Information Security Exception Procedure
Library and Technology Services – Information Security Office Last Revised: March 2026
Purpose
This process allows Lehigh University community members to request an exception to established information security policies and standards when necessary for legitimate business or academic purposes. Exceptions are granted only when compliance is infeasible or creates an undue hardship, and when sufficient compensating controls are in place.
Important Considerations
Exceptions are not automatically granted.
All exceptions are temporary and must include an expiration date.
The requester must demonstrate the necessity of the exception.
All exceptions must be documented and tracked by the Information Security Office.
Scope
This process applies to all Lehigh University community members subject to established information security policies and standards when necessary for legitimate business or academic purposes. Exceptions are granted only when compliance is infeasible or creates an undue hardship, and when sufficient compensating controls are in place.
Procedure
3.1 Submit a Request
Exception requests must be submitted through the Information Security Exception Request form in the LTS Help Center (Jira Service Management portal). Requests submitted outside this channel will not be processed. The form requires the following information:
The specific policy or standard from which an exception is requested.
A detailed reason for the exception, including why compliance is infeasible or creates undue hardship.
Proposed alternative or compensating security measures, if applicable.
Requested start and expiration dates.
Potential risks associated with the exception.
Mitigating controls to address identified risks.
Requests involving systems or services supported by an LTS Computing Consultant or departmental IT liaison should be submitted by that individual on behalf of the requester. This ensures the request is technically complete and the appropriate LTS contact is engaged from the outset.
3.2 Review and Approval
The Information Security Office will review the submitted request and may consult with relevant stakeholders, including senior leaders who would be affected if the exception leads to a compromise. The ISO will approve or deny the request based on the following factors:
The legitimacy of the business or academic need.
The level of risk introduced by the exception, evaluated against Lehigh's risk rating framework.
The adequacy of proposed mitigating controls.
Approval authority is tiered as follows:
Standard exceptions: Approved by the CISO or designee.
High or Critical risk exceptions: Require CISO approval and notification to the CIO.
3.3 Denial and Appeals
If a request is denied, the ISO will communicate the rationale to the requester. