | Renewals | Renewal limit | Renewal check | Closed date | Closure evidence | Status | Days to expiry | Reminder | Working days since expiry | Expired action | Days open in total | Chronic | Record check | Notes.

Columns used in calculations: Exception ID, Title, Band, Decision, First start date, Expiry date, Renewals and Closed date. Only rows whose Decision is Approved are counted, so Requested and Refused rows can stay in the paste. The register's own Status, day counts and Chronic flag are carried across but not used, because they are calculated at its as-at date rather than your report date. If the register's columns change, this sheet's must change to match.

An exception is open at a date when it was approved, its first start date is on or before that date and it has no closed date on or before it. It is expired when it is open and its expiry date is before that date. It is chronic when it is open and its renewals exceed its band's limit (Low 2, Medium 2, High 1, Critical 1; EX-08). How long it has been open shows in the ageing table, not in the chronic count.

Last month's figures are recalculated from this month's register. A renewal since then has already replaced the old expiry date, so an exception that was expired last month and has since been renewed does not show as expired last month. For the figure as it was reported, keep last month's copy of this workbook.

Tailoring — small organisation: with a handful of exceptions, report quarterly and name every open High and Critical exception rather than relying on the counts. Keep the expiry and chronic checks monthly.

Tailoring — regulated entity (NIS2, DORA): exceptions from ICT security policies are recorded and reported (see Framework References). Take this dashboard to the management body at least quarterly, keep each report as a record, and link each exception to the critical or important function it affects in the register's notes.

Tailoring — IT run by a service provider: ask the provider for their open exceptions and waivers against your policies in the register's columns, add them to your register with the provider as control owner, and report them here with your own.

Register Data

Paste the whole Security Exception Register table here as values (columns A–AP, from row 4). Columns AR–BC are calculated at the Dashboard's report date. The 27 EXAMPLE rows show the format — delete them first.

ExampleException IDException typeTitlePolicy or standard clause not metSystem or assetRequesterRisk ownerControl ownerImpact (1–4)Likelihood without compensating control (1–4)Compensating controlCompensating control last testedCompensating control effectiveLikelihood with compensating controlScoreBandApprover requiredRequest complete dateDecisionDecided byDecision dateDecision time (working days)Decided on timeFirst start dateExpiry dateMaximum allowed expiryExpiry checkRenewalsRenewal limitRenewal checkClosed dateClosure evidenceStatusDays to expiryReminderWorking days since expiryExpired actionDays open in totalChronicRecord checkNotesApproved (calc)First start (calc)Expiry (calc)Closed (calc)Renewals (calc)Renewal limit (calc)Open at report date (calc)Days open at report date (calc)Age bucket (calc)Expired at report date (calc)Working days past expiry (calc)Chronic at report date (calc)Chronic no. (calc)
EXAMPLEEX-2024-031Policy or standard requirementDefault administrator passwords on the printer fleetAccess Control Standard — change default passwordsPrinter fleet (AST-044)Facilities ManagerChief Operating OfficerIT Operations Manager13Printers on an isolated network segment; admin pages blocked from user networks20 Oct 2025Yes22LowControl owner29 Oct 2025ApprovedIT Operations Manager3 Nov 20253On time4 Nov 20242 Nov 20263 Nov 2026Within maximum12Within limitOpen63665OKPrinter replacement planned for 202714 Nov 20242 Nov 202612Yes665Over 365 days
EXAMPLEEX-2025-005Policy or standard requirementShared Wi-Fi key in the warehouseNetwork Security Standard — individual wireless authenticationWarehouse wireless networkWarehouse ManagerChief Operating OfficerIT Operations Manager13Key changed quarterly; warehouse network has no route to finance systemsNo33LowControl owner26 Feb 2025ApprovedIT Operations Manager3 Mar 20253On time3 Mar 20252 Mar 20263 Mar 2026Within maximum02Within limit15 Dec 2025Certificate-based Wi-Fi rolled out, change CHG-2210Closed287OK13 Mar 20252 Mar 202615 Dec 202502No
EXAMPLEEX-2025-011Policy or standard requirementLegacy file server without multi-factor authentication for administratorsAccess Control Standard — MFA for privileged accessFile server FS-02IT Operations ManagerFinance DirectorIT Operations Manager23Administrator logons only from the management networkNo36MediumHead of Information Security7 Jan 2026ApprovedHead of Information Security12 Jan 20263On time16 Jun 202510 Jun 202611 Jul 2026Within maximum32Over limitExpired-8258Escalate441ChronicOver renewal limit — refer one level up (EX-08)Migration to the cloud file service slipped three times; the third renewal should have gone one level up (EX-08)116 Jun 202510 Jun 202632Yes441Over 365 daysYes58Renewals over limit1
EXAMPLEEX-2025-014Policy or standard requirementPayroll server on an unsupported operating systemVulnerability Management Standard — supported software onlyPayroll application server (AST-007)Finance Systems LeadFinance DirectorIT Operations Manager33Server isolated; only the payroll team's subnet can reach itNo39HighHead of Information Security and the accountable executive (risk owner)3 Jun 2026ApprovedHead of Information Security; Chief Operating Officer8 Jun 20263On time8 Sep 20255 Sep 20266 Sep 2026Within maximum31Over limitOpen5Reminder due357ChronicOver renewal limit — refer one level up (EX-08)Replacement payroll system go-live moved to March 202718 Sep 20255 Sep 202631Yes357181–365 daysRenewals over limit2
EXAMPLEEX-2025-016Policy or standard requirementDoor-entry controller on the office networkNetwork Security Standard — building systems segregatedDoor-entry controllerFacilities ManagerChief Operating OfficerIT Operations Manager12Firewall rule limits the controller to the vendor's cloud serviceNo22LowControl owner17 Sep 2025ApprovedIT Operations Manager22 Sep 20253On time22 Sep 202521 Sep 202622 Sep 2026Within maximum02Within limitOpen21Reminder due343OK122 Sep 202521 Sep 202602Yes343181–365 days
EXAMPLEEX-2025-018Policy or standard requirementSupplier remote access through a permanent firewall ruleSupplier Access Standard — access enabled only when neededBuilding management systemFacilities ManagerChief Operating OfficerNetwork Engineer22Source address limited to the supplier's office; sessions loggedNo24MediumHead of Information Security1 Apr 2026ApprovedHead of Information Security6 Apr 20263On time6 Oct 202530 Sep 20263 Oct 2026Within maximum12Within limitOpen30Reminder due329OK16 Oct 202530 Sep 202612Yes329181–365 days
EXAMPLEEX-2025-020Policy or standard requirementUnencrypted backup tapes stored off siteCryptography Standard — encrypt backups leaving the siteBackup serviceIT Operations ManagerChief Operating OfficerIT Operations Manager32Tapes carried in locked cases by a vetted courierNo26MediumHead of Information Security15 Oct 2025ApprovedHead of Information Security20 Oct 20253On time20 Oct 202517 Apr 202618 Apr 2026Within maximum02Within limit10 Apr 2026Encrypted cloud backup in use; last tape collection 2026-04-08Closed172OK120 Oct 202517 Apr 202610 Apr 202602No
