Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Exception & SoD Responsibility Matrix

Fixes the ambiguity over who requests, who assesses risk, who approves and who monitors, which is where exception processes usually stall.

Available soon

Format
Excel
Size
67 KB
Length
11 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Responsibility Matrix
  • Role Holders
  • Role Combinations
  • Combined Roles Check
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Read the Responsibility Matrix. Each row is one activity, with the rule in the Standard it comes from. R = does the work; A = accountable, signs it off, exactly one per activity; C = consulted before it is done; I = informed after. A/R means the accountable role also does the work.
2Adjust the letters to how your organisation works, using the drop-down in each yellow cell. Keep exactly one A (or A/R) and at least one R per row: the Check column says OK only when both hold.
3Keep the approval rows (EX-A05 to EX-A08) as they are unless your approved Standard changes the bands. They follow the approvers and decision times in the Exception Risk Scoring & Expiry Model.
4On Role Holders, name the post that holds each role and its deputy. A deputy may act for the role only as set out on that sheet; approval authority is never delegated downwards.
5If one person holds several roles, list them on Combined Roles Check and mark each role they hold. The Result column shows whether any combination is never acceptable, or needs the safeguard on the Role Combinations sheet.
6Resolve every Never acceptable combination before approving this matrix, by moving a role to someone else or to an external reviewer. Record the safeguard you use for each Acceptable with safeguard combination.
7Review the matrix with the conflict matrix (annually, and after any restructure or new core system) and whenever a role holder changes.
8Delete the EXAMPLE rows on Combined Roles Check before the matrix is approved.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: the managing director is often executive management and risk owner, and the IT manager is control owner, information security and service desk. That is workable with the safeguards on the Role Combinations sheet. The one thing that must be bought in is an independent reviewer: an external adviser or your auditor, once a year.

Tailoring — regulated entity (NIS2, DORA): keep the independent reviewer separate from information security and from executive management; DORA expects the control function for ICT risk to be independent and separate from internal audit. Name the management body as the Critical approver.

Tailoring — IT run by a service provider: the provider's desk usually does the IT service desk work, including the conflict check before granting access (SD-A02). Put that duty and the emergency-access records into the service agreement. Accountability (the A) stays with people in your organisation.

Delegation: a deputy may act for a role while its holder is absent, at the same or a higher level of authority. Nobody may approve an exception above the authority the Standard gives their role, and a deputy is bound by the same combination rules as the person they stand in for.

Responsibility Matrix

R = responsible (does it) · A = accountable (exactly one per activity) · C = consulted · I = informed · A/R = accountable and does it. Yellow cells are yours to adjust.

