Security Exception Register
Maintains the authoritative record of every live deviation with owner, expiry and compensating control status.
Available soon
- Format
- Excel
- Size
- 117 KB
- Length
- 9 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Register
- Monthly Review
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Monthly Review sheet. It shows today's date; type a fixed date over it to freeze a month-end review. Every status, countdown and flag uses this date. |
| 2 | Add a row as soon as a complete request arrives on the Security Exception Request & Approval Form, and keep it whatever the decision: refused requests stay in the register (EX-11). Give it a unique Exception ID (for example EX-2026-012) and keep the same ID for the life of the exception, including renewals. A segregation-of-duties conflict that cannot be separated is recorded here too, with Exception type set accordingly (SD-04). |
| 3 | Describe the exception in plain words: the title, the exact policy or standard clause that is not met, and the system or asset it applies to (use the ID from your asset register). Name the requester, the risk owner (the executive accountable for the affected service) and the control owner (who owns the requirement that is not met). |
| 4 | Score it as the Exception Risk Scoring & Expiry Model does (EX-04): Impact 1–4 and Likelihood without compensating control 1–4. If the compensating control is in place and has been tested, enter the test date and set Compensating control effective to Yes: likelihood then drops one step, never more and never below 1 (EX-07). The Score, Band and Approver required columns calculate. |
| 5 | Record the decision: Decision, Decided by and Decision date. Decided by must match the Approver required for the band (EX-05): Low (score 1–3) — control owner, decided within 5 working days from a complete request; at most 365 days; 2 renewals. Medium (score 4–6) — head of Information Security, decided within 10 working days from a complete request; at most 180 days; 2 renewals. High (score 8–9) — head of Information Security and the accountable executive (risk owner), decided within 10 working days from a complete request; at most 90 days; 1 renewal. Critical (score 12–16) — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management, decided within 5 working days from a complete request; at most 30 days; 1 renewal. Nobody decides their own request or an exception to a control they operate; the decision then passes to the next level up. |
| 6 | For an approved exception, enter the First start date once and never change it, and the Expiry date. Maximum allowed expiry is the decision date plus the band's maximum duration (EX-06). On each renewal, overwrite Decided by, Decision date and Expiry date with the renewal's, and add one to Renewals; a renewal's expiry counts from its own approval date. |
| 7 | Act on the flags: Reminder due appears 30 days before expiry — tell the requester and risk owner to close, renew or let it lapse (EX-09). An Expired exception must be remediated, renewed or escalated within 10 working days; after that, Expired action shows Escalate (EX-10). Over limit on Renewal check means the renewal goes to the next approval level up (EX-08). |
| 8 | Close an exception only with evidence that it is no longer needed: enter the Closed date and describe the evidence in Closure evidence (EX-13). Do not delete closed or refused rows; they are the record. |
| 9 | Every month, review the whole register and the Monthly Review sheet, record the review at the foot of that sheet, and carry the figures into the quarterly management report (EX-11, EX-12). |
| 10 | Clear every Record check that does not say OK. Delete the EXAMPLE rows before the register is approved. Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: one person often requests, owns the requirement and runs security. That is workable, but nobody may decide their own request: if the approver for the band is the requester, the next level up decides. Record who actually signed in Decided by. The Exception & SoD Responsibility Matrix shows which role combinations are acceptable.
Tailoring — regulated entity (NIS2, DORA): add a column for the critical or important function each exception affects, keep month-end copies of this register (freeze the As-at date first) as records for supervisors and auditors, and report expired High and Critical exceptions to their approver on the first working day after expiry.
Tailoring — IT run by a service provider: exceptions the provider needs (for example an unsupported component in its service) are still raised and recorded here by your organisation. The provider may run the compensating control, but the risk owner and the person who decides are always people in your organisation.
Bands, approvers, decision times, maximum durations and renewal limits are read from the Lists sheet (Band, BandMinScore, BandApprover, BandDecisionDays, BandMaxDays, BandRenewals). If your approved Standard or Exception Risk Scoring & Expiry Model sets different values, change them there and nowhere else. Decision time counts working days from a complete request, excluding weekends but not public holidays.
Example rows use the template's revision date (2026-09-28) as their reference point, so their statuses change as the As-at date moves on. EX-2026-004 matches the exception on finding VF-0004 in the P01 Vulnerability Remediation Tracker example.
