Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Security Exception Register

Maintains the authoritative record of every live deviation with owner, expiry and compensating control status.

Available soon

Format
Excel
Size
117 KB
Length
9 sheets
Version
1.1
Updated

What's inside

  • Instructions
  • Register
  • Monthly Review
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Monthly Review sheet. It shows today's date; type a fixed date over it to freeze a month-end review. Every status, countdown and flag uses this date.
2Add a row as soon as a complete request arrives on the Security Exception Request & Approval Form, and keep it whatever the decision: refused requests stay in the register (EX-11). Give it a unique Exception ID (for example EX-2026-012) and keep the same ID for the life of the exception, including renewals. A segregation-of-duties conflict that cannot be separated is recorded here too, with Exception type set accordingly (SD-04).
3Describe the exception in plain words: the title, the exact policy or standard clause that is not met, and the system or asset it applies to (use the ID from your asset register). Name the requester, the risk owner (the executive accountable for the affected service) and the control owner (who owns the requirement that is not met).
4Score it as the Exception Risk Scoring & Expiry Model does (EX-04): Impact 1–4 and Likelihood without compensating control 1–4. If the compensating control is in place and has been tested, enter the test date and set Compensating control effective to Yes: likelihood then drops one step, never more and never below 1 (EX-07). The Score, Band and Approver required columns calculate.
5Record the decision: Decision, Decided by and Decision date. Decided by must match the Approver required for the band (EX-05): Low (score 1–3) — control owner, decided within 5 working days from a complete request; at most 365 days; 2 renewals. Medium (score 4–6) — head of Information Security, decided within 10 working days from a complete request; at most 180 days; 2 renewals. High (score 8–9) — head of Information Security and the accountable executive (risk owner), decided within 10 working days from a complete request; at most 90 days; 1 renewal. Critical (score 12–16) — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management, decided within 5 working days from a complete request; at most 30 days; 1 renewal. Nobody decides their own request or an exception to a control they operate; the decision then passes to the next level up.
6For an approved exception, enter the First start date once and never change it, and the Expiry date. Maximum allowed expiry is the decision date plus the band's maximum duration (EX-06). On each renewal, overwrite Decided by, Decision date and Expiry date with the renewal's, and add one to Renewals; a renewal's expiry counts from its own approval date.
7Act on the flags: Reminder due appears 30 days before expiry — tell the requester and risk owner to close, renew or let it lapse (EX-09). An Expired exception must be remediated, renewed or escalated within 10 working days; after that, Expired action shows Escalate (EX-10). Over limit on Renewal check means the renewal goes to the next approval level up (EX-08).
8Close an exception only with evidence that it is no longer needed: enter the Closed date and describe the evidence in Closure evidence (EX-13). Do not delete closed or refused rows; they are the record.
9Every month, review the whole register and the Monthly Review sheet, record the review at the foot of that sheet, and carry the figures into the quarterly management report (EX-11, EX-12).
10Clear every Record check that does not say OK. Delete the EXAMPLE rows before the register is approved. Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Tailoring — small organisation: one person often requests, owns the requirement and runs security. That is workable, but nobody may decide their own request: if the approver for the band is the requester, the next level up decides. Record who actually signed in Decided by. The Exception & SoD Responsibility Matrix shows which role combinations are acceptable.

Tailoring — regulated entity (NIS2, DORA): add a column for the critical or important function each exception affects, keep month-end copies of this register (freeze the As-at date first) as records for supervisors and auditors, and report expired High and Critical exceptions to their approver on the first working day after expiry.

Tailoring — IT run by a service provider: exceptions the provider needs (for example an unsupported component in its service) are still raised and recorded here by your organisation. The provider may run the compensating control, but the risk owner and the person who decides are always people in your organisation.

Bands, approvers, decision times, maximum durations and renewal limits are read from the Lists sheet (Band, BandMinScore, BandApprover, BandDecisionDays, BandMaxDays, BandRenewals). If your approved Standard or Exception Risk Scoring & Expiry Model sets different values, change them there and nowhere else. Decision time counts working days from a complete request, excluding weekends but not public holidays.

Example rows use the template's revision date (2026-09-28) as their reference point, so their statuses change as the As-at date moves on. EX-2026-004 matches the exception on finding VF-0004 in the P01 Vulnerability Remediation Tracker example.

Register

One row per exception request, whatever the decision, from request to closure. Yellow columns are inputs; white columns calculate. Status colours always carry a text label.

ExampleException IDException typeTitlePolicy or standard clause not metSystem or assetRequesterRisk ownerControl ownerImpact (1–4)Likelihood without compensating control (1–4)Compensating controlCompensating control last testedCompensating control effectiveLikelihood with compensating controlScoreBandApprover requiredRequest complete dateDecisionDecided byDecision dateDecision time (working days)Decided on timeFirst start dateExpiry dateMaximum allowed expiryExpiry checkRenewalsRenewal limitRenewal checkClosed dateClosure evidenceStatusDays to expiryReminderWorking days since expiryExpired actionDays open in totalChronicRecord checkNotes
EXAMPLEEX-2023-006Segregation of duties conflictPayroll officer both maintains employee bank details and runs the payrollSegregation of Duties Conflict Matrix — payroll master data and payment run, rated HighPayroll system (AST-008)Payroll ManagerFinance DirectorFinancial Controller32Finance Director reviews the bank-detail change report against signed requests before each payroll run15 Jun 2026Yes13LowControl owner20 Mar 2026ApprovedFinancial Controller27 Mar 20265On time3 Apr 202326 Mar 202727 Mar 2027Within maximum32Over limitOpen1791274ChronicOver renewal limit — refer one level up (EX-08)Two-person payroll team. Renewed every year since 2023; the third renewal should have gone one level up (EX-08)
EXAMPLEEX-2026-002Policy or standard requirementSupplier remote support account without multi-factor authenticationRemote Access Standard §3.1 — multi-factor authentication for all remote accessWarehouse management system (AST-014)Logistics Systems LeadHead of LogisticsIT Operations Manager23Account enabled only for each agreed support session and disabled afterwards; sessions recordedNo36MediumHead of Information Security26 Jan 2026ApprovedHead of Information Security2 Feb 20265On time2 Feb 20261 Aug 20261 Aug 2026Within maximum02Within limitExpired-5841Escalate238Expired — remediate, renew or escalate (EX-10)Control never tested, so likelihood not lowered. Supplier's multi-factor roll-out slipped; no renewal requested before expiry
EXAMPLEEX-2026-004Policy or standard requirementPayroll application server on an unsupported operating systemVulnerability & Exposure Management Standard — remediation deadline for finding VF-0004Payroll application server (AST-007)Finance Systems LeadFinance DirectorIT Operations Manager43Server on its own network segment; only the payroll application port open, and only from finance workstations6 Jul 2026Yes28HighHead of Information Security and the accountable executive (risk owner)26 Jun 2026ApprovedHead of Information Security and Finance Director8 Jul 20268On time8 Jul 20266 Oct 20266 Oct 2026Within maximum01Within limitOpen8Reminder due82OKReplacement system due March 2027. Renewal request with a fresh risk assessment needed before expiry
EXAMPLEEX-2026-011Policy or standard requirementInternet-facing file transfer server awaiting the vendor's fix for an actively exploited flawVulnerability & Exposure Management Standard — Priority 1 remediation deadlineManaged file transfer server (AST-012)Digital Services ManagerChief Operating OfficerNetwork Manager44Web application firewall rule blocks the exploited request path; access limited to partner IP addresses16 Sep 2026Yes312CriticalThe board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management14 Sep 2026ApprovedExecutive Committee17 Sep 20263On time17 Sep 202631 Oct 202617 Oct 2026Beyond band maximum01Within limitOpen3311Shorten expiry to the band maximum (EX-06)Requested end date is past the Critical band's maximum; shorten it to the maximum and renew then if the fix is still not available
EXAMPLEEX-2026-005Policy or standard requirementWarehouse label printers use an unencrypted management protocolNetwork Security Standard §5 — encrypted management protocols onlyWarehouse label printers (AST-030)Logistics Systems LeadHead of LogisticsNetwork Manager23Printers on a separate network segment; management only from the IT administration network10 Apr 2026Yes24MediumHead of Information Security30 Mar 2026ApprovedHead of Information Security14 Apr 202611Late14 Apr 202611 Oct 202611 Oct 2026Within maximum02Within limit4 Sep 2026Printers replaced under CHG-2268; configuration export shows only encrypted management enabled; filed with the change recordClosed143OKDecided a day after the band's decision time

Monthly Review

Monthly register review

Every figure is calculated from the Register as at the date shown (EX-11). Use them for the quarterly management report (EX-12). The fourth headline measure, unmitigated SoD conflicts, comes from the Segregation of Duties Conflict Matrix.