EXAMPLEEX-2025-022Segregation of duties conflictDeveloper with production deployment rights (SOD-IT-05)Segregation of duties — develop and deployCustomer portalDevelopment LeadChief Operating OfficerDevelopment Lead42Weekly review of deployments by the IT Operations ManagerNo28HighHead of Information Security and the accountable executive (risk owner)27 Jan 2026ApprovedHead of Information Security; Chief Operating Officer30 Jan 20263On time3 Nov 202529 Apr 202630 Apr 2026Within maximum11Within limit28 Apr 2026Deployment moved to the build pipeline with required code reviewClosed176OK13 Nov 202529 Apr 202628 Apr 202611No
EXAMPLEEX-2025-024Policy or standard requirementRemote access appliance flaw awaiting the vendor's fixVulnerability Management Standard — Priority 1 deadlineRemote access gateway (SRV-022)Network EngineerChief ExecutiveNetwork Engineer44Vendor's mitigation applied; access limited to managed devices17 Nov 2025Yes312CriticalThe board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management12 Nov 2025ApprovedExecutive Committee17 Nov 20253On time17 Nov 202517 Dec 202517 Dec 2025Within maximum01Within limit12 Dec 2025Vendor fix installed; rescan clean 2025-12-12Closed25OK117 Nov 202517 Dec 202512 Dec 202501No
EXAMPLEEX-2025-027Policy or standard requirementEnd-of-life database on the finance reporting serverVulnerability Management Standard — supported software onlyFinance reporting server (APP-011)Finance Systems LeadFinance DirectorIT Operations Manager33Database reachable only from the reporting applicationNo39HighHead of Information Security and the accountable executive (risk owner)24 Feb 2026ApprovedHead of Information Security; Chief Operating Officer27 Feb 20263On time1 Dec 202527 May 202628 May 2026Within maximum11Within limitExpired-9668Escalate273Expired — remediate, renew or escalate (EX-10)Expired; renewal beyond the band's limit needs executive management (EX-08)11 Dec 202527 May 202611Yes273181–365 daysYes68
EXAMPLEEX-2026-001Policy or standard requirementShort passwords on shop-floor terminalsPassword Standard — minimum lengthShop-floor terminalsProduction ManagerChief Operating OfficerIT Operations Manager13Terminals on a separate network; badge needed to log onNo33LowControl owner7 Jan 2026ApprovedIT Operations Manager12 Jan 20263On time12 Jan 202611 Jan 202712 Jan 2027Within maximum02Within limitOpen133231OK112 Jan 202611 Jan 202702Yes231181–365 days
EXAMPLEEX-2026-003Policy or standard requirementContractor laptops outside device managementEndpoint Standard — managed devices onlyContractor laptopsProject ManagerChief Operating OfficerIT Operations Manager23Contractors use the virtual desktop only; no local data20 Jan 2026Yes24MediumHead of Information Security21 Jan 2026ApprovedHead of Information Security26 Jan 20263On time26 Jan 202624 Jul 202625 Jul 2026Within maximum02Within limit20 Jul 2026Contract ended; accounts disabled 2026-07-20Closed175OK126 Jan 202624 Jul 202620 Jul 202602No
EXAMPLEEX-2026-005Policy or standard requirementHR system logs not sent to the central log storeLogging Standard — central log collectionHR systemHR Systems LeadHR DirectorIT Operations Manager22Weekly export of the HR system's audit reportNo24MediumHead of Information Security4 Feb 2026ApprovedHead of Information Security9 Feb 20263On time9 Feb 20267 Aug 20268 Aug 2026Within maximum02Within limitExpired-2416Escalate203Expired — remediate, renew or escalate (EX-10)Connector ordered; renewal request not yet made19 Feb 20267 Aug 202602Yes203181–365 daysYes16
EXAMPLEEX-2026-006Segregation of duties conflictOne administrator for the finance system and payment approval (SOD-FI-03)Segregation of duties — administer and transactFinance systemFinancial ControllerFinance DirectorFinancial Controller42Monthly review of administrator activity by the Finance DirectorNo28HighHead of Information Security and the accountable executive (risk owner)19 May 2026ApprovedHead of Information Security; Chief Operating Officer22 May 20263On time23 Feb 202619 Aug 202620 Aug 2026Within maximum11Within limit14 Aug 2026Second administrator trained; payment approval removed from the admin accountClosed172OK123 Feb 202619 Aug 202614 Aug 202611No
EXAMPLEEX-2026-008Policy or standard requirementOld encryption protocol accepted on the intranetCryptography Standard — current TLS onlyIntranetDigital Services ManagerChief Operating OfficerDigital Services Manager12Intranet reachable only from the internal networkNo22LowControl owner4 Mar 2026ApprovedIT Operations Manager9 Mar 20263On time9 Mar 20268 Mar 20279 Mar 2027Within maximum02Within limitOpen189175OK19 Mar 20268 Mar 202702Yes17591–180 days
EXAMPLEEX-2026-009Policy or standard requirementVendor-managed CCTV recorders not patchedVulnerability Management Standard — patch deadlinesCCTV recordersFacilities ManagerChief Operating OfficerFacilities Manager23Recorders on their own network with no internet accessNo36MediumHead of Information Security18 Mar 2026ApprovedHead of Information Security23 Mar 20263On time23 Mar 202618 Sep 202619 Sep 2026Within maximum02Within limitOpen18Reminder due161OK123 Mar 202618 Sep 202602Yes16191–180 days
EXAMPLEEX-2026-011Policy or standard requirementE-mail gateway flaw pending replacementVulnerability Management Standard — Priority 1 deadlineE-mail gatewayIT Operations ManagerChief ExecutiveIT Operations Manager43Attachment types restricted; extra filtering by the providerNo312CriticalThe board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management1 May 2026ApprovedExecutive Committee6 May 20263On time6 Apr 20265 Jun 20265 Jun 2026Within maximum11Within limit1 Jun 2026Replacement gateway live 2026-06-01Closed56OK16 Apr 20265 Jun 20261 Jun 202611No
