Exception Register (Risk Acceptance)

Columns

ColumnPurpose
Exception IDe.g., EX-2025-004
Finding RefLink to item in SLA tracker
SeverityCritical / High / Medium / Low
ScopeService / image / env affected
JustificationWhy acceptance is necessary
Compensating ControlsWAF rule, feature flag, NetPol, monitoring
OwnerPerson/team managing risk
ApproverSecurity approver
ExpiryYYYY-MM-DD (hard stop)
StatusProposed / Approved / Expired / Revoked / Closed
Review NotesOutcome of periodic review

Rule: expired = revoked unless explicitly renewed.

CSV seed

Exception ID,Finding Ref,Severity,Scope,Justification,Compensating Controls,Owner,Approver,Expiry,Status,Review Notes
EX-2025-004,SCA-2025-014,High,ship/app-prod,"Upgrade blocked by vendor","WAF block + NetPol egress limit",alice,sec-lead,2025-11-15,Approved,"Review weekly"