RefProcessActivityRuleRequesterRisk ownerControl ownerInformation securityExecutive managementIndependent reviewerIT service deskOutput, evidence or noteA countR countCheck
EX-A01ExceptionRaise an exception request: requirement not met, reason, risk, compensating controls, remediation plan and end dateEX-01, EX-03A/RCCICompleted Security Exception Request & Approval Form, before the requirement is breached where possible11OK
EX-A02ExceptionCheck the request is complete, in scope and not something that may never be exceptedEX-02, EX-03IA/RRequest accepted for assessment, or returned with reasons11OK
EX-A03ExceptionAssess the risk: score impact and likelihood, and set the bandEX-04CCCA/RScored request, using the Exception Risk Scoring & Expiry Model. The requester and risk owner may comment on the score but not set it11OK
EX-A04ExceptionConfirm the compensating control is in place and has been testedEX-07RACTest evidence. A planned control does not lower the score11OK
EX-A05ExceptionApprove or refuse a Low exception (score 1–3): control ownerEX-05IIA/RCDecided within 5 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form11OK
EX-A06ExceptionApprove or refuse a Medium exception (score 4–6): head of Information SecurityEX-05ICCA/RDecided within 10 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form11OK
EX-A07ExceptionApprove or refuse a High exception (score 8–9): head of Information Security and the accountable executive (risk owner)EX-05IACRIDecided within 10 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form. Both sign; the risk owner is accountable for accepting the risk11OK
EX-A08ExceptionApprove or refuse a Critical exception (score 12–16): the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive managementEX-05IRCRADecided within 5 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form. The risk owner presents the case; information security presents the assessment12OK
EX-A09ExceptionRecord the decision in the register, with an expiry no later than the band's maximumEX-06, EX-11IIA/RRow in the Security Exception Register, refused requests included11OK
EX-A10ExceptionRun the compensating control, and re-test it while the exception is openEX-07A/RCIEvidence the control is still in place, checked at each monthly review. Whoever runs it does not approve the exception11OK
EX-A11ExceptionRemind the requester and risk owner 30 days before expiryEX-09IIIA/RReminder sent and noted in the register11OK
EX-A12ExceptionRequest a renewal before expiry, with an updated risk assessment and a progress reportEX-08RACRenewal request; approved as for its band (EX-A05 to EX-A08)11OK
EX-A13ExceptionRefer a renewal beyond the band's limit to the next approval level upEX-08ICA/RIThe next level up decides. Above Critical: [[the full board, or its equivalent]]11OK
EX-A14ExceptionDeal with an expired exception within 10 working days: remediate, renew or escalateEX-10RACRIExpired High and Critical exceptions reported to their approver on the first working day after expiry12OK
EX-A15ExceptionClose the exception, checking and filing the closure evidenceEX-13RICAClosed date and evidence reference in the register11OK
EX-A16ExceptionReview the whole register (monthly)EX-11ICA/RReview record on the register's Monthly Review sheet11OK
EX-A17ExceptionReport exceptions to executive management (quarterly)EX-12IA/RIReport from the Exception Ageing & Expiry Dashboard: the headline measures, every High and Critical exception, and chronic exceptions by name11OK
EX-A18ExceptionDecide on chronic exceptions: fund the fix or formally carry the riskEX-08, EX-12CCA/RDecision minuted11OK
EX-A19ExceptionCheck a sample of decisions, renewals and closures against the StandardEX-11, EX-12CIA/RIndependent review findings11OK
SD-A01SoDMaintain the conflict matrix and rate each conflict (annually, and after any restructure or new core system)SD-02CCA/RICSegregation of Duties Conflict Matrix, reviewed and dated11OK
SD-A02SoDCheck the conflict matrix before granting or changing a role or access rightSD-03ICCA/RConflict check recorded on the access request11OK
SD-A03SoDRate a newly found conflict High, Medium or Low and add it to the matrixSD-02CCA/RMatrix entry; rating as the Security Exception & Waiver Standard defines it11OK
SD-A04SoDRecord a conflict that cannot be separated as an exception, with a compensating control performed by someone without the conflictSD-04RCCARow in the Security Exception Register; approved as for its band (EX-A05 to EX-A08). Method in the SoD Conflict Review & Compensating Control Procedure11OK
SD-A05SoDPerform the compensating control for an accepted conflict (for example, independent review of the person's activity)SD-04ARIEvidence of each review. Never performed by the person with the conflict, nor by whoever approved the exception11OK
SD-A06SoDReview each accepted conflict and its evidence: High quarterly, Medium every six months, Low at the annual matrix reviewSD-05CCA/RReview record. A High conflict with no control reviewed in the last quarter is reported as unmitigated11OK
SD-A07SoDReview each use of emergency or privileged access after the eventSD-06IARCReview within [[2 working days]], by someone other than the user; administrators never review their own logs11OK
SD-A08SoDKeep the records of conflict checks, accepted conflicts, compensating control evidence, reviews and emergency accessSD-07A/RRRecords an independent reviewer can follow from detection to latest review12OK
SD-A09SoDCheck independently that conflicts are detected, decided and reviewed as the Standard requiresSD-01, SD-05CIA/RIndependent review findings11OK

Role Holders

Name who holds each role and who deputises. The counts show how much of the matrix each role carries.

RoleWhat the role does hereHeld by (post)Deputy (post)What the deputy may doAccountable for (A)Responsible for (R)
RequesterRaises the request, runs the compensating controls, delivers the remediation plan, and asks for renewal or closure in time.[[e.g. system owner, project lead]][[Deputy post]]May raise or renew a request on the holder's behalf.27
Risk ownerAccepts the residual risk for the affected service and answers for it until closure. Co-approves High exceptions and presents Critical ones.[[the accountable business executive for the affected service]][[Deputy post]]Another executive of the same or higher level; never someone who reports to the requester.41
Control ownerOwns the requirement that is not met and confirms the compensating control works. Approves Low exceptions.[[e.g. IT Operations Manager]][[Deputy post]]May approve Low exceptions if at the same level of authority and not the requester.22
Information securityKeeps the Standard, the register and the conflict matrix; assesses every request; approves Medium and co-approves High exceptions; runs the monthly review and quarterly report.[[e.g. Head of Information Security]][[Deputy post]]A named deputy may assess requests and run the monthly review. Medium and High approvals need someone of equal authority, never a member of the requester's team.1515
Executive managementApproves Critical exceptions where the organisation has no board; otherwise takes them to the board or its equivalent, as the approval bands set out; approves escalated renewals, receives the quarterly report and decides on chronic exceptions.[[e.g. Executive Committee or its risk committee]][[Deputy post]]Acts as a body; a quorum under its terms of reference, excluding anyone with an interest in the request.21
Independent reviewerChecks that exceptions and conflicts are decided and recorded as the Standard requires, and reviews emergency and privileged access.[[e.g. internal audit, or an external reviewer for small organisations]][[Deputy post]]Another reviewer independent of the process, internal or external.23
IT service deskGrants and changes access after checking the conflict matrix, and keeps the emergency-access log.[[e.g. IT service desk, or the managed service provider's desk]][[Deputy post]]Any trained desk member, except for access to their own accounts.12

Role Combinations

The small-organisation variant: which duties and roles one person may hold together. The first rows apply in every organisation.

