Exceptions
An exception records a deliberate, approved deviation from a control, a policy or a requirement: the legacy server that cannot take the current TLS baseline, the contractor laptop outside MDM, the quarterly review skipped during a migration. Documenting it turns an invisible gap into a governed one — with a reason, an owner, an approver and, crucially, a date on which it stops being acceptable.
Where to find it
Section titled “Where to find it”Governance → Exceptions in the sidebar.
Key concepts
Section titled “Key concepts”Fields
Section titled “Fields”Each exception carries a Reference ID and Name, a Description of what is being deviated from and why, a Severity on the shared scale — undefined, info, low, medium, high, critical — used to prioritise follow-up, an Expiration date marking when the exception no longer applies, one or more Owners responsible for closing it, an Approver who authorised it, an Observation field for review notes, Evidences substantiating the case, and an external Link.
Status lifecycle
Section titled “Status lifecycle”| Status | Meaning |
|---|---|
| Draft | Being written up, not yet submitted |
| In review | With the approver |
| Approved | Authorised and in force |
| Rejected | Declined; the deviation is not sanctioned |
| Resolved | The underlying gap has been closed |
| Expired | The expiration date has passed |
| Deprecated | Superseded or no longer relevant |
Prefer Resolved or Deprecated over deletion: the record of what was tolerated, by whom, and for how long is often exactly what an assessor asks to see.
What an exception attaches to
Section titled “What an exception attaches to”An exception is not a free-floating note — it points at the thing it excuses. Exceptions can be linked to assets, applied controls, vulnerabilities, risk scenarios and requirement assessments. That link is what lets a non-conforming requirement in an audit, or an unpatched vulnerability past its SLA, carry a visible, approved reason instead of looking like neglect.
Working with exceptions
Section titled “Working with exceptions”Create one with Add exception, set its domain, severity and expiration date, then attach it to the objects it covers. The list supports search and filters by severity, status, owner and domain, so the standing question — which approved exceptions expire this quarter, and who owns them — is one filter away.
Exceptions roll up into reporting: the analytics dashboard breaks the population down by status, and per-audit analytics show which requirements in that audit are covered by an exception.
Related
Section titled “Related”- Risk acceptances — the formal decision to tolerate a whole risk scenario, with its own approval workflow.
- Applied controls — what an exception typically deviates from.
- Vulnerabilities — link an exception to a weakness you cannot fix inside the SLA.
- Audits — where an exception explains a non-conforming requirement.