EXAMPLEEX-2026-012Policy or standard requirementGuest wireless on the corporate network segmentNetwork Security Standard — guest traffic separatedGuest wirelessOffice ManagerChief Operating OfficerNetwork Engineer13Guest network filtered to internet onlyNo33LowControl owner15 Apr 2026ApprovedIT Operations Manager20 Apr 20263On time20 Apr 202617 Oct 202620 Apr 2027Within maximum02Within limitOpen47133OK120 Apr 202617 Oct 202602Yes13391–180 days
EXAMPLEEX-2026-013Segregation of duties conflictIT Operations Manager both creates and approves user access (SOD-IT-01)Segregation of duties — access administrationDirectory serviceIT Operations ManagerFinance DirectorHead of Information Security23Weekly directory change report signed by the Finance Director30 Apr 2026Yes24MediumHead of Information Security29 Apr 2026ApprovedHead of Information Security4 May 20263On time4 May 202631 Oct 202631 Oct 2026Within maximum02Within limitOpen61119OK14 May 202631 Oct 202602Yes11991–180 days
EXAMPLEEX-2026-015Policy or standard requirementRemote access without multi-factor authentication for a board memberAccess Control Standard — MFA for remote accessRemote access serviceCompany SecretaryChief ExecutiveIT Operations Manager33Access limited to one managed laptop; sign-ins reviewed weeklyNo39HighHead of Information Security and the accountable executive (risk owner)11 Aug 2026ApprovedHead of Information Security; Chief Operating Officer14 Aug 20263On time18 May 202611 Nov 202612 Nov 2026Within maximum11Within limitOpen72105OK118 May 202611 Nov 202611Yes10591–180 days
EXAMPLEEX-2026-016Segregation of duties conflictAdministrators can read their own servers' logs (SOD-IT-03)Segregation of duties — administer and review logsWindows serversIT Operations ManagerChief Operating OfficerHead of Information Security32Logs copied to the managed security service's store, which administrators cannot change11 May 2026Yes13LowControl owner13 May 2026ApprovedIT Operations Manager18 May 20263On time18 May 202617 May 202718 May 2027Within maximum02Within limitOpen259105OK118 May 202617 May 202702Yes10591–180 days
EXAMPLEEX-2026-018Policy or standard requirementPlant-floor workstation without endpoint protectionEndpoint Standard — anti-malware on every deviceLine 2 control workstationProduction ManagerChief Operating OfficerProduction Engineer42USB ports blocked; no e-mail or web accessNo28HighHead of Information Security and the accountable executive (risk owner)10 Jun 2026ApprovedHead of Information Security; Chief Operating Officer15 Jun 20263On time15 Jun 202612 Sep 202613 Sep 2026Within maximum01Within limitOpen12Reminder due77OK115 Jun 202612 Sep 202601Yes7731–90 days
EXAMPLEEX-2026-020Policy or standard requirementUSB storage allowed for the design teamEndpoint Standard — removable media blockedDesign team laptopsDesign ManagerChief Operating OfficerIT Operations Manager13Encrypted company USB drives only; use loggedNo33LowControl owner1 Jul 2026ApprovedIT Operations Manager6 Jul 20263On time6 Jul 20261 Jan 20276 Jul 2027Within maximum02Within limitOpen12356OK16 Jul 20261 Jan 202702Yes5631–90 days
EXAMPLEEX-2026-021Policy or standard requirementFirewall management interface exposed pending a firmware updateNetwork Security Standard — management interfaces not internet-facingPerimeter firewall (FW-002)Network EngineerChief ExecutiveNetwork Engineer43Access limited to two source addresses; login alerts to the security serviceNo312CriticalThe board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management5 Aug 2026ApprovedExecutive Committee10 Aug 20263On time10 Aug 20269 Sep 20269 Sep 2026Within maximum01Within limitOpen9Reminder due21OK110 Aug 20269 Sep 202601Yes210–30 days
EXAMPLEEX-2026-019Policy or standard requirementTurn off anti-malware scanning on the build serverEndpoint Standard — anti-malware on every deviceBuild serverDevelopment LeadChief Operating OfficerIT Operations Manager23None proposedNo36MediumHead of Information Security5 Jun 2026RefusedHead of Information Security10 Jun 20263On time02Within limitRefusedOKRefused: exclude the build folders from scanning instead002No
EXAMPLEEX-2026-023Policy or standard requirementPersonal phones on the production wireless networkNetwork Security Standard — managed devices onlyProduction wireless networkProduction ManagerChief Operating OfficerNetwork Engineer13Client isolation on the wireless networkNo33LowControl owner27 Aug 202602Within limitRequestedAwaiting decision (EX-05)Awaiting the risk assessment002No
EXAMPLEEX-2026-022Policy or standard requirementShared mailbox without multi-factor authenticationAccess Control Standard — MFA for all accountsCustomer service mailboxCustomer Service ManagerChief Operating OfficerIT Operations Manager22Sign-in limited to the office networkNo24MediumHead of Information Security19 Aug 2026ApprovedHead of Information Security24 Aug 20263On time24 Aug 202619 Feb 202720 Feb 2027Within maximum02Within limitOpen1727OK124 Aug 202619 Feb 202702Yes70–30 days

