Concept and mechanism
An urgent change may require accelerated steps, but the emergency path should state who may authorize, under which criteria, and how records are preserved. Coordinate with the incident process so recovery and change do not create incompatible instructions. Make performed tests, deferred checks, known risk, and follow-up actions explicit. An accepted exception needs understood scope; it does not authorize additional changes without review. If implementation deviates from the plan, record actual state and consult appropriate authority before assuming original approval covers the new path. The objective is responding to urgency with informed, traceable decisions.
Guided application
In a fictional example, an urgent fix resolves an application blocker but needs an additional temporary permission. The team wants to keep it active for future convenience. Separate the immediate need from permanent configuration. Agree who reviews the permission, when it should be removed, and how return to authorized configuration is confirmed. Rollback must also consider data and dependencies: restoring the application can be insufficient if the schema changed. Confirm recovery criteria, flow validation, and reconciliation before closure. When tests are accelerated or deferred through the emergency process, retain owners and dates for completing required evidence.
A temporary permission needs an owner and a removal criterion.
Common pitfalls
Urgent treated as exempt; unbounded exception; forgotten temporary configuration; rollback without data considerations.
Related topics: Mandate, models, and authorization · Impact, dependencies, and calendar · Evidence, artifacts, and controls
Make the exception explicit and track recovery and residual work.
Reference: SP 800-128 full publication · NIST SP 800-128 updated October 2019; DORA five-metric model and change approval guidance; vendor documentation inspected 2026-10-01