Exception Ageing & Expiry Dashboard
Shows management the accumulation of deviations over time and the exposure concentrated in expired or repeatedly renewed exceptions.
Available soon
- Format
- Excel
- Size
- 204 KB
- Length
- 11 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Register Data
- Metric Definitions
- Dashboard
- Trend
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Register Data sheet: in the Security Exception Register, copy the whole register table's data rows (sheet Register, columns A to AP, from row 4 down). Paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order, headings on row 3. |
| 2 | Do not paste over the grey calculated columns to the right of column AP. If the register has more rows than this table, drag the table's bottom-right corner down first so the calculated columns extend. |
| 3 | Dates must be real dates, not text. After pasting, check that First start date, Expiry date and Closed date are right-aligned; left-aligned dates are text and are not counted. |
| 4 | Dashboard sheet: enter the report date — normally the last day of the month being reported. The previous month end is worked out for you. Every figure is recalculated at the report date, not at the register's own as-at date. |
| 5 | Dashboard sheet: type this month's and last month's 'Unmitigated SoD conflicts' figures from the Summary sheet of the Segregation of Duties Conflict Matrix. |
| 6 | Read the results. Every figure has a status in words beside it; the colour only repeats what the word says. Add a line of commentary to any figure that moved. |
| 7 | Name every chronic exception to management (the Dashboard lists up to 10). Each needs a decision: fix it, retire the system, or renew it at the next approval level up (EX-08). |
| 8 | Every quarter (EX-12), complete 'What to say to management' on the Dashboard and take it, with the Trend sheet, to [[e.g. Executive Committee or its risk committee]]. Keep a copy of the workbook for each report as the record. |
| 9 | Trend sheet: shows the open exceptions by band for the twelve month ends up to the report date. Use it to show direction; one month on its own rarely tells management much. |
| 10 | Printing: the Register Data sheet prints only its first rows, so that empty input rows do not print as blank pages. To print all your data, clear or reset the print area on that sheet (Page Layout → Print Area). |
| 11 | Delete the EXAMPLE rows on the Register Data sheet before you paste your own data, replace the EXAMPLE figures in the yellow cells on the Dashboard, then check that the Dashboard recalculates. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Paste all 42 register columns, A to AP: Example | Exception ID | Exception type | Title | Policy or standard clause not met | System or asset | Requester | Risk owner | Control owner | Impact (1–4) | Likelihood without compensating control (1–4) | Compensating control | Compensating control last tested | Compensating control effective | Likelihood with compensating control | Score | Band | Approver required | Request complete date | Decision | Decided by | Decision date | Decision time (working days) | Decided on time | First start date | Expiry date | Maximum allowed expiry | Expiry check | Renewals | Renewal limit | Renewal check | Closed date | Closure evidence | Status | Days to expiry | Reminder | Working days since expiry | Expired action | Days open in total | Chronic | Record check | Notes.
Columns used in calculations: Exception ID, Title, Band, Decision, First start date, Expiry date, Renewals and Closed date. Only rows whose Decision is Approved are counted, so Requested and Refused rows can stay in the paste. The register's own Status, day counts and Chronic flag are carried across but not used, because they are calculated at its as-at date rather than your report date. If the register's columns change, this sheet's must change to match.
An exception is open at a date when it was approved, its first start date is on or before that date and it has no closed date on or before it. It is expired when it is open and its expiry date is before that date. It is chronic when it is open and its renewals exceed its band's limit (Low 2, Medium 2, High 1, Critical 1; EX-08). How long it has been open shows in the ageing table, not in the chronic count.
Last month's figures are recalculated from this month's register. A renewal since then has already replaced the old expiry date, so an exception that was expired last month and has since been renewed does not show as expired last month. For the figure as it was reported, keep last month's copy of this workbook.
Tailoring — small organisation: with a handful of exceptions, report quarterly and name every open High and Critical exception rather than relying on the counts. Keep the expiry and chronic checks monthly.
Tailoring — regulated entity (NIS2, DORA): exceptions from ICT security policies are recorded and reported (see Framework References). Take this dashboard to the management body at least quarterly, keep each report as a record, and link each exception to the critical or important function it affects in the register's notes.
Tailoring — IT run by a service provider: ask the provider for their open exceptions and waivers against your policies in the register's columns, add them to your register with the provider as control owner, and report them here with your own.