Metric Definitions

Metric definitions

The four headline measures the pack reports, defined once so every month is calculated the same way. Change a definition only through a new version of the Security Exception & Waiver Standard.

MeasureDefinitionHow this workbook calculates itTargetHow to read it
Open exceptions by bandLive approved exceptions at month end, by Low, Medium, High and Critical.Approved rows with a first start date on or before the report date and no closed date on or before it, counted by Band.Trend down; no unexplained rise in High or CriticalA steady number can hide a shift upward in band. Read High and Critical on their own; each rise needs a reason in the commentary.
Expired exceptionsExceptions past their expiry date that are neither closed nor renewed, as a share of all open exceptions.Open rows whose expiry date is before the report date. Shown as a count for High and Critical, a count for all bands, and a share of all open exceptions.Zero High or Critical; below 5% overallAn expired exception is a control left off with nobody's current approval. After 10 working days it must have been remediated, renewed or escalated (EX-10).
Chronic exceptionsExceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits.Open rows whose Renewals exceed the band's renewal limit (Low 2, Medium 2, High 1, Critical 1).Zero; each one reported by nameA chronic exception has stopped being temporary. Management decides: fix it, retire the system, or accept it at the next approval level up (EX-08).
Unmitigated SoD conflictsKnown High conflicts with no compensating control recorded and reviewed in the last quarter.Typed in from the Summary sheet of the Segregation of Duties Conflict Matrix; not calculated here.ZeroA High conflict with no working, reviewed compensating control lets one person act and hide it.