Register
One row per exception request, whatever the decision, from request to closure. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.
| Example | Exception ID | Exception type | Title | Policy or standard clause not met | System or asset | Requester | Risk owner | Control owner | Impact (1–4) | Likelihood without compensating control (1–4) | Compensating control | Compensating control last tested | Compensating control effective | Likelihood with compensating control | Score | Band | Approver required | Request complete date | Decision | Decided by | Decision date | Decision time (working days) | Decided on time | First start date | Expiry date | Maximum allowed expiry | Expiry check | Renewals | Renewal limit | Renewal check | Closed date | Closure evidence | Status | Days to expiry | Reminder | Working days since expiry | Expired action | Days open in total | Chronic | Record check | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | EX-2023-006 | Segregation of duties conflict | Payroll officer both maintains employee bank details and runs the payroll | Segregation of Duties Conflict Matrix — payroll master data and payment run, rated High | Payroll system (AST-008) | Payroll Manager | Finance Director | Financial Controller | 3 | 2 | Finance Director reviews the bank-detail change report against signed requests before each payroll run | 15 Jun 2026 | Yes | 1 | 3 | Low | Control owner | 20 Mar 2026 | Approved | Financial Controller | 27 Mar 2026 | 5 | On time | 3 Apr 2023 | 26 Mar 2027 | 27 Mar 2027 | Within maximum | 3 | 2 | Over limit | Open | 179 | 1274 | Chronic | Over renewal limit — refer one level up (EX-08) | Two-person payroll team. Renewed every year since 2023; the third renewal should have gone one level up (EX-08) | |||||
| EXAMPLE | EX-2026-002 | Policy or standard requirement | Supplier remote support account without multi-factor authentication | Remote Access Standard §3.1 — multi-factor authentication for all remote access | Warehouse management system (AST-014) | Logistics Systems Lead | Head of Logistics | IT Operations Manager | 2 | 3 | Account enabled only for each agreed support session and disabled afterwards; sessions recorded | No | 3 | 6 | Medium | Head of Information Security | 26 Jan 2026 | Approved | Head of Information Security | 2 Feb 2026 | 5 | On time | 2 Feb 2026 | 1 Aug 2026 | 1 Aug 2026 | Within maximum | 0 | 2 | Within limit | Expired | -58 | 41 | Escalate | 238 | Expired — remediate, renew or escalate (EX-10) | Control never tested, so likelihood not lowered. Supplier's multi-factor roll-out slipped; no renewal requested before expiry | |||||
| EXAMPLE | EX-2026-004 | Policy or standard requirement | Payroll application server on an unsupported operating system | Vulnerability & Exposure Management Standard — remediation deadline for finding VF-0004 | Payroll application server (AST-007) | Finance Systems Lead | Finance Director | IT Operations Manager | 4 | 3 | Server on its own network segment; only the payroll application port open, and only from finance workstations | 6 Jul 2026 | Yes | 2 | 8 | High | Head of Information Security and the accountable executive (risk owner) | 26 Jun 2026 | Approved | Head of Information Security and Finance Director | 8 Jul 2026 | 8 | On time | 8 Jul 2026 | 6 Oct 2026 | 6 Oct 2026 | Within maximum | 0 | 1 | Within limit | Open | 8 | Reminder due | 82 | OK | Replacement system due March 2027. Renewal request with a fresh risk assessment needed before expiry | |||||
| EXAMPLE | EX-2026-011 | Policy or standard requirement | Internet-facing file transfer server awaiting the vendor's fix for an actively exploited flaw | Vulnerability & Exposure Management Standard — Priority 1 remediation deadline | Managed file transfer server (AST-012) | Digital Services Manager | Chief Operating Officer | Network Manager | 4 | 4 | Web application firewall rule blocks the exploited request path; access limited to partner IP addresses | 16 Sep 2026 | Yes | 3 | 12 | Critical | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | 14 Sep 2026 | Approved | Executive Committee | 17 Sep 2026 | 3 | On time | 17 Sep 2026 | 31 Oct 2026 | 17 Oct 2026 | Beyond band maximum | 0 | 1 | Within limit | Open | 33 | 11 | Shorten expiry to the band maximum (EX-06) | Requested end date is past the Critical band's maximum; shorten it to the maximum and renew then if the fix is still not available | ||||||
| EXAMPLE | EX-2026-005 | Policy or standard requirement | Warehouse label printers use an unencrypted management protocol | Network Security Standard §5 — encrypted management protocols only | Warehouse label printers (AST-030) | Logistics Systems Lead | Head of Logistics | Network Manager | 2 | 3 | Printers on a separate network segment; management only from the IT administration network | 10 Apr 2026 | Yes | 2 | 4 | Medium | Head of Information Security | 30 Mar 2026 | Approved | Head of Information Security | 14 Apr 2026 | 11 | Late | 14 Apr 2026 | 11 Oct 2026 | 11 Oct 2026 | Within maximum | 0 | 2 | Within limit | 4 Sep 2026 | Printers replaced under CHG-2268; configuration export shows only encrypted management enabled; filed with the change record | Closed | 143 | OK | Decided a day after the band's decision time |
Monthly Review
Monthly register review
Every figure is calculated from the Register as at the date shown (EX-11). Use them for the quarterly management report (EX-12). The fourth headline measure, unmitigated SoD conflicts, comes from the Segregation of Duties Conflict Matrix.