Register Data
Paste the whole Security Exception Register table here as values (columns A–AP, from row 4). Columns AR–BC are calculated at the Dashboard's report date. The 27 EXAMPLE rows show the format — delete them first.
| Example | Exception ID | Exception type | Title | Policy or standard clause not met | System or asset | Requester | Risk owner | Control owner | Impact (1–4) | Likelihood without compensating control (1–4) | Compensating control | Compensating control last tested | Compensating control effective | Likelihood with compensating control | Score | Band | Approver required | Request complete date | Decision | Decided by | Decision date | Decision time (working days) | Decided on time | First start date | Expiry date | Maximum allowed expiry | Expiry check | Renewals | Renewal limit | Renewal check | Closed date | Closure evidence | Status | Days to expiry | Reminder | Working days since expiry | Expired action | Days open in total | Chronic | Record check | Notes | Approved (calc) | First start (calc) | Expiry (calc) | Closed (calc) | Renewals (calc) | Renewal limit (calc) | Open at report date (calc) | Days open at report date (calc) | Age bucket (calc) | Expired at report date (calc) | Working days past expiry (calc) | Chronic at report date (calc) | Chronic no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | EX-2024-031 | Policy or standard requirement | Default administrator passwords on the printer fleet | Access Control Standard — change default passwords | Printer fleet (AST-044) | Facilities Manager | Chief Operating Officer | IT Operations Manager | 1 | 3 | Printers on an isolated network segment; admin pages blocked from user networks | 20 Oct 2025 | Yes | 2 | 2 | Low | Control owner | 29 Oct 2025 | Approved | IT Operations Manager | 3 Nov 2025 | 3 | On time | 4 Nov 2024 | 2 Nov 2026 | 3 Nov 2026 | Within maximum | 1 | 2 | Within limit | Open | 63 | 665 | OK | Printer replacement planned for 2027 | 1 | 4 Nov 2024 | 2 Nov 2026 | 1 | 2 | Yes | 665 | Over 365 days | |||||||||||
| EXAMPLE | EX-2025-005 | Policy or standard requirement | Shared Wi-Fi key in the warehouse | Network Security Standard — individual wireless authentication | Warehouse wireless network | Warehouse Manager | Chief Operating Officer | IT Operations Manager | 1 | 3 | Key changed quarterly; warehouse network has no route to finance systems | No | 3 | 3 | Low | Control owner | 26 Feb 2025 | Approved | IT Operations Manager | 3 Mar 2025 | 3 | On time | 3 Mar 2025 | 2 Mar 2026 | 3 Mar 2026 | Within maximum | 0 | 2 | Within limit | 15 Dec 2025 | Certificate-based Wi-Fi rolled out, change CHG-2210 | Closed | 287 | OK | 1 | 3 Mar 2025 | 2 Mar 2026 | 15 Dec 2025 | 0 | 2 | No | |||||||||||||
| EXAMPLE | EX-2025-011 | Policy or standard requirement | Legacy file server without multi-factor authentication for administrators | Access Control Standard — MFA for privileged access | File server FS-02 | IT Operations Manager | Finance Director | IT Operations Manager | 2 | 3 | Administrator logons only from the management network | No | 3 | 6 | Medium | Head of Information Security | 7 Jan 2026 | Approved | Head of Information Security | 12 Jan 2026 | 3 | On time | 16 Jun 2025 | 10 Jun 2026 | 11 Jul 2026 | Within maximum | 3 | 2 | Over limit | Expired | -82 | 58 | Escalate | 441 | Chronic | Over renewal limit — refer one level up (EX-08) | Migration to the cloud file service slipped three times; the third renewal should have gone one level up (EX-08) | 1 | 16 Jun 2025 | 10 Jun 2026 | 3 | 2 | Yes | 441 | Over 365 days | Yes | 58 | Renewals over limit | 1 | |||||
| EXAMPLE | EX-2025-014 | Policy or standard requirement | Payroll server on an unsupported operating system | Vulnerability Management Standard — supported software only | Payroll application server (AST-007) | Finance Systems Lead | Finance Director | IT Operations Manager | 3 | 3 | Server isolated; only the payroll team's subnet can reach it | No | 3 | 9 | High | Head of Information Security and the accountable executive (risk owner) | 3 Jun 2026 | Approved | Head of Information Security; Chief Operating Officer | 8 Jun 2026 | 3 | On time | 8 Sep 2025 | 5 Sep 2026 | 6 Sep 2026 | Within maximum | 3 | 1 | Over limit | Open | 5 | Reminder due | 357 | Chronic | Over renewal limit — refer one level up (EX-08) | Replacement payroll system go-live moved to March 2027 | 1 | 8 Sep 2025 | 5 Sep 2026 | 3 | 1 | Yes | 357 | 181–365 days | Renewals over limit | 2 | ||||||||
