University of California (UC) systemwide and UC Merced Information security policies recognize that there are occasions where a system, device, or process, cannot be compliant with the policies as written and that alternative equivalent mitigations may be acceptable. There may also be occasions when mitigations may be inadequate to reach an equivalent level of protection, and risk acceptance may be required. UC Merced requires units to request a security exception when institutional information and/or IT resources (Data Protection Levels P1-P4) cannot comply with an information security policy or standard.
FREQUENTLY ASKED QUESTIONS
What Is a Security Exception?
A security exception is a permission to continue operating a system, service, or product that cannot comply with information security policies and standards. While exceptions to policies and standards may weaken protection of institutional information and IT resources, they are occasionally necessary.
When Should I Submit a Security Exception Request?
What Information do I need to Request a Security Exception?
Campus units must follow a risk-based approach when requesting an exception to the security controls. They must list the measures in place to mitigate risk (compensating controls) until they meet campus policies or standards. In the security exception request, units must explain:
- Why the exception is needed.
- For example, a Protection Level 2 (P2) operating system is end-of-life (EOL).
- Data from a Vendor has an unusual configuration that creates a vulnerability
- Critical Equipment cannot be replaced and needs to be secured
- What policy or standard they are requesting an exception from the operating system cannot comply with.
- For example, IS-3, 12.6: Technical Vulnerability Management and Patch Management.
- How any proposed compensating controls mitigate the security risks that this policy would otherwise address.
- For example, the unit will move the system behind a secure network segment or firewall and install Extended Detection & Response (XDR) software.
- The duration of the exception request.
- 1 Year Maximum
Units will also need the following information when submitting the request:
- Name and contact information for exception sponsor
- Name and contact information for Unit Head
- Name and contact information of Unit Information Security Lead (UISL)
- Data Protection Level Classification (P1-P4)
- Data Availability Level Classification (A1-A4)
- Applicable system, service, or product Information, such as:
- IP Address(es)
- MAC Addresses(es)
- Hostname(s)
- URL(s)
- Physical Location of System(s)/Device(s)
- Other Unique Identifiers
- Vendor-supplied technical information and documentation
The security exception will not be granted without the approval of both the Unit Head and the CISO. Additional approval from the Chief Information Security Officer (CISO) or a higher authority may be required if an exception poses an exceptionally high security, financial, reputational, and operational risk to the institution. The Information Security team may need to develop a Risk Treatment Plan (RTP) to address pre-identified risks in specific situations. For example, an RTP is needed for an outdated system that does not support the recommended anti-malware software and needs a long-term security exception until the system is upgraded, patched, or replaced.
How Do I Request a Security Exception?
Complete all the required fields in the Security Exception Request form. Once the form is submitted, a request ticket will be created and sent to the Information Security group.
What Happens After I Request a Security Exception?
- Information Security will review the request, determine a risk rating, and document any other relevant information for consideration.
- If additional information is needed, it will be requested in the comments of the ServiceHub ticket.
- The security exception sponsor, unit head, or data proprietor will review the information in the request, including the risk rating, and approve or reject the security exception.
- If the security exception is approved, subsequent tasks and reminders will be sent to manage the security exception lifecycle/resolution.
- The requester and units are responsible for meeting compliance by the exception expiration date.
- Reminders will be emailed to the requester, security exception sponsor, unit head, or data proprietor, and Unit Information Security Lead (UISL) 30 days, 15 days, and 1 day before the exception expiration date.
- If the security exception expires without renewal, the Information Security team will close the exception.
How Do I Request a Security Exception Extension?
- If the extension is approved, the security exception is valid for up to one additional year.
How Do I Ask Questions Not Answered Here?


