Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

GLOSSARY · Governance

Security exception (derogation)

A security exception, also called a derogation, is the formal decision to tolerate a known gap against a security policy or a control for a defined period, because fixing it is impossible or disproportionate for now. A valid exception names the asset and the control, the residual risk accepted, the compensating controls in place, the owner who accepts it at the right level of authority, and an expiry date at which it is either closed or re-decided.

Why exceptions are where posture is lost

The exceptions register is usually the least governed document in a security program and the first thing an auditor or a regulator asks for after an incident. An exception granted by email, without expiry, is a permanent hole nobody remembers agreeing to. Unpatchable medical devices, legacy industrial controllers, a supplier that cannot meet a contractual clause: each is legitimate as a time-boxed decision and dangerous as a forgotten one.

The lifecycle that makes them defensible

A governed exception moves through request, risk assessment, approval by the authority the residual risk requires (a team lead for low, the CISO for medium, the risk committee for high), active with compensating controls verified, then expiry with a forced re-decision: close, extend with a new date, or escalate. Every step is dated and attributable, so the register can answer “who accepted this, when, and on what basis” for any item at any time.

In the regulations

Neither NIS2 nor DORA uses the word derogation, but both require risk-management measures to be approved by management and assessed for effectiveness, and DORA explicitly expects documented risk acceptance for residual ICT risk. An exception is precisely that acceptance, and a register that shows the decision ladder and the expiry dates is what turns a policy gap from a finding into a governed risk.

ON MINDLAPSE

Where this term lives in the platform.

The pages that put the definition to work.

SEE IT VERIFIED

Definitions are the easy part. Proving them is the product.

Thirty minutes on your scope: risk, compliance, third parties, and how each term above becomes a verified control.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.