| EXAMPLE | EX-2025-016 | Policy or standard requirement | Door-entry controller on the office network | Network Security Standard — building systems segregated | Door-entry controller | Facilities Manager | Chief Operating Officer | IT Operations Manager | 1 | 2 | Firewall rule limits the controller to the vendor's cloud service | No | 2 | 2 | Low | Control owner | 17 Sep 2025 | Approved | IT Operations Manager | 22 Sep 2025 | 3 | On time | 22 Sep 2025 | 21 Sep 2026 | 22 Sep 2026 | Within maximum | 0 | 2 | Within limit | Open | 21 | Reminder due | 343 | OK | 1 | 22 Sep 2025 | 21 Sep 2026 | 0 | 2 | Yes | 343 | 181–365 days | ||||||||||||
| EXAMPLE | EX-2025-018 | Policy or standard requirement | Supplier remote access through a permanent firewall rule | Supplier Access Standard — access enabled only when needed | Building management system | Facilities Manager | Chief Operating Officer | Network Engineer | 2 | 2 | Source address limited to the supplier's office; sessions logged | No | 2 | 4 | Medium | Head of Information Security | 1 Apr 2026 | Approved | Head of Information Security | 6 Apr 2026 | 3 | On time | 6 Oct 2025 | 30 Sep 2026 | 3 Oct 2026 | Within maximum | 1 | 2 | Within limit | Open | 30 | Reminder due | 329 | OK | 1 | 6 Oct 2025 | 30 Sep 2026 | 1 | 2 | Yes | 329 | 181–365 days | ||||||||||||
| EXAMPLE | EX-2025-020 | Policy or standard requirement | Unencrypted backup tapes stored off site | Cryptography Standard — encrypt backups leaving the site | Backup service | IT Operations Manager | Chief Operating Officer | IT Operations Manager | 3 | 2 | Tapes carried in locked cases by a vetted courier | No | 2 | 6 | Medium | Head of Information Security | 15 Oct 2025 | Approved | Head of Information Security | 20 Oct 2025 | 3 | On time | 20 Oct 2025 | 17 Apr 2026 | 18 Apr 2026 | Within maximum | 0 | 2 | Within limit | 10 Apr 2026 | Encrypted cloud backup in use; last tape collection 2026-04-08 | Closed | 172 | OK | 1 | 20 Oct 2025 | 17 Apr 2026 | 10 Apr 2026 | 0 | 2 | No | |||||||||||||
| EXAMPLE | EX-2025-022 | Segregation of duties conflict | Developer with production deployment rights (SOD-IT-05) | Segregation of duties — develop and deploy | Customer portal | Development Lead | Chief Operating Officer | Development Lead | 4 | 2 | Weekly review of deployments by the IT Operations Manager | No | 2 | 8 | High | Head of Information Security and the accountable executive (risk owner) | 27 Jan 2026 | Approved | Head of Information Security; Chief Operating Officer | 30 Jan 2026 | 3 | On time | 3 Nov 2025 | 29 Apr 2026 | 30 Apr 2026 | Within maximum | 1 | 1 | Within limit | 28 Apr 2026 | Deployment moved to the build pipeline with required code review | Closed | 176 | OK | 1 | 3 Nov 2025 | 29 Apr 2026 | 28 Apr 2026 | 1 | 1 | No | |||||||||||||
| EXAMPLE | EX-2025-024 | Policy or standard requirement | Remote access appliance flaw awaiting the vendor's fix | Vulnerability Management Standard — Priority 1 deadline | Remote access gateway (SRV-022) | Network Engineer | Chief Executive | Network Engineer | 4 | 4 | Vendor's mitigation applied; access limited to managed devices | 17 Nov 2025 | Yes | 3 | 12 | Critical | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | 12 Nov 2025 | Approved | Executive Committee | 17 Nov 2025 | 3 | On time | 17 Nov 2025 | 17 Dec 2025 | 17 Dec 2025 | Within maximum | 0 | 1 | Within limit | 12 Dec 2025 | Vendor fix installed; rescan clean 2025-12-12 | Closed | 25 | OK | 1 | 17 Nov 2025 | 17 Dec 2025 | 12 Dec 2025 | 0 | 1 | No | ||||||||||||
| EXAMPLE | EX-2025-027 | Policy or standard requirement | End-of-life database on the finance reporting server | Vulnerability Management Standard — supported software only | Finance reporting server (APP-011) | Finance Systems Lead | Finance Director | IT Operations Manager | 3 | 3 | Database reachable only from the reporting application | No | 3 | 9 | High | Head of Information Security and the accountable executive (risk owner) | 24 Feb 2026 | Approved | Head of Information Security; Chief Operating Officer | 27 Feb 2026 | 3 | On time | 1 Dec 2025 | 27 May 2026 | 28 May 2026 | Within maximum | 1 | 1 | Within limit | Expired | -96 | 68 | Escalate | 273 | Expired — remediate, renew or escalate (EX-10) | Expired; renewal beyond the band's limit needs executive management (EX-08) | 1 | 1 Dec 2025 | 27 May 2026 | 1 | 1 | Yes | 273 | 181–365 days | Yes | 68 | ||||||||
| EXAMPLE | EX-2026-001 | Policy or standard requirement | Short passwords on shop-floor terminals | Password Standard — minimum length | Shop-floor terminals | Production Manager | Chief Operating Officer | IT Operations Manager | 1 | 3 | Terminals on a separate network; badge needed to log on | No | 3 | 3 | Low | Control owner | 7 Jan 2026 | Approved | IT Operations Manager | 12 Jan 2026 | 3 | On time | 12 Jan 2026 | 11 Jan 2027 | 12 Jan 2027 | Within maximum | 0 | 2 | Within limit | Open | 133 | 231 | OK | 1 | 12 Jan 2026 | 11 Jan 2027 | 0 | 2 | Yes | 231 | 181–365 days | |||||||||||||
