KU SEC 05 - Exception Management Policy


Exception Management Policy

Table of Contents

1. Overview

When technology, operations, or business needs prevent someone from meeting a required Kean University security control or policy, an Exception Management Process must be followed. This ensures all exceptions are:

  • Properly reviewed
  • Time‑limited
  • Risk‑assessed
  • Documented and monitored

This policy inherits its authority from university governance standards and must follow all applicable compliance requirements.

2. When This Policy Applies

This policy applies when a person, team, vendor, or system cannot meet a required security control or policy. Examples include:

  • Security controls that cannot be implemented
  • Technical standard exceptions
  • Configuration exceptions
  • Vendor or contract exceptions

It applies to:

  • Faculty, staff, and student employees
  • Contractors and vendors
  • Anyone requesting an exception

3. What Systems and Data Are Covered?

This policy covers all Kean systems and environments, including:

  • On‑premises and cloud systems
  • Identity and access systems
  • Research systems
  • Administrative systems

It applies to all data classifications:

  • Public
  • Internal
  • Confidential
  • Restricted (e.g., FERPA, GLBA, research‑controlled data)

4. Key Requirements for Exceptions

Expand Key Requirements

4.1 Submitting an Exception

All exceptions must be submitted through the official Exception Request Form and must include:

  • Business justification
  • Risk analysis
  • Proposed compensating controls
  • Requested duration (maximum 12 months)

4.2 Review & Approval

Exceptions are reviewed by:

  • Kean IT – Information Security (ISO)
  • Data Owners (if applicable)
  • CIO (for high‑risk exceptions)

Exceptions involving regulatory requirements require Legal & Compliance approval.

4.3 Documentation & Tracking

  • All approved exceptions must be logged in the Exception Register.
  • Information Security performs quarterly reviews to ensure accuracy.

4.4 Expiration & Renewal

  • Exceptions expire after no more than 12 months.
  • Renewal requires a new submission and updated risk analysis.
  • Renewals must be submitted at least 30 days before expiration.

4.5 Compensating Controls

Compensating controls are alternative safeguards used when a required control cannot be implemented. All exceptions must include compensating controls.

4.6 Regulatory Safeguards

Exceptions must not weaken requirements such as FERPA, GLBA, or HIPAA unless approved by Legal & Compliance.

5. Roles & Responsibilities

Expand Roles & Responsibilities

Requestor

  • Submit exception requests
  • Provide business justification and risk analysis

Kean IT – Information Security (ISO)

  • Validate risk analysis
  • Recommend compensating controls
  • Maintain the exception register
  • Conduct quarterly reviews

CIO

  • Approve high‑risk exceptions
  • Ensure compliance with security and regulatory requirements

Data Owners

  • Approve exceptions involving their systems or data

Internal Audit

  • Validate compliance during audits

Vendors

  • Follow Kean’s exception process for contract deviations

6. Enforcement

Not following this policy may result in corrective action, including written warnings, mandatory training, loss of access, or HR/legal action for severe violations.

  • RC01 – Policy Governance Standard
  • KU SEC 10 – Cybersecurity & IT Governance Standard
  • Information Security Policy
  • Risk Management Policy
  • Data Classification Policy
  • Access Management Policy
  • Incident Response Plan
  • Exception Request Form (IT Service Portal)

8. Review & Maintenance

This policy is reviewed annually by Information Security and Internal Audit, or sooner if regulations, risks, or technologies change.

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.