CombinationVerdictWhySafeguard, or what to do instead
Deciding an exception you requestedNever acceptableThe approval is the only independent look at the request.The decision passes to the next level up (EX-05).
Deciding an exception to a control you operate yourselfNever acceptableYou would be judging your own shortfall.The decision passes to the next level up (EX-05).
Approving an exception whose compensating control you performNever acceptableThe exception is only acceptable because the control works; you would be vouching for your own work.Someone else performs the control, or the decision passes to the next level up (EX-05).
Co-approving a High exception as its risk ownerAcceptableExpected: the Standard makes the risk owner co-approve High exceptions, because they carry the risk.Not if the risk owner also requested it or performs its compensating control (rows above).
Reviewing a conflict you hold, or performing its compensating controlNever acceptableThe compensating control exists because nobody else sees your work.Someone without the conflict reviews it (SD-04, SD-05).
Granting access or a role to yourselfNever acceptableThe conflict check before granting (SD-03) needs a second person.Another administrator, or the service desk, grants it.
Reviewing your own use of emergency or privileged accessNever acceptableAdministrators do not review the logs of their own activity (SD-06).The reviewer named in SD-A07.
Requester + Risk ownerAcceptable with safeguardRisk owners often ask for exceptions on their own service.For a High exception, which the risk owner co-approves, executive management decides instead.
Requester + Control ownerAcceptable with safeguardCommon where the owner of a requirement also runs the system.For a Low exception, which the control owner approves, the Medium approver decides instead.
Requester + Information securityAcceptable with safeguardSecurity staff raise exceptions for their own tools.Another person checks the risk assessment, and the decision passes to the next level up.
Requester + Executive managementAcceptable with safeguardExecutives request exceptions for their own areas.For a Critical exception, they declare the interest and take no part in the decision.
Requester + Independent reviewerAcceptable with safeguardAn internal reviewer may need exceptions for their own systems.Exceptions they raised are sampled by another reviewer.
Requester + IT service deskAcceptableThe service desk raises exceptions for the tools it runs.—
Risk owner + Control ownerAcceptableIn small organisations the person accountable for a service often owns its requirements too.Low approvals then come from the risk owner's own area; keep the Medium and higher bands unchanged.
Risk owner + Information securityAcceptable with safeguardThe risk assessment (EX-04) is meant to be independent of the business that wants the exception.For a High exception, which needs both signatures, executive management signs in place of the second.
Risk owner + Executive managementAcceptableRisk owners are usually executives.For a Critical exception on their own service, they present it and do not decide it.
Risk owner + Independent reviewerNever acceptableThe reviewer would be checking risk decisions they made themselves.Use another reviewer, or an external one.
Risk owner + IT service deskAcceptableUnusual, but no duty in the process conflicts.—
Control owner + Information securityAcceptable with safeguardTypical where the IT manager also covers security: they would assess exceptions to requirements they own.The independent reviewer samples these exceptions, and approvals for them pass to the next level up.
Control owner + Executive managementAcceptableExecutives often own policy requirements.—
Control owner + Independent reviewerNever acceptableThe reviewer would be checking exceptions to requirements they own.Use another reviewer, or an external one.
Control owner + IT service deskAcceptable with safeguardThe person who grants access also owns the access requirements.Emergency and privileged access is reviewed by someone else (SD-A07).
Information security + Executive managementAcceptableA head of security may sit on the executive committee.For a Critical exception, the rest of the committee decides on information security's assessment.
Information security + Independent reviewerNever acceptableThe reviewer would be checking the register and matrix they keep.Use internal audit, or an external reviewer once a year.
Information security + IT service deskAcceptable with safeguardIn small IT teams one person grants access and checks conflicts.Every grant they make to an administrator, and all emergency access, is reviewed by someone else (SD-06).
Executive management + Independent reviewerNever acceptableThe reviewer would be checking decisions they took.Use internal audit reporting to the board, or an external reviewer.
Executive management + IT service deskAcceptablePossible in very small organisations.—
Independent reviewer + IT service deskNever acceptableThe reviewer would be checking access they granted, including emergency access.Use another reviewer, or an external one.

Combined Roles Check

One row per person who holds more than one role. Mark each role they hold; the Result shows whether the combination is allowed.

