All lessons Leer en español

Security in depth · Unit 23 · Lesson 13 of 14

Exceptions need an end condition

Distinguish an expired approval from a control that was actually restored.

4 minreadyShort lesson

Helpful before thisDefenses and detection

See all lessons in this topic

After this lesson you can

  • Choose a defensible status when an exception expires but its configuration remains active.

A date can end permission without changing a setting.

Give temporary decisions an exit

A security exception is an explicitly approved deviation from a required control, limited by recorded scope and review conditions. It should identify the reason, accountable owner, temporary protections, and the route to restoration or reassessment. An exception is neither a permanent permission nor evidence that its risk disappeared.

Assume a fictional archive temporarily permits a legacy client while replacing it. Approval X4 applies to one named application until the end of day ten. The policy requires the owner to verify restoration before closing the technical work item.

Justified exception → Owner and review → Control restoredJustified exceptionOwner and reviewControl restored
The final node is a verified closure objective. Expiry and review do not automatically restore the control.

Supplied exception record

  • X1: X4’s owner is the application manager; temporary access is limited to a small approved user group.
  • X2: The replacement is delayed. No extension has been approved.
  • X3: On day twelve, the configuration review still shows the legacy allowance. The scheduled removal job reported failure.

Track two states honestly

The approval has expired, while the technical deviation remains. Calling the issue fixed because the date passed would conceal X3. Calling it automatically renewed because work is delayed would invent authorization.

The owner needs prompt coordination with the responsible risk authority: restore the intended control through the approved change process, or obtain an explicit, time-limited decision about the remaining deviation. Record its scope and temporary measures if a new exception is approved.

Closure should include the effective configuration and evidence that required legitimate work still functions. A completed ticket or removal-job schedule alone cannot establish those outcomes.

Model status: Approval expired on day ten. Legacy allowance observed on day twelve; restoration and closure verification remain outstanding.

Terms you met

Security exception

Check yourself

No timer. No penalties. Read the explanation and try again whenever you like.

  1. How should X4 be recorded on day twelve?

    Show the answer

    Correct answer: Approval expired; the technical deviation remains, requiring prompt owner action and an authorized decision. The date ended permission but did not change configuration. Technical closure requires verified restoration. A new exception changes approval status while the deviation remains.

Try it

  • WriteWrite a status update for X4: approval state, observed configuration, responsible role, and closure evidence. Model the distinction as approval expired; technical deviation still present.
References