| EXAMPLE | EX-2026-003 | Policy or standard requirement | Contractor laptops outside device management | Endpoint Standard — managed devices only | Contractor laptops | Project Manager | Chief Operating Officer | IT Operations Manager | 2 | 3 | Contractors use the virtual desktop only; no local data | 20 Jan 2026 | Yes | 2 | 4 | Medium | Head of Information Security | 21 Jan 2026 | Approved | Head of Information Security | 26 Jan 2026 | 3 | On time | 26 Jan 2026 | 24 Jul 2026 | 25 Jul 2026 | Within maximum | 0 | 2 | Within limit | 20 Jul 2026 | Contract ended; accounts disabled 2026-07-20 | Closed | 175 | OK | 1 | 26 Jan 2026 | 24 Jul 2026 | 20 Jul 2026 | 0 | 2 | No | ||||||||||||
| EXAMPLE | EX-2026-005 | Policy or standard requirement | HR system logs not sent to the central log store | Logging Standard — central log collection | HR system | HR Systems Lead | HR Director | IT Operations Manager | 2 | 2 | Weekly export of the HR system's audit report | No | 2 | 4 | Medium | Head of Information Security | 4 Feb 2026 | Approved | Head of Information Security | 9 Feb 2026 | 3 | On time | 9 Feb 2026 | 7 Aug 2026 | 8 Aug 2026 | Within maximum | 0 | 2 | Within limit | Expired | -24 | 16 | Escalate | 203 | Expired — remediate, renew or escalate (EX-10) | Connector ordered; renewal request not yet made | 1 | 9 Feb 2026 | 7 Aug 2026 | 0 | 2 | Yes | 203 | 181–365 days | Yes | 16 | ||||||||
| EXAMPLE | EX-2026-006 | Segregation of duties conflict | One administrator for the finance system and payment approval (SOD-FI-03) | Segregation of duties — administer and transact | Finance system | Financial Controller | Finance Director | Financial Controller | 4 | 2 | Monthly review of administrator activity by the Finance Director | No | 2 | 8 | High | Head of Information Security and the accountable executive (risk owner) | 19 May 2026 | Approved | Head of Information Security; Chief Operating Officer | 22 May 2026 | 3 | On time | 23 Feb 2026 | 19 Aug 2026 | 20 Aug 2026 | Within maximum | 1 | 1 | Within limit | 14 Aug 2026 | Second administrator trained; payment approval removed from the admin account | Closed | 172 | OK | 1 | 23 Feb 2026 | 19 Aug 2026 | 14 Aug 2026 | 1 | 1 | No | |||||||||||||
| EXAMPLE | EX-2026-008 | Policy or standard requirement | Old encryption protocol accepted on the intranet | Cryptography Standard — current TLS only | Intranet | Digital Services Manager | Chief Operating Officer | Digital Services Manager | 1 | 2 | Intranet reachable only from the internal network | No | 2 | 2 | Low | Control owner | 4 Mar 2026 | Approved | IT Operations Manager | 9 Mar 2026 | 3 | On time | 9 Mar 2026 | 8 Mar 2027 | 9 Mar 2027 | Within maximum | 0 | 2 | Within limit | Open | 189 | 175 | OK | 1 | 9 Mar 2026 | 8 Mar 2027 | 0 | 2 | Yes | 175 | 91–180 days | |||||||||||||
| EXAMPLE | EX-2026-009 | Policy or standard requirement | Vendor-managed CCTV recorders not patched | Vulnerability Management Standard — patch deadlines | CCTV recorders | Facilities Manager | Chief Operating Officer | Facilities Manager | 2 | 3 | Recorders on their own network with no internet access | No | 3 | 6 | Medium | Head of Information Security | 18 Mar 2026 | Approved | Head of Information Security | 23 Mar 2026 | 3 | On time | 23 Mar 2026 | 18 Sep 2026 | 19 Sep 2026 | Within maximum | 0 | 2 | Within limit | Open | 18 | Reminder due | 161 | OK | 1 | 23 Mar 2026 | 18 Sep 2026 | 0 | 2 | Yes | 161 | 91–180 days | ||||||||||||
| EXAMPLE | EX-2026-011 | Policy or standard requirement | E-mail gateway flaw pending replacement | Vulnerability Management Standard — Priority 1 deadline | E-mail gateway | IT Operations Manager | Chief Executive | IT Operations Manager | 4 | 3 | Attachment types restricted; extra filtering by the provider | No | 3 | 12 | Critical | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | 1 May 2026 | Approved | Executive Committee | 6 May 2026 | 3 | On time | 6 Apr 2026 | 5 Jun 2026 | 5 Jun 2026 | Within maximum | 1 | 1 | Within limit | 1 Jun 2026 | Replacement gateway live 2026-06-01 | Closed | 56 | OK | 1 | 6 Apr 2026 | 5 Jun 2026 | 1 Jun 2026 | 1 | 1 | No | |||||||||||||
| EXAMPLE | EX-2026-012 | Policy or standard requirement | Guest wireless on the corporate network segment | Network Security Standard — guest traffic separated | Guest wireless | Office Manager | Chief Operating Officer | Network Engineer | 1 | 3 | Guest network filtered to internet only | No | 3 | 3 | Low | Control owner | 15 Apr 2026 | Approved | IT Operations Manager | 20 Apr 2026 | 3 | On time | 20 Apr 2026 | 17 Oct 2026 | 20 Apr 2027 | Within maximum | 0 | 2 | Within limit | Open | 47 | 133 | OK | 1 | 20 Apr 2026 | 17 Oct 2026 | 0 | 2 | Yes | 133 | 91–180 days | |||||||||||||
| EXAMPLE | EX-2026-013 | Segregation of duties conflict | IT Operations Manager both creates and approves user access (SOD-IT-01) | Segregation of duties — access administration | Directory service | IT Operations Manager | Finance Director | Head of Information Security | 2 | 3 | Weekly directory change report signed by the Finance Director | 30 Apr 2026 | Yes | 2 | 4 | Medium | Head of Information Security | 29 Apr 2026 | Approved | Head of Information Security | 4 May 2026 | 3 | On time | 4 May 2026 | 31 Oct 2026 | 31 Oct 2026 | Within maximum | 0 | 2 | Within limit | Open | 61 | 119 | OK | 1 | 4 May 2026 | 31 Oct 2026 | 0 | 2 | Yes | 119 | 91–180 days | ||||||||||||
| EXAMPLE | EX-2026-015 | Policy or standard requirement | Remote access without multi-factor authentication for a board member | Access Control Standard — MFA for remote access | Remote access service | Company Secretary | Chief Executive | IT Operations Manager | 3 | 3 | Access limited to one managed laptop; sign-ins reviewed weekly | No | 3 | 9 | High | Head of Information Security and the accountable executive (risk owner) | 11 Aug 2026 | Approved | Head of Information Security; Chief Operating Officer | 14 Aug 2026 | 3 | On time | 18 May 2026 | 11 Nov 2026 | 12 Nov 2026 | Within maximum | 1 | 1 | Within limit | Open | 72 | 105 | OK | 1 | 18 May 2026 | 11 Nov 2026 | 1 | 1 | Yes | 105 | 91–180 days | |||||||||||||
| EXAMPLE | EX-2026-016 | Segregation of duties conflict | Administrators can read their own servers' logs (SOD-IT-03) | Segregation of duties — administer and review logs | Windows servers | IT Operations Manager | Chief Operating Officer | Head of Information Security | 3 | 2 | Logs copied to the managed security service's store, which administrators cannot change | 11 May 2026 | Yes | 1 | 3 | Low | Control owner | 13 May 2026 | Approved | IT Operations Manager | 18 May 2026 | 3 | On time | 18 May 2026 | 17 May 2027 | 18 May 2027 | Within maximum | 0 | 2 | Within limit | Open | 259 | 105 | OK | 1 | 18 May 2026 | 17 May 2027 | 0 | 2 | Yes | 105 | 91–180 days | ||||||||||||
| EXAMPLE | EX-2026-018 | Policy or standard requirement | Plant-floor workstation without endpoint protection | Endpoint Standard — anti-malware on every device | Line 2 control workstation | Production Manager | Chief Operating Officer | Production Engineer | 4 | 2 | USB ports blocked; no e-mail or web access | No | 2 | 8 | High | Head of Information Security and the accountable executive (risk owner) | 10 Jun 2026 | Approved | Head of Information Security; Chief Operating Officer | 15 Jun 2026 | 3 | On time | 15 Jun 2026 | 12 Sep 2026 | 13 Sep 2026 | Within maximum | 0 | 1 | Within limit | Open | 12 | Reminder due | 77 | OK | 1 | 15 Jun 2026 | 12 Sep 2026 | 0 | 1 | Yes | 77 | 31–90 days | ||||||||||||
| EXAMPLE | EX-2026-020 | Policy or standard requirement | USB storage allowed for the design team | Endpoint Standard — removable media blocked | Design team laptops | Design Manager | Chief Operating Officer | IT Operations Manager | 1 | 3 | Encrypted company USB drives only; use logged | No | 3 | 3 | Low | Control owner | 1 Jul 2026 | Approved | IT Operations Manager | 6 Jul 2026 | 3 | On time | 6 Jul 2026 | 1 Jan 2027 | 6 Jul 2027 | Within maximum | 0 | 2 | Within limit | Open | 123 | 56 | OK | 1 | 6 Jul 2026 | 1 Jan 2027 | 0 | 2 | Yes | 56 | 31–90 days | |||||||||||||
| EXAMPLE | EX-2026-021 | Policy or standard requirement | Firewall management interface exposed pending a firmware update | Network Security Standard — management interfaces not internet-facing | Perimeter firewall (FW-002) | Network Engineer | Chief Executive | Network Engineer | 4 | 3 | Access limited to two source addresses; login alerts to the security service | No | 3 | 12 | Critical | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | 5 Aug 2026 | Approved | Executive Committee | 10 Aug 2026 | 3 | On time | 10 Aug 2026 | 9 Sep 2026 | 9 Sep 2026 | Within maximum | 0 | 1 | Within limit | Open | 9 | Reminder due | 21 | OK | 1 | 10 Aug 2026 | 9 Sep 2026 | 0 | 1 | Yes | 21 | 0–30 days | ||||||||||||