Supporting views

ViewDefinitionHow this workbook calculates itTargetHow to read it
AgeingOpen exceptions by how long they have been open, by band.Report date minus first start date, in the buckets 0–30 days, 31–90 days, 91–180 days, 181–365 days, Over 365 days.No target — contextOld exceptions in the High and Critical rows are the ones to ask about.
Expiry positionExpired exceptions by band, those past the grace period, and those due to expire soon.Expired: as above. Past grace: more than 10 working days since expiry. Due: open, not yet expired, expiry within 30, 60, 90 days of the report date.No expired High or CriticalOwners are reminded 30 days before expiry (EX-09); a large 'within 30 days' column is next month's expired count if nobody acts.
TrendOpen exceptions by band at each of the last twelve month ends, with those opened, closed and expired in each month.The open rule above, applied at each month end.Trend downDirection over several months matters more than any single month.

Dashboard

Exception ageing and expiry — dashboard

Yellow cells are yours: the report date, the segregation of duties figures and the commentary. Everything else is calculated at the report date. Each figure has a status in words; the colour only repeats it.

Report settings

SettingValue
Report date (normally a month end)31 Aug 2026EXAMPLE report date — replace with your own
Previous month end31 Jul 2026
Unmitigated SoD conflicts — this month2EXAMPLE — from the Segregation of Duties Conflict Matrix Summary
Unmitigated SoD conflicts — previous month1

Headline measures — this month against last month

MeasureTargetThis monthPrevious monthChangeStatusCommentary — what changed and why
Open exceptions by band — LowTrend down770No change
Open exceptions by band — MediumTrend down65+1Rising
Open exceptions by band — HighNo unexplained rise45-1Falling
Open exceptions by band — CriticalNo unexplained rise10+1Rising — explain
Open exceptions by band — all bandsTrend down1817+1Rising
Expired exceptions — High or Critical0110Action needed
Expired exceptions — all bands—32+1
Expired as a share of all open exceptionsBelow 5%16.7%11.8%+4.9%Above target
Chronic exceptions0220Action needed
Unmitigated SoD conflicts021+1Action needed

Change is this month minus last month; for the share it is in percentage points. Last month is recalculated from this month's data — see the Instructions.

Ageing — open exceptions by time open

Band0–30 days31–90 days91–180 days181–365 daysOver 365 daysTotal open
Low013217
Medium102216
High011204
Critical100001
All bands2266218

Expiry position by band

BandExpiredExpired over 10 working daysOldest expired (days)Due within 30 daysDue within 60 daysDue within 90 days
Low00—123
Medium2282223
High1196223
Critical00—111
All bands33966710

'Due within' counts are cumulative: the 60-day figure includes the 30-day one. Owners are reminded 30 days before expiry (EX-09); expired exceptions are remediated, renewed or escalated within 10 working days (EX-10).

Chronic exceptions — named for management (first 10)

TitleException IDBandDays openRenewalsRenewal limitWhy chronicDecision sought from management
Legacy file server without multi-factor authentication for administratorsEX-2025-011Medium44132Renewals over limit
Payroll server on an unsupported operating systemEX-2025-014High35731Renewals over limit

What to say to management — quarterly report (EX-12)

PointWhat to say
The position in one sentence[[e.g. 18 exceptions are open; one High exception has been expired since May and one Critical exception expires on 9 September.]]
Decisions needed from management[[e.g. Decide by 30 September whether the finance reporting database exception (EX-2025-027) is renewed by executive management or the server is switched off.]]
Chronic exceptions and what we propose for each[[e.g. Payroll server (EX-2025-014): renewed three times; propose funding the replacement project's earlier start.]]
Segregation of duties[[e.g. Two High conflicts have no reviewed compensating control; both will be reviewed by 15 October.]]
What has improved since the last report[[e.g. Three exceptions closed in the quarter, including both segregation of duties exceptions in finance.]]
Prepared by (name, role) and date[[Name, role, YYYY-MM-DD]]

Trend

Trend — twelve month ends to the report date

Open exceptions by band at each month end, with those opened, closed and expired in the month. The bars repeat the numbers beside them. Use the last column to note what happened.

