Kean University DG – Exception Management (SOP) 14


Kean University DG – Exception Management (SOP) 14

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines the formal process for requesting, reviewing, approving, documenting, and monitoring exceptions to Kean University data governance and information security policies, standards, and SOPs.

Exceptions are permitted only when full compliance is not immediately feasible and must include documented risk analysis, compensating controls, and executive approval.

Scope

  • All University employees, contractors, vendors, and student workers
  • All University systems, applications, and data environments
  • All data classifications, including Internal, Confidential, and Restricted
  • Exceptions to policies, standards, and SOP requirements

Definitions

  • Exception – A formally approved, time‑limited deviation from a requirement
  • Compensating Control – A safeguard that reduces risk when compliance is not met
  • Risk Analysis – Assessment of security, privacy, operational, and regulatory risk
  • Exception Register – Official repository of approved exceptions
  • Expiration Date – Maximum duration of 12 months

Roles & Responsibilities

Requester

  • Submit exception requests with justification and risk details
  • Implement approved compensating controls

Manager

  • Validate business justification
  • Approve or reject exception requests

Data Owners

  • Confirm data classification impact
  • Review exceptions involving Confidential or Restricted data

Governance, Risk & Compliance (GRC)

  • Perform formal risk analysis
  • Maintain the Exception Register

Chief Information Security Officer (CISO)

  • Grant final approval or denial

Procedure

Step 1 — Initiate Exception Request

Requester submits justification, impacted requirement, risk details, duration, and compensating controls.

Step 2 — Manager & Data Owner Review

Business justification and classification impact are reviewed.

Step 3 — GRC Risk Analysis

Formal risk analysis and compensating control validation are completed.

Step 4 — CISO Approval

Final approval or denial is issued.

Step 5 — Register, Monitor, and Expire

Approved exceptions are logged, monitored, and expire within 12 months unless renewed.

  • KU DG 01 – Data Governance & Protection Policy
  • KU DG 02 – Data Access & Privacy Policy
  • KU DG SOP 11 – Logging, Monitoring & Alerting
  • KU DG SOP 12 – Data Incident Response
  • KU SEC 05 – Exception Management

Compliance Mapping

NIST CSF Function Category Subcategory
Identify ID.RA – Risk Assessment ID.RA01, ID.RA06
Protect PR.IP – Policy Implementation PR.IP01, PR.IP04
Detect DE.CM – Monitoring DE.CM01

Metrics & KPIs

  • Number of active exceptions
  • Percentage of exceptions with completed risk analysis
  • Percentage of exceptions expired on time
  • Average time to approve or deny requests

Required Records & Storage

  • Exception Register
  • Risk analysis documentation
  • Approval records
  • Compensating control evidence

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Governance, Risk & Compliance Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.