Views
3 years ago

3502 - Information Security Exception Request - The DCS Service ...

3502 - Information Security Exception Request - The DCS Service ...

3502 - Information Security Exception Request - The DCS Service

ProcedureInformation Security Exception RequestOwner:Operations – Security Management ServicesNumber:3502Issue Date:5/12/2008Revised Date:7/1/2013DistributionAll employeesOwnershipThe California Department of Technology (CalTech), Office of Technology Services (OTech),Security Management Section (SMS), is responsible for ensuring this document is necessary,reflects actual practice, and supports organization policy. This document was lastreviewed/updated in July, 2013.Section 1 – IntroductionThe SMS published information security policies and multiple supporting security standards andprocedures to ensure a safe and secure working environment for its customers, visitors, andemployees. These security policies and procedures were written to directly reflect the position ofthe CalTech Information Security Office; they should be adhered to by customers, visitors, andemployees. The SMS is aware that exceptions can occur from time to time. This documentexplains the exception request procedure for an SMS policy or procedure.Section 2 – Exception Request ProcedureA. Exception QualificationThe exception request procedure should be followed if either of the criteria belowapplies.1. The security policy or procedure in question cannot be adhered to for unforeseenreasons outside of your control.2. In working closely with the SMS, alternative solutions have been exhausted andare not possible.B. Exception Request ProcedureInformation security policy or procedure exception requests must be linked to an existingService Request. The following procedure begins when a customer or employee has anexception request to a published security policy or procedure:1. An SMS representative provides risk assessment and alternativerecommendations to the requester’s Information Security Officer (ISO); doing somay involve more CalTech subject matter experts.2. The requester’s ISO either accepts or declines the assessment and alternativerecommendations.a. If the requester’s ISO accepts, the SMS works with the customer tore-architect the issue to mitigate security risk(s). The exception isterminated and efforts continue.Page 1 of 2

And WHAT? Of Requesting Exceptions and ACRs - Texas ...
Requests for information - Health Care Compliance Association
Information Security and Service Management for better business ...
NET-Centric Information & Integration Services for Security System
United States EU Japan China India and Southeast Asia Information Technology (IT) Security as a Service Market Size Status and Forecast 2021
Request for Security Policy/Procedures Exception - Information ...
Investigational Drug Services Exception Request - Emory University
Security Exception Request Form
The Exception Process - Information Technology and Services
General Exception Request Form - Office of Compliance Services
Reviews, Appeals and Requests for Exceptions - NAIA
Request Zoning Exception - Columbia County Schools
Therapy CAP Exception Preapproval Request
excepted service – merit pay plan administration - News Room, DC
Worksheet for Requesting Exceptions To The Diversion Law (SB 859)
Service Request information Sheet - Shared Services SA - SA.Gov.au
Information Technology Services STS-06 Security Services Request ...
Request for Social Security Earnings Information
Exceptional Item Request - Texas General Land Office
Commissioning policy for exceptional treatment requests - National ...
policy on dealing with requests for information - Security Industry ...
Request for Visit (RFV) Form - Defense Security Service
ELIGIBILITY EXCEPTION REQUEST - CYO Camp Howard
Appendix B - Requests for Exception to the NDP - Avanco ...
Request for absence in exceptional circumstances - Warden Park ...
NoT MD04 Individual exceptional treatment requests - Medlaw
Guidelines for Requesting an Exception to Policy for H1-B Visa
Server Vulnerability Scan Guideline - The DCS Service Catalog
rfp 2005-01 request for proposal for security services