| EXAMPLE | EX-2026-019 | Policy or standard requirement | Turn off anti-malware scanning on the build server | Endpoint Standard — anti-malware on every device | Build server | Development Lead | Chief Operating Officer | IT Operations Manager | 2 | 3 | None proposed | No | 3 | 6 | Medium | Head of Information Security | 5 Jun 2026 | Refused | Head of Information Security | 10 Jun 2026 | 3 | On time | 0 | 2 | Within limit | Refused | OK | Refused: exclude the build folders from scanning instead | 0 | 0 | 2 | No | ||||||||||||||||||||||
| EXAMPLE | EX-2026-023 | Policy or standard requirement | Personal phones on the production wireless network | Network Security Standard — managed devices only | Production wireless network | Production Manager | Chief Operating Officer | Network Engineer | 1 | 3 | Client isolation on the wireless network | No | 3 | 3 | Low | Control owner | 27 Aug 2026 | 0 | 2 | Within limit | Requested | Awaiting decision (EX-05) | Awaiting the risk assessment | 0 | 0 | 2 | No | |||||||||||||||||||||||||||
| EXAMPLE | EX-2026-022 | Policy or standard requirement | Shared mailbox without multi-factor authentication | Access Control Standard — MFA for all accounts | Customer service mailbox | Customer Service Manager | Chief Operating Officer | IT Operations Manager | 2 | 2 | Sign-in limited to the office network | No | 2 | 4 | Medium | Head of Information Security | 19 Aug 2026 | Approved | Head of Information Security | 24 Aug 2026 | 3 | On time | 24 Aug 2026 | 19 Feb 2027 | 20 Feb 2027 | Within maximum | 0 | 2 | Within limit | Open | 172 | 7 | OK | 1 | 24 Aug 2026 | 19 Feb 2027 | 0 | 2 | Yes | 7 | 0–30 days |
Metric Definitions
Metric definitions
The four headline measures the pack reports, defined once so every month is calculated the same way. Change a definition only through a new version of the Security Exception & Waiver Standard.
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| Open exceptions by band | Live approved exceptions at month end, by Low, Medium, High and Critical. | Approved rows with a first start date on or before the report date and no closed date on or before it, counted by Band. | Trend down; no unexplained rise in High or Critical | A steady number can hide a shift upward in band. Read High and Critical on their own; each rise needs a reason in the commentary. |
| Expired exceptions | Exceptions past their expiry date that are neither closed nor renewed, as a share of all open exceptions. | Open rows whose expiry date is before the report date. Shown as a count for High and Critical, a count for all bands, and a share of all open exceptions. | Zero High or Critical; below 5% overall | An expired exception is a control left off with nobody's current approval. After 10 working days it must have been remediated, renewed or escalated (EX-10). |
| Chronic exceptions | Exceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits. | Open rows whose Renewals exceed the band's renewal limit (Low 2, Medium 2, High 1, Critical 1). | Zero; each one reported by name | A chronic exception has stopped being temporary. Management decides: fix it, retire the system, or accept it at the next approval level up (EX-08). |
| Unmitigated SoD conflicts | Known High conflicts with no compensating control recorded and reviewed in the last quarter. | Typed in from the Summary sheet of the Segregation of Duties Conflict Matrix; not calculated here. | Zero | A High conflict with no working, reviewed compensating control lets one person act and hide it. |
Supporting views
| View | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| Ageing | Open exceptions by how long they have been open, by band. | Report date minus first start date, in the buckets 0–30 days, 31–90 days, 91–180 days, 181–365 days, Over 365 days. | No target — context | Old exceptions in the High and Critical rows are the ones to ask about. |
| Expiry position | Expired exceptions by band, those past the grace period, and those due to expire soon. | Expired: as above. Past grace: more than 10 working days since expiry. Due: open, not yet expired, expiry within 30, 60, 90 days of the report date. | No expired High or Critical | Owners are reminded 30 days before expiry (EX-09); a large 'within 30 days' column is next month's expired count if nobody acts. |
| Trend | Open exceptions by band at each of the last twelve month ends, with those opened, closed and expired in each month. | The open rule above, applied at each month end. | Trend down | Direction over several months matters more than any single month. |
Dashboard
Exception ageing and expiry — dashboard
Yellow cells are yours: the report date, the segregation of duties figures and the commentary. Everything else is calculated at the report date. Each figure has a status in words; the colour only repeats it.
