Home > Blog > ISACA Certified Information Security Manager > Managing Security Exceptions and Waivers for CISM

Managing Security Exceptions and Waivers for CISM

Deep Dive Cert Sensei Team 2030-11-24 8 min read

Security exceptions and waivers are formal approvals to bypass specific security controls when business needs outweigh the risk. Within information security governance, these must be documented, time-bound, and mitigated with compensating controls to ensure risks are consciously accepted by senior management rather than ignored or forgotten.

#CISM #Information Security Governance #Risk Management #ISACA #Security Compliance

What is a security exception and why does it matter for governance?

In a perfect world, every single policy and standard would be followed to the letter. In the real world, business requirements often clash with rigid security controls. This is where security exceptions and waivers come in. From an information security governance perspective, an exception isn't just 'letting something slide'—it's a formal, documented decision to deviate from a policy for a specific reason and a specific period.

If you're studying for the CISM, you need to understand that governance is about alignment. When a business unit cannot meet a security requirement—perhaps due to a legacy application that doesn't support MFA—the governance framework must provide a way to handle this without creating a 'shadow' security posture. Without a formal process, you end up with undocumented risks that will eventually haunt you during an audit or, worse, during a breach.

How do you build a robust exception request process?

A professional exception process should never be a casual email to the CISO. It needs to be a structured workflow. First, the requester must define the business justification—why is this exception necessary for the organization to function? Second, a formal risk assessment must be conducted to determine the impact of bypassing the control. You aren't just asking for permission; you're quantifying the risk.

Once the risk is understood, it must be routed to the appropriate risk owner. A common CISM exam trap is suggesting that the CISO or the security team should approve the exception. Remember: the security team identifies the risk, but the business owner—the person who owns the budget and the process—is the one who must accept the risk. This ensures accountability is placed where the business value resides, not just on the technical staff.

What are compensating controls and when should you use them?

You should rarely grant a 'naked' exception. Whenever possible, you want to implement compensating controls. These are alternative measures that provide a similar level of protection as the original control, even if they don't meet the exact policy specification. If you can't encrypt a legacy database (the primary control), a compensating control might be to isolate that database on a strictly controlled VLAN with aggressive monitoring and restricted access.

When documenting these in your governance framework, be specific. Don't just say 'we will monitor it.' Say 'we will implement daily log reviews of all administrative access to the legacy server.' This level of detail is what auditors look for and what separates a junior analyst from a CISM-certified manager. It proves that while the primary control is missing, the risk is being actively managed rather than simply ignored.

Why are expiration dates critical for security waivers?

The most dangerous phrase in security is 'temporary fix.' Without a hard expiration date, a temporary waiver becomes a permanent vulnerability. Every exception must have a sunset clause—typically 6 to 12 months—after which the exception must be re-evaluated, renewed, or remediated. This forces the business to keep looking for a permanent solution rather than settling for the easy path.

During the renewal process, the risk owner must re-justify the need for the exception. If the business reason no longer exists, the exception is revoked, and the control must be implemented. This lifecycle management is a core component of information security governance, ensuring that the organization's risk profile doesn't bloat over time due to accumulated 'temporary' permissions that were forgotten by the original requestors.

How do you track and audit accepted exceptions effectively?

You cannot manage what you cannot measure. All exceptions must be recorded in a centralized Exception Register or a GRC (Governance, Risk, and Compliance) tool. This register should track the requester, the risk owner, the expiration date, the compensating controls, and the date of the last review. This becomes your primary evidence during an ISACA or internal audit to prove that the organization is operating under a controlled governance model.

To truly master this domain, you need to practice applying these concepts to complex scenarios. At Cert Sensei, we offer 1,000 expert-curated CISM practice questions that dive deep into these governance nuances. Our platform provides detailed expert reasoning for every answer and domain-level analytics, so you can see exactly where your gaps are—whether it's in risk management or governance—before you sit for the actual exam.

Who should actually be responsible for approving a security waiver?

This is a critical distinction for the CISM exam: the difference between the 'Risk Advisor' and the 'Risk Owner.' The CISO and the security team act as advisors; they provide the technical expertise to explain why a control is necessary and what happens if it's missing. However, the authority to approve a waiver must lie with the individual who owns the business process and accepts the potential loss associated with the risk.

If a VP of Operations wants to bypass a security check to speed up production, they are the ones who must sign off on the waiver. If a breach occurs because of that exception, the accountability rests with the VP, not the security team. This structure prevents the security department from becoming a 'rubber stamp' and ensures that business leaders are making informed decisions about the trade-off between operational speed and organizational security.

❓ Frequently Asked Questions

Can the CISO approve a security exception if the risk is low?

Generally, no. While the CISO may provide a recommendation, the business owner who owns the risk should provide the final approval. This maintains proper governance and ensures that the person responsible for the business outcome is also responsible for the risk.


What happens if a business owner refuses to sign a waiver for a high risk?

If the risk owner refuses to accept the risk, the control must be implemented regardless of the operational impact. If the conflict cannot be resolved, it should be escalated to the steering committee or senior executive leadership for a final decision.


Is a security waiver the same as a risk acceptance?

They are closely related, but a waiver is specifically the formal permission to deviate from a policy or standard. Risk acceptance is the broader decision to live with a risk without further mitigation. A waiver is often the mechanism used to document that risk acceptance.

More from ISACA Certified Information Security Manager

🧠

Test Your Knowledge

Ready to practice Certified Information Security Manager? Put what you've learned to the test.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium
📖 Browse the Glossary

Join thousands of certification students

Sign Up Free