As-at date28 Sep 2026Shows today. Type a fixed date to freeze a month-end review.

Live exceptions by band

BandLive (open or expired)Last month (enter)ChangeExpiredExpiring within 30 daysChronicClosed in the last 30 days
Low (score 1–3)10010
Medium (score 4–6)11001
High (score 8–9)10100
Critical (score 12–16)10000
All bands41111

Headline measures

MeasureResultTargetStatusWhat it means
Open exceptions by band4Trend down; no unexplained rise in High or CriticalEnter last monthLive approved exceptions at month end, by Low, Medium, High and Critical. Compare with last month in the table above.
Expired exceptions — share of live25%Below 5%Action neededExceptions past their expiry date that are neither closed nor renewed, as a share of all open exceptions.
Expired exceptions — High or Critical00Meets targetZero expired High or Critical exceptions; below 5% of all open exceptions expired. Report each to its approver on the first working day after expiry (EX-10).
Chronic exceptions10Action neededExceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits. Zero; each one reported by name: filter the Register's Chronic column and name each one in the report.
Requests decided within the band's decision time80%90% or moreAction needed≥ 90% of requests decided within the band's decision time, counted in working days from a complete request (EX-05). All decisions on the register, including renewals as last recorded.

Needs attention

MeasureResultTargetStatusWhat it means
Expired for more than 10 working days10Action neededEscalate to the next approval level up (EX-10).
Expiry date beyond the band's maximum10Action neededShorten to the Maximum allowed expiry (EX-06).
Renewed more than the band allows10Action neededThe next renewal goes to the next approval level up (EX-08).
Live exceptions whose compensating control is not tested and effective1—Likelihood is not lowered for these (EX-07). Test the control or accept the higher score.
Requests awaiting a decision0—Each band has a decision time in working days from a complete request (EX-05).
Rows with a record check to resolve30Action neededAny row whose Record check does not say OK.

Review record

ItemEntry
Reviewed by[[Name, role]]
Review date[[YYYY-MM-DD]]
Scores changed, and why[[e.g. EX-2026-004 likelihood raised: exploit published]]
Exceptions escalated, and to whom[[e.g. EX-2026-002 to the Chief Operating Officer]]
Actions agreed, with owner and date[[Action — owner — date]]
Items for the quarterly management report (EX-12)[[e.g. chronic exceptions by name; every High and Critical exception]]

Lists

YesNoLevelExceptionTypeDecisionBandBandMinScoreBandDecisionDaysBandMaxDaysBandRenewalsBandApproverStatus
Yes1Policy or standard requirementApprovedLow153652Control ownerRequested
No2Segregation of duties conflictRefusedMedium4101802Head of Information SecurityRefused
3High810901Head of Information Security and the accountable executive (risk owner)Open
4Critical125301The board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive managementExpired