Report settings
| Setting | Value | |
|---|---|---|
| Report date (normally a month end) | 31 Aug 2026 | EXAMPLE report date — replace with your own |
| Previous month end | 31 Jul 2026 | |
| Unmitigated SoD conflicts — this month | 2 | EXAMPLE — from the Segregation of Duties Conflict Matrix Summary |
| Unmitigated SoD conflicts — previous month | 1 |
Headline measures — this month against last month
| Measure | Target | This month | Previous month | Change | Status | Commentary — what changed and why | |
|---|---|---|---|---|---|---|---|
| Open exceptions by band — Low | Trend down | 7 | 7 | 0 | No change | ||
| Open exceptions by band — Medium | Trend down | 6 | 5 | +1 | Rising | ||
| Open exceptions by band — High | No unexplained rise | 4 | 5 | -1 | Falling | ||
| Open exceptions by band — Critical | No unexplained rise | 1 | 0 | +1 | Rising — explain | ||
| Open exceptions by band — all bands | Trend down | 18 | 17 | +1 | Rising | ||
| Expired exceptions — High or Critical | 0 | 1 | 1 | 0 | Action needed | ||
| Expired exceptions — all bands | — | 3 | 2 | +1 | |||
| Expired as a share of all open exceptions | Below 5% | 16.7% | 11.8% | +4.9% | Above target | ||
| Chronic exceptions | 0 | 2 | 2 | 0 | Action needed | ||
| Unmitigated SoD conflicts | 0 | 2 | 1 | +1 | Action needed | ||
Change is this month minus last month; for the share it is in percentage points. Last month is recalculated from this month's data — see the Instructions.
Ageing — open exceptions by time open
| Band | 0–30 days | 31–90 days | 91–180 days | 181–365 days | Over 365 days | Total open |
|---|---|---|---|---|---|---|
| Low | 0 | 1 | 3 | 2 | 1 | 7 |
| Medium | 1 | 0 | 2 | 2 | 1 | 6 |
| High | 0 | 1 | 1 | 2 | 0 | 4 |
| Critical | 1 | 0 | 0 | 0 | 0 | 1 |
| All bands | 2 | 2 | 6 | 6 | 2 | 18 |
Expiry position by band
| Band | Expired | Expired over 10 working days | Oldest expired (days) | Due within 30 days | Due within 60 days | Due within 90 days |
|---|---|---|---|---|---|---|
| Low | 0 | 0 | — | 1 | 2 | 3 |
| Medium | 2 | 2 | 82 | 2 | 2 | 3 |
| High | 1 | 1 | 96 | 2 | 2 | 3 |
| Critical | 0 | 0 | — | 1 | 1 | 1 |
| All bands | 3 | 3 | 96 | 6 | 7 | 10 |
'Due within' counts are cumulative: the 60-day figure includes the 30-day one. Owners are reminded 30 days before expiry (EX-09); expired exceptions are remediated, renewed or escalated within 10 working days (EX-10).
Chronic exceptions — named for management (first 10)
| Title | Exception ID | Band | Days open | Renewals | Renewal limit | Why chronic | Decision sought from management |
|---|---|---|---|---|---|---|---|
| Legacy file server without multi-factor authentication for administrators | EX-2025-011 | Medium | 441 | 3 | 2 | Renewals over limit | |
| Payroll server on an unsupported operating system | EX-2025-014 | High | 357 | 3 | 1 | Renewals over limit |
What to say to management — quarterly report (EX-12)
| Point | What to say | ||||||
|---|---|---|---|---|---|---|---|
| The position in one sentence | [[e.g. 18 exceptions are open; one High exception has been expired since May and one Critical exception expires on 9 September.]] | ||||||
| Decisions needed from management | [[e.g. Decide by 30 September whether the finance reporting database exception (EX-2025-027) is renewed by executive management or the server is switched off.]] | ||||||
| Chronic exceptions and what we propose for each | [[e.g. Payroll server (EX-2025-014): renewed three times; propose funding the replacement project's earlier start.]] | ||||||
| Segregation of duties | [[e.g. Two High conflicts have no reviewed compensating control; both will be reviewed by 15 October.]] | ||||||
| What has improved since the last report | [[e.g. Three exceptions closed in the quarter, including both segregation of duties exceptions in finance.]] | ||||||
| Prepared by (name, role) and date | [[Name, role, YYYY-MM-DD]] | ||||||
Trend
Trend — twelve month ends to the report date
Open exceptions by band at each month end, with those opened, closed and expired in the month. The bars repeat the numbers beside them. Use the last column to note what happened.
