What needs a decision
A fund migration project can finish within budget while leaving an exposure without an owner. To prevent this separation, express the security decision as a concrete choice: which service may operate, under what conditions, for how long and with what consequence if those conditions fail. Distinguish the security lead’s recommendation from acceptance by the person authorized to own the business risk. In this lesson, internal delegation allows the service owner to accept only exposures within approved tolerance. This rule is a teaching assumption, not a description of a particular bank’s governance.
A decision record that can be acted on
The record should identify the service and data in scope, the reason for the exception, alternatives considered, temporary controls, evidence of operation, risk owner, execution owner, expiry and reassessment triggers. An “approved” field does not answer these questions. Consider a 30-day exception for an old interface, conditional on daily access review. APS needs to know who performs that review on Saturday, where evidence is kept and who is contacted if it is missing. The owner’s absence requires a suitably authorized deputy, not a shared account or a copied signature.
A total does not describe the dependency
Three projects submit different exceptions for the same identity platform. Counting three separate approvals hides the fact that its failure could affect all three services simultaneously. Link the records to the shared dependency and build a cross-service scenario with identified consequences and owners. Do not add probabilities as though they represented independent losses, or remove local records: each team remains responsible for its conditions. The committee may discover that a central repair reduces exposure across several projects, while three local solutions duplicate costs and retain the same failure point.
Scope changes and expiry
Before expiry, request evidence of remediation or a justified new decision. Automatic renewal turns a temporary arrangement into permanent acceptance that may never have been authorized. Review should also occur when a relevant condition changes: new connectivity, more sensitive data, monitoring failure or delayed retirement. In the exercise, adding a settlement application puts the risk beyond delegated authority. The manager prepares options and escalates to the designated authority while retaining already authorized containment actions. Escalation does not mean suspending every useful measure while waiting for a meeting.
Committee exercise and summary
Prepare a five-line committee brief: affected service; condition no longer met; exposure and uncertainty; feasible options with costs and dates; requested decision and owner. Use this case: the daily control was missed for two days, the exception has ten days remaining and migration can be delayed by one week. The conclusion must separate calendar validity from compliance with conditions. A sound answer proposes reviewing access during the uncovered period, restoring coverage and requesting an operating or deferral decision under delegated limits. It does not claim an attack occurred without evidence.
Three exceptions depend on the same directory. The committee receives a combined exposure view while retaining separate owners for each service.
Common pitfalls
Treating an unexpired date as an effective control; renewing through silence; confusing project sponsorship with risk authority; adding dependent scenarios as if independent.
Related topics: Risk acceptance · Shared dependencies
An exception is a conditional, monitored decision. Its scope, authority and evidence must remain valid throughout operation.
Reference: The NIST Cybersecurity Framework 2.0 · CISM current outline before November 3, 2026