H.8.4 Policy Exceptions

Reading progress1 missing

1 required article is still unread. Reading it first is recommended, but not required.

Article in preparation — showing conspect notes

An exception is a governed temporary state, not an invisible second architecture.

  • Record owner, exact scope, reason, risk, compensating control, evidence, approval, expiry, and review date.
  • Make exceptions discoverable beside the standard and affected code or service.
  • Distinguish a temporary migration waiver from a permanent supported variant.
  • Aggregate repeated exceptions to identify a broken standard, missing platform capability, or unmanaged domain difference.
  • Expire, renew with fresh evidence, convert to a supported path, or remove the exception explicitly.