| As-at date | 28 Sep 2026 | Shows today. Type a fixed date to freeze a month-end review. |
Live exceptions by band
| Band | Live (open or expired) | Last month (enter) | Change | Expired | Expiring within 30 days | Chronic | Closed in the last 30 days |
|---|---|---|---|---|---|---|---|
| Low (score 1–3) | 1 | 0 | 0 | 1 | 0 | ||
| Medium (score 4–6) | 1 | 1 | 0 | 0 | 1 | ||
| High (score 8–9) | 1 | 0 | 1 | 0 | 0 | ||
| Critical (score 12–16) | 1 | 0 | 0 | 0 | 0 | ||
| All bands | 4 | 1 | 1 | 1 | 1 |
Headline measures
| Measure | Result | Target | Status | What it means | |||
|---|---|---|---|---|---|---|---|
| Open exceptions by band | 4 | Trend down; no unexplained rise in High or Critical | Enter last month | Live approved exceptions at month end, by Low, Medium, High and Critical. Compare with last month in the table above. | |||
| Expired exceptions — share of live | 25% | Below 5% | Action needed | Exceptions past their expiry date that are neither closed nor renewed, as a share of all open exceptions. | |||
| Expired exceptions — High or Critical | 0 | 0 | Meets target | Zero expired High or Critical exceptions; below 5% of all open exceptions expired. Report each to its approver on the first working day after expiry (EX-10). | |||
| Chronic exceptions | 1 | 0 | Action needed | Exceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits. Zero; each one reported by name: filter the Register's Chronic column and name each one in the report. | |||
| Requests decided within the band's decision time | 80% | 90% or more | Action needed | ≥ 90% of requests decided within the band's decision time, counted in working days from a complete request (EX-05). All decisions on the register, including renewals as last recorded. | |||
Needs attention
| Measure | Result | Target | Status | What it means | |||
|---|---|---|---|---|---|---|---|
| Expired for more than 10 working days | 1 | 0 | Action needed | Escalate to the next approval level up (EX-10). | |||
| Expiry date beyond the band's maximum | 1 | 0 | Action needed | Shorten to the Maximum allowed expiry (EX-06). | |||
| Renewed more than the band allows | 1 | 0 | Action needed | The next renewal goes to the next approval level up (EX-08). | |||
| Live exceptions whose compensating control is not tested and effective | 1 | — | Likelihood is not lowered for these (EX-07). Test the control or accept the higher score. | ||||
| Requests awaiting a decision | 0 | — | Each band has a decision time in working days from a complete request (EX-05). | ||||
| Rows with a record check to resolve | 3 | 0 | Action needed | Any row whose Record check does not say OK. | |||
Review record
| Item | Entry | ||||||
|---|---|---|---|---|---|---|---|
| Reviewed by | [[Name, role]] | ||||||
| Review date | [[YYYY-MM-DD]] | ||||||
| Scores changed, and why | [[e.g. EX-2026-004 likelihood raised: exploit published]] | ||||||
| Exceptions escalated, and to whom | [[e.g. EX-2026-002 to the Chief Operating Officer]] | ||||||
| Actions agreed, with owner and date | [[Action — owner — date]] | ||||||
| Items for the quarterly management report (EX-12) | [[e.g. chronic exceptions by name; every High and Critical exception]] | ||||||
Lists
| YesNo | Level | ExceptionType | Decision | Band | BandMinScore | BandDecisionDays | BandMaxDays | BandRenewals | BandApprover | Status |
|---|---|---|---|---|---|---|---|---|---|---|
| Yes | 1 | Policy or standard requirement | Approved | Low | 1 | 5 | 365 | 2 | Control owner | Requested |
| No | 2 | Segregation of duties conflict | Refused | Medium | 4 | 10 | 180 | 2 | Head of Information Security | Refused |
| 3 | High | 8 | 10 | 90 | 1 | Head of Information Security and the accountable executive (risk owner) | Open | |||
| 4 | Critical | 12 | 5 | 30 | 1 | The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | Expired |
Closed
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Security exception | An approved, time-limited decision to operate a system or process that does not meet a named requirement of a security policy or standard, with a named risk owner and, where possible, a compensating control. A waiver is the same thing under another name. |
| Exception ID | Your unique reference for the exception, such as EX-2026-004. It stays the same through every renewal. Not to be confused with rule numbers such as EX-06, which are the Standard's. |
| Exception type | Policy or standard requirement: a requirement of a security policy or standard is not met. Segregation of duties conflict: one person holds duties that should be separated and cannot be, accepted under SD-04 with a compensating control performed by someone without the conflict. |
| Policy or standard clause not met | The exact requirement the exception departs from, identified by document and section (or, for a conflict, the entry in the conflict matrix), so the deviation is tested against something specific. |
| Requester | The person who asks for the exception, runs the compensating controls and delivers the remediation plan. [[e.g. system owner, project lead]] |
| Risk owner | The accountable business executive for the affected service, who accepts the residual risk. [[the accountable business executive for the affected service]] |
| Control owner | The person who owns the requirement that is not met and confirms the compensating control works. [[e.g. IT Operations Manager]] |