ExamplePerson or postRequesterRisk ownerControl ownerInformation securityExecutive managementIndependent reviewerIT service deskRoles heldNever-acceptable pairsPairs needing a safeguardResultFirst pair to resolve
EXAMPLEManaging DirectorYesYes200OK
EXAMPLEIT ManagerYesYesYes303Allowed with safeguardControl owner + Information security (safeguard)
EXAMPLEFinance DirectorYesYesYes320Conflict — move a roleRisk owner + Independent reviewer (never)
EXAMPLEExternal adviser (annual review)Yes100OK

Lists

RACIYesNoVerdict
RYesNever acceptable
ANoAcceptable with safeguard
A/RAcceptable

C

I

Definitions

Definitions

TermMeaning in this workbook
R — ResponsibleDoes the work. There may be more than one.
A — AccountableOwns the outcome and signs it off. Exactly one per activity, so there is never doubt about who decides.
C — ConsultedAsked for input before the activity is done.
I — InformedTold of the outcome after the activity is done.
A/RAccountable and also does the work. Counts as both an A and an R in the Check column.
RequesterRaises the request, runs the compensating controls, delivers the remediation plan, and asks for renewal or closure in time. [[e.g. system owner, project lead]]
Risk ownerAccepts the residual risk for the affected service and answers for it until closure. Co-approves High exceptions and presents Critical ones. [[the accountable business executive for the affected service]]
Control ownerOwns the requirement that is not met and confirms the compensating control works. Approves Low exceptions. [[e.g. IT Operations Manager]]
Information securityKeeps the Standard, the register and the conflict matrix; assesses every request; approves Medium and co-approves High exceptions; runs the monthly review and quarterly report. [[e.g. Head of Information Security]]
Executive managementApproves Critical exceptions where the organisation has no board; otherwise takes them to the board or its equivalent, as the approval bands set out; approves escalated renewals, receives the quarterly report and decides on chronic exceptions. [[e.g. Executive Committee or its risk committee]]
Independent reviewerChecks that exceptions and conflicts are decided and recorded as the Standard requires, and reviews emergency and privileged access. [[e.g. internal audit, or an external reviewer for small organisations]]
IT service deskGrants and changes access after checking the conflict matrix, and keeps the emergency-access log. [[e.g. IT service desk, or the managed service provider's desk]]
Security exceptionAn approved, time-limited decision to operate without meeting a named requirement of a security policy or standard, with a named risk owner and a compensating control.
BandThe level an exception's score (impact × likelihood, 1–16) falls in, which sets its approver and decision time: Low 1–3 — control owner, within 5 working days from a complete request; Medium 4–6 — head of Information Security, within 10 working days from a complete request; High 8–9 — head of Information Security and the accountable executive (risk owner), within 10 working days from a complete request; Critical 12–16 — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management, within 5 working days from a complete request.
Segregation of duties (SoD)Splitting duties so that no one person can make, approve and conceal an unauthorised change, payment or access grant (SD-01).
ConflictA combination of duties or access rights one person should not hold together. Rated: High — one person could make and hide an unauthorised change, payment or access grant with no second person seeing it. Medium — one person could make an unauthorised change that another control would probably, but not certainly, detect later. Low — the combination is undesirable but the damage is small or detected quickly by routine checks.
Compensating controlA measure that reduces the risk while a requirement is not met or a conflict cannot be separated, performed by someone without the conflict.
Emergency (break-glass) accessPrivileged access granted outside the normal process for an urgent need, for a stated purpose and a limited time, and reviewed after use (SD-06).
DeputyThe person who acts for a role holder while they are absent, with no more authority than the role holds.
Never acceptableA combination that defeats the purpose of the control. Move one of the roles to someone else.
Acceptable with safeguardA combination that is workable if the safeguard shown is applied and recorded.
EXAMPLE rowA worked example on Combined Roles Check. Delete before approval.
EX-05, SD-04 …Rule numbers in the Security Exception & Waiver Standard.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 5.3 — Organizational roles, responsibilities and authoritiesResponsibility Matrix and Role Holders
ISO/IEC 27001:2022Annex A 5.2 — Information security roles and responsibilitiesResponsibility Matrix: one accountable role per activity
ISO/IEC 27001:2022Annex A 5.3 — Segregation of dutiesSoD activities; Role Combinations; Combined Roles Check
NIST CSF 2.0GV.RR-02 — “Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced”Responsibility Matrix and Role Holders
DORA — Regulation (EU) 2022/2554Article 6(4) — a control function for ICT risk, independent enough to avoid conflicts of interest, and segregation of ICT risk management, control and internal audit functionsIndependent reviewer kept separate from the roles it checks
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(g) — ICT security policies specify segregation-of-duties arrangements to avoid conflicts of interestRole Combinations and Combined Roles Check

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774