← SecurityX/CASP+: architecture and secure operations
01 / 8 · 45 MIN

Governance, risk, and exceptions

Turn findings into decisions with authority, criteria, and expiry.

Concept and mechanism

A security decision should connect the technical issue to the affected service and the authority allowed to accept risk. An analyst identifies evidence and recommends treatment; task ownership does not automatically confer risk acceptance authority. Distinguish policy, execution, and outcome: an access review policy does not demonstrate that reviews occurred or inappropriate access was removed. Evidence should identify scope, period, owner, and actions taken. Prioritize using exposure and process impact while preserving the distinction between technical severity and business context. The same flaw can require different schedules across services with different dependencies and tolerances.

Guided application

In a fictional funds project, the supplier delays a patch by six weeks. Prepare the exception with impact, temporary controls, residual risk, expiry, and exit condition. Approval of the original release date does not automatically authorize that new risk. The committee needs to choose treatment, bounded acceptance, or a changed plan. When using numbers, state assumptions: a loss of two hundred thousand euros per event and expected frequency of zero point two per year produces forty thousand euros annual expected loss in a simplified model. This is neither a certain loss forecast nor a substitute for uncertainty analysis. During follow-up, confirm controls remain active and someone is responsible for reassessing the exception before expiry.

IN PRACTICE

Exception: service, exposure, mitigation, owner, approval, expiry, and closure evidence.

Common pitfalls

Ticket owner as risk authority; policy as execution; average as forecast; exception without expiry.

Related topics: Suppliers, data, and threats · Resilience and recovery dependencies · Identity, zero trust, and cloud

Take this idea with you

A decision is complete when it can be executed, tracked, and reviewed.

Create account

Reference: Cybersecurity Framework 2.0 · CAS-005 / SecurityX V5; objectives 3.0; launched 2024-12-17