ZenGRC

Risk Exception Management Process: How to Manage Non-Compliance

The Risk Exception Management Process addresses situations where organizations cannot fully comply with policies or security standards—such as working with non-compliant vendors or missing security patches—by distinguishing between risk exceptions, security exceptions, and risk acceptance, and emphasizes managing these risks through formal documentation, risk analysis, and appropriate mitigation strategies within an overall risk management program.

Risk Exception

In day-to-day operations, organizations often encounter situations that violate established policies and procedures. A risk exception occurs when a particular policy, standard, security program requirement, or security best practice cannot be fully implemented.

For example, an organization might make an exception to do business with a third-party vendor who isn’t fully compliant with laws, policies, or regulations. Granting such an exception can have consequences and may expose the organization to risk.

Risk Exception vs. Security Exception and Risk Acceptance

A security exception is a type of risk exception that specifically pertains to information security and cybersecurity. Security exceptions are made when a condition does not align with formal security expectations as defined by policy, standard, or procedure—such as a missing patch.

A security exception is fundamentally a question of compliance, which may or may not represent an excessive level of risk.

Risk acceptance, on the other hand, is a formal and documented decision by a stakeholder to not remediate a level of risk that exceeds the organization’s risk appetite or risk tolerance. Risk acceptance is not always the result of a security exception. For example, a missing patch may not represent much risk, or the risk associated with applying the patch might outweigh the risk of not applying it. Sometimes, a risk analysis may show significant risk even if a security exception is not required.

Risk acceptance is part of risk mitigation and is one potential option for determining the appropriate risk response or treatment. Other treatments include risk avoidance, risk transfer, or risk reduction.

Risk Exception Management

Avoiding risk altogether is almost impossible, so it’s best to implement systems to manage it. An organization’s overall risk management program should aim to minimize the impact of risks before they materialize as threats, incidents, or events. The steps of risk management include:

  • Risk assessment
  • Risk analysis
  • Risk evaluation and prioritization
  • Risk treatment and mitigation
  • Risk monitoring and review

Vulnerability management programs identify, classify, prioritize, and mitigate cybersecurity vulnerabilities, often found in software and networks. Vulnerabilities can include open ports, poorly written code, unpatched applications, and dependencies on insecure libraries.

Making risk exceptions can complicate both risk management and vulnerability management programs by exposing the organization to otherwise avoidable risk.

If a risk exception is made, a risk exception management program should be implemented as part of the risk management program. This helps determine the potential impact and likelihood that the resulting risk could be exploited.

A risk exception management program helps organizations identify and evaluate risk exceptions consistently, recognize areas of non-compliance, and determine whether there is risk for malicious activity or fines and penalties due to non-compliance.

Non-compliance can result in legal penalties, fines, business loss, and reputational loss.

If a risk exception results in non-compliance, the risk exception management program should include methods for managing policy exceptions.

Policy Exceptions

A policy exception allows an individual or entity to circumvent one or more restrictions while maintaining the policy. For example, if a vendor cannot meet a certain information security policy, the organization must decide whether the risk of making an exception is greater than the potential loss from not doing business with that vendor.

If a business or vendor fails to fulfill policies, it should submit a policy exception request form. The chief information security officer (CISO) can approve or deny the request based on the risk it poses.

Strategies for granting policy exception requests within a risk exception management program include:

  • Attach conditions to the policy exception request. Granting a policy exception adds risk, so it is important to attach conditions, such as limiting the exception’s validity period or adding disclosure requirements to contracts.
  • Monitor exceptions to manage risk. Each risk exception adds risk, so treat each as a special case requiring attention. Ongoing monitoring and periodic assessments should be part of the program.
  • Regularly review and update company policies. Reviewing exception requests may reveal the need to update or create new policies. A concentration of exception requests for a specific policy indicates it should be reviewed. Policies should be reviewed annually to ensure they are defined, updated, and clear to users, helping manage risk and protect the organization.

Risk Exception and GRC

For some organizations, managing policy exceptions can be handled manually on a case-by-case basis. However, the risk exception process is often more complex and demanding.

A governance, risk, and compliance (GRC) platform can help process exceptions through multiple approval workflows, provide risk scoring, and present data for a holistic view of risks associated with exceptions.

ZenGRC is a compliance, risk, and workflow management software that offers an intuitive platform to track workflows and identify areas of high risk before they become real threats. It provides a flexible platform to fit unique program requirements, including integration with ServiceNow for efficiency, streamlined processes, and centralized metrics reporting and insights.

ZenGRC comes pre-loaded with content and templates, and offers onboarding support from industry experts. The platform aims to simplify information security risk and compliance management, and foster transparency and trusted relationships with stakeholders.