Closed

Definitions

Definitions

TermMeaning in this workbook
Security exceptionAn approved, time-limited decision to operate a system or process that does not meet a named requirement of a security policy or standard, with a named risk owner and, where possible, a compensating control. A waiver is the same thing under another name.
Exception IDYour unique reference for the exception, such as EX-2026-004. It stays the same through every renewal. Not to be confused with rule numbers such as EX-06, which are the Standard's.
Exception typePolicy or standard requirement: a requirement of a security policy or standard is not met. Segregation of duties conflict: one person holds duties that should be separated and cannot be, accepted under SD-04 with a compensating control performed by someone without the conflict.
Policy or standard clause not metThe exact requirement the exception departs from, identified by document and section (or, for a conflict, the entry in the conflict matrix), so the deviation is tested against something specific.
RequesterThe person who asks for the exception, runs the compensating controls and delivers the remediation plan. [[e.g. system owner, project lead]]
Risk ownerThe accountable business executive for the affected service, who accepts the residual risk. [[the accountable business executive for the affected service]]
Control ownerThe person who owns the requirement that is not met and confirms the compensating control works. [[e.g. IT Operations Manager]]
Impact1 Minor: affects one system of Standard criticality or non-sensitive data; no customer or regulatory effect. 2 Moderate: affects a High criticality system or internal confidential data; limited, recoverable disruption. 3 Major: affects a Critical system, personal or customer data, or a regulated service; notifiable if it went wrong. 4 Severe: could stop a core business service, expose sensitive data at scale, or breach a legal obligation.
Likelihood1 Unlikely: not reachable from the internet or by ordinary users; no known exploitation; strong compensating control in place. 2 Possible: reachable internally; exploitation needs skill or insider access. 3 Likely: reachable by many users or from partner networks; exploitation techniques are public. 4 Almost certain: internet-facing or known to be actively exploited, with no effective compensating control.
Compensating controlA measure that reduces the risk while the requirement is not met, such as isolating the system or reviewing a person's activity. It lowers likelihood by one step only when in place and tested; it never lowers impact (EX-07).
Compensating control last testedThe date the compensating control was last checked to be in place and working, by someone who can show evidence of it.
ScoreImpact × likelihood with compensating control, 1 to 16, as set out in the Exception Risk Scoring & Expiry Model.
BandLow: score 1–3; Medium: score 4–6; High: score 8–9; Critical: score 12–16. The band sets the approver, the decision time, the maximum duration and the renewal limit.
Approver requiredWho must approve an exception in this band (EX-05): Low — control owner; Medium — head of Information Security; High — head of Information Security and the accountable executive (risk owner); Critical — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management.
Request complete dateThe day the request arrived with every field the Standard requires (EX-03). The decision time counts from here.
DecisionApproved or Refused. Blank while the request is being assessed.
Decision time (working days)Working days (Monday to Friday) from the request complete date to the decision date. The band's limit, in working days from a complete request: Low 5, Medium 10, High 10, Critical 5.
First start dateThe day the exception first took effect. It never changes, and it is the start for Days open in total.
Days open in totalCalendar days from the first start date to the closed date, or to the As-at date while live. For information: age alone does not make an exception chronic.
Expiry dateThe day the present approval ends. From the day after, the exception is Expired unless closed.
Maximum allowed expiryDecision date plus the band's maximum duration in calendar days (EX-06): Low 365 days, Medium 180 days, High 90 days, Critical 30 days. For a renewal, the renewal's approval date.
RenewalA new approval for a further term, requested before expiry with an updated risk assessment and a progress report on the remediation plan (EX-08).
Renewal limitThe number of renewals the band's approver may grant: Low 2, Medium 2, High 1, Critical 1. A renewal beyond the band's limit goes to the next approval level up (EX-08). Above Critical, the next level up is [[the full board, or its equivalent]].
StatusRequested: no decision yet. Refused: the request was turned down. Open: approved and within its term. Expired: past its expiry date and neither closed nor renewed; must be remediated, renewed or escalated within 10 working days (EX-10). Closed: no longer needed, with evidence (EX-13).
Reminder dueThe exception expires within 30 days; the requester and risk owner must be reminded (EX-09).
Expired actionIn grace period for up to 10 working days after expiry; Escalate after that.
ChronicExceptions renewed more than their band allows (EX-08), so the gap has outlived every renewal the Standard permits. Shown only for live (open or expired) exceptions.
Closure evidenceWhat proves the exception is no longer needed: for example a scan, a configuration export or test result, the record of the system's retirement, or the formal revision of the requirement. A remediation plan marked complete is not enough (EX-13).
Record checkA calculated prompt showing the first missing or inconsistent item on the row. OK means nothing is outstanding.
As-at dateThe date every status and countdown is measured against. Set on the Monthly Review sheet; it defaults to today.
EXAMPLE rowA worked example showing how a completed row looks. Delete before approval.
EX-03, SD-04 …Rule numbers in the Security Exception & Waiver Standard.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.36 — Compliance with policies, rules and standards for information securityThe register as a whole: every departure from policy recorded, decided and time-limited
ISO/IEC 27001:2022Clause 9.1 — Monitoring, measurement, analysis and evaluationMonthly Review sheet: measures and targets
NIST CSF 2.0ID.RA-06 — “Risk responses are chosen, prioritized, planned, tracked, and communicated”Score, band, approver, expiry and renewal columns
NIST CSF 2.0ID.RA-07 — “Changes and exceptions are managed, assessed for risk impact, recorded, and tracked”The register as a whole: each exception assessed for risk, recorded and tracked to closure
DORA — Delegated Regulation (EU) 2024/1774Article 2(2)(c)(ii) and (iii) — ICT security policies record exceptions from their implementation and keep resilience assured while exceptions existThe register as the record of exceptions, with their compensating controls

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774