| Impact | 1 Minor: affects one system of Standard criticality or non-sensitive data; no customer or regulatory effect. 2 Moderate: affects a High criticality system or internal confidential data; limited, recoverable disruption. 3 Major: affects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong. 4 Severe: could stop a core business service, expose sensitive data at scale, or breach a legal obligation. |
| Likelihood | 1 Unlikely: not reachable from the internet or by ordinary users; no known exploitation; strong compensating control in place. 2 Possible: reachable internally; exploitation needs skill or insider access. 3 Likely: reachable by many users or from partner networks; exploitation techniques are public. 4 Almost certain: internet-facing or known to be actively exploited, with no effective compensating control. |
| Compensating control | A measure that reduces the risk while the requirement is not met, such as isolating the system or reviewing a person's activity. It lowers likelihood by one step only when in place and tested; it never lowers impact (EX-07). |
| Compensating control last tested | The date the compensating control was last checked to be in place and working, by someone who can show evidence of it. |
| Score | Impact × likelihood with compensating control, 1 to 16, as set out in the Exception Risk Scoring & Expiry Model. |
| Band | Low: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16. The band sets the approver, the decision time, the maximum duration and the renewal limit. |
| Approver required | Who must approve an exception in this band (EX-05): Low — control owner; Medium — head of Information Security; High — head of Information Security and the accountable executive (risk owner); Critical — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management. |
| Request complete date | The day the request arrived with every field the Standard requires (EX-03). The decision time counts from here. |
| Decision | Approved or Refused. Blank while the request is being assessed. |
| Decision time (working days) | Working days (Monday to Friday) from the request complete date to the decision date. The band's limit, in working days from a complete request: Low 5, Medium 10, High 10, Critical 5. |
| First start date | The day the exception first took effect. It never changes, and it is the start for Days open in total. |
| Days open in total | Calendar days from the first start date to the closed date, or to the As-at date while live. For information: age alone does not make an exception chronic. |
| Expiry date | The day the present approval ends. From the day after, the exception is Expired unless closed. |
| Maximum allowed expiry | Decision date plus the band's maximum duration in calendar days (EX-06): Low 365 days, Medium 180 days, High 90 days, Critical 30 days. For a renewal, the renewal's approval date. |
| Renewal | A new approval for a further term, requested before expiry with an updated risk assessment and a progress report on the remediation plan (EX-08). |
| Renewal limit | The number of renewals the band's approver may grant: Low 2, Medium 2, High 1, Critical 1. A renewal beyond the band's limit goes to the next approval level up (EX-08). Above Critical, the next level up is [[the full board, or its equivalent]]. |
| Status | Requested: no decision yet. Refused: the request was turned down. Open: approved and within its term. Expired: past its expiry date and neither closed nor renewed; must be remediated, renewed or escalated within 10 working days (EX-10). Closed: no longer needed, with evidence (EX-13). |
| Reminder due | The exception expires within 30 days; the requester and risk owner must be reminded (EX-09). |
| Expired action | In grace period for up to 10 working days after expiry; Escalate after that. |
| Chronic | Exceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits. Shown only for live (open or expired) exceptions. |
| Closure evidence | What proves the exception is no longer needed: for example a scan, a configuration export or test result, the record of the system's retirement, or the formal revision of the requirement. A remediation plan marked complete is not enough (EX-13). |
| Record check | A calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding. |
| As-at date | The date every status and countdown is measured against. Set on the Monthly Review sheet; it defaults to today. |
| EXAMPLE row | A worked example showing how a completed row looks. Delete before approval. |
| EX-03, SD-04 … | Rule numbers in the Security Exception & Waiver Standard. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.36 — Compliance with policies, rules and standards for information security | The register as a whole: every departure from policy recorded, decided and time-limited |
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | Monthly Review sheet: measures and targets |
| NIST CSF 2.0 | ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated” | Score, band, approver, expiry and renewal columns |
| NIST CSF 2.0 | ID.RA-07 — “Changes and exceptions are managed, assessed for risk impact, recorded, and tracked” | The register as a whole: each exception assessed for risk, recorded and tracked to closure |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(c)(ii) and (iii) — ICT security policies record exceptions from their implementation and keep resilience assured while exceptions exist | The register as the record of exceptions, with their compensating controls |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774