Month endLowMediumHighCriticalTotal openHigh and CriticalOpened in monthClosed in monthExpired at month endDirection (total)Commentary
30 Sep 2025311051200—
31 Oct 2025331071200Rising
30 Nov 2025332193200Rising
31 Dec 2025233083120Falling
31 Jan 20263430103200Rising
28 Feb 20263540124200Rising
31 Mar 20264640144200Rising
30 Apr 20265531144220No change
31 May 20266641175301Rising
30 Jun 20266650175112No change
31 Jul 20267550175112No change
31 Aug 20267641185213Rising

Expired at month end uses each exception's current expiry date, so one renewed late since then no longer shows as expired in the earlier month. Keep each month's copy for the figures as reported.

Lists

BandBandMaxDaysBandRenewalsExceptionTypeDecisionStatusYesNoLevel
Low3652Policy or standard requirementApprovedRequestedYes1
Medium1802Segregation of duties conflictRefusedRefusedNo2
High901Open3
Critical301Expired4

Closed

Definitions

Definitions

TermMeaning in this workbook
ExceptionAn approved, time-limited decision that a security policy or standard requirement will not be met, with a named risk owner, compensating controls and an expiry date (Security Exception & Waiver Standard).
BandLow, Medium, High or Critical, from the exception's score in the Exception Risk Scoring & Expiry Model. The band sets who approves and how long the exception may run: Low up to 365 days, 2 renewals; Medium up to 180 days, 2 renewals; High up to 90 days, 1 renewal; Critical up to 30 days, 1 renewal (EX-05, EX-06, EX-08).
First start dateThe date the exception first came into force. Ageing counts from this date, across renewals.
Expiry dateThe date the current term of the exception ends. After it the exception is expired unless renewed or closed.
RenewalA new approval that extends an exception for another term. Each band allows a set number; a renewal beyond it goes to the next approval level up (EX-08).
OpenAt a given date: approved, first start date on or before it and no closed date on or before it. Requested and refused exceptions are never open.
ExpiredOpen, with an expiry date before the date being reported. Remediate, renew or escalate within the grace period (EX-10).
Grace period10 working days after expiry, within which an expired exception must be remediated, renewed or escalated (EX-10).
ChronicOpen, and renewed more times than its band allows (EX-08). Age alone does not make an exception chronic; the ageing table shows how long each has been open.
Unmitigated SoD conflictKnown High conflicts with no compensating control recorded and reviewed in the last quarter. Taken from the Segregation of Duties Conflict Matrix.
Report dateThe date every figure is calculated at, normally the last day of the month being reported. Set on the Dashboard.
Ageing bucketHow long an open exception has been open at the report date: 0–30 days, 31–90 days, 91–180 days, 181–365 days, Over 365 days.
Risk ownerThe accountable business executive for the affected service, who accepts the exception's remaining risk.
EX-nn, SD-nnRequirement numbers in the Security Exception & Waiver Standard: EX for exceptions, SD for segregation of duties.
(calc)A column or cell the workbook calculates. Do not type or paste over it.
EXAMPLE rowA worked example showing the format. Delete before approval.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationThe workbook as a whole: defined measures, calculated each month
ISO/IEC 27001:2022Clause 9.3 — Management reviewWhat to say to management; quarterly report (EX-12)
ISO/IEC 27001:2022Annex A 5.36 — Compliance with policies, rules and standards for information securityExpired and chronic exceptions: where policies are not being complied with
NIST CSF 2.0GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed”Headline measures, period comparison, Trend
NIST CSF 2.0ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated”Expiry position, chronic exceptions and the decisions sought
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(c)(ii) and (iii) — ICT security policies record exceptions from their implementation and keep resilience assured while exceptions existRegister Data and the Dashboard: exceptions recorded and reported while they exist

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774