| Month end | Low | Medium | High | Critical | Total open | High and Critical | Opened in month | Closed in month | Expired at month end | Direction (total) | Commentary |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 30 Sep 2025 | 3 | 1 | 1 | 0 | 5 | 1 | 2 | 0 | 0 | — | |
| 31 Oct 2025 | 3 | 3 | 1 | 0 | 7 | 1 | 2 | 0 | 0 | Rising | |
| 30 Nov 2025 | 3 | 3 | 2 | 1 | 9 | 3 | 2 | 0 | 0 | Rising | |
| 31 Dec 2025 | 2 | 3 | 3 | 0 | 8 | 3 | 1 | 2 | 0 | Falling | |
| 31 Jan 2026 | 3 | 4 | 3 | 0 | 10 | 3 | 2 | 0 | 0 | Rising | |
| 28 Feb 2026 | 3 | 5 | 4 | 0 | 12 | 4 | 2 | 0 | 0 | Rising | |
| 31 Mar 2026 | 4 | 6 | 4 | 0 | 14 | 4 | 2 | 0 | 0 | Rising | |
| 30 Apr 2026 | 5 | 5 | 3 | 1 | 14 | 4 | 2 | 2 | 0 | No change | |
| 31 May 2026 | 6 | 6 | 4 | 1 | 17 | 5 | 3 | 0 | 1 | Rising | |
| 30 Jun 2026 | 6 | 6 | 5 | 0 | 17 | 5 | 1 | 1 | 2 | No change | |
| 31 Jul 2026 | 7 | 5 | 5 | 0 | 17 | 5 | 1 | 1 | 2 | No change | |
| 31 Aug 2026 | 7 | 6 | 4 | 1 | 18 | 5 | 2 | 1 | 3 | Rising |
Expired at month end uses each exception's current expiry date, so one renewed late since then no longer shows as expired in the earlier month. Keep each month's copy for the figures as reported.
Lists
| Band | BandMaxDays | BandRenewals | ExceptionType | Decision | Status | YesNo | Level |
|---|---|---|---|---|---|---|---|
| Low | 365 | 2 | Policy or standard requirement | Approved | Requested | Yes | 1 |
| Medium | 180 | 2 | Segregation of duties conflict | Refused | Refused | No | 2 |
| High | 90 | 1 | Open | 3 | |||
| Critical | 30 | 1 | Expired | 4 |
Closed
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Exception | An approved, time-limited decision that a security policy or standard requirement will not be met, with a named risk owner, compensating controls and an expiry date (Security Exception & Waiver Standard). |
| Band | Low, Medium, High or Critical, from the exception's score in the Exception Risk Scoring & Expiry Model. The band sets who approves and how long the exception may run: Low up to 365 days, 2 renewals; Medium up to 180 days, 2 renewals; High up to 90 days, 1 renewal; Critical up to 30 days, 1 renewal (EX-05, EX-06, EX-08). |
| First start date | The date the exception first came into force. Ageing counts from this date, across renewals. |
| Expiry date | The date the current term of the exception ends. After it the exception is expired unless renewed or closed. |
| Renewal | A new approval that extends an exception for another term. Each band allows a set number; a renewal beyond it goes to the next approval level up (EX-08). |
| Open | At a given date: approved, first start date on or before it and no closed date on or before it. Requested and refused exceptions are never open. |
| Expired | Open, with an expiry date before the date being reported. Remediate, renew or escalate within the grace period (EX-10). |
| Grace period | 10 working days after expiry, within which an expired exception must be remediated, renewed or escalated (EX-10). |
| Chronic | Open, and renewed more times than its band allows (EX-08). Age alone does not make an exception chronic; the ageing table shows how long each has been open. |
| Unmitigated SoD conflict | Known High conflicts with no compensating control recorded and reviewed in the last quarter. Taken from the Segregation of Duties Conflict Matrix. |
| Report date | The date every figure is calculated at, normally the last day of the month being reported. Set on the Dashboard. |
| Ageing bucket | How long an open exception has been open at the report date: 0–30 days, 31–90 days, 91–180 days, 181–365 days, Over 365 days. |
| Risk owner | The accountable business executive for the affected service, who accepts the exception's remaining risk. |
| EX-nn, SD-nn | Requirement numbers in the Security Exception & Waiver Standard: EX for exceptions, SD for segregation of duties. |
| (calc) | A column or cell the workbook calculates. Do not type or paste over it. |
| EXAMPLE row | A worked example showing the format. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | The workbook as a whole: defined measures, calculated each month |
| ISO/IEC 27001:2022 | Clause 9.3 — Management review | What to say to management; quarterly report (EX-12) |
| ISO/IEC 27001:2022 | Annex A 5.36 — Compliance with policies, rules and standards for information security | Expired and chronic exceptions: where policies are not being complied with |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Headline measures, period comparison, Trend |
| NIST CSF 2.0 | ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated” | Expiry position, chronic exceptions and the decisions sought |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(c)(ii) and (iii) — ICT security policies record exceptions from their implementation and keep resilience assured while exceptions exist | Register Data and the Dashboard: exceptions recorded and reported while they exist |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774