Skip to content

Cybersecurity planning

Keep temporary security exceptions connected to a review date

A temporary exception can become a permanent arrangement when nobody owns its review.

A temporary exception can become a permanent arrangement when nobody owns its review. A clear record helps the organization revisit the business need and the controls approved for that situation.

Describe the reason

State the business activity, affected systems, and reason the normal process cannot currently meet the need. Have the appropriate security and business owners review the request. Keep the discussion specific rather than treating schedule pressure as a general reason to bypass established approval requirements.

Record the authorized decision

Document the approved scope, responsible owner, review date, and any conditions set by the qualified decision-makers. Keep technical controls and sensitive details in the designated records. Make the exception visible to the people who maintain the affected service without distributing unnecessary security information broadly.

Return to the original purpose

At review, ask whether the business need still exists and whether the normal process can now support it. Record the authorized decision to close, change, or continue the exception. Update dependent operating instructions so the approved status is reflected in the work people actually perform.

Practical takeaway

A review date is useful only when someone owns the decision. Keep temporary exceptions bounded, authorized, and connected to a business purpose that can be reassessed.

Related services

Further reading