# Exception Governance

Time-boxed risk-acceptance recording and the separation-of-duties boundary for exception approval.

- A policy exception is a time-boxed, owned, compensated risk acceptance (POA&M), not a way to ignore a policy.
- Self-approval of an exception violates separation of duties; the approver must be a distinct, authorized owner.
- An expired exception, or one missing a compensating control, is a finding, not a status quo.

## Sources

- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
- https://www.iso.org/standard/27001
- https://csrc.nist.gov/glossary/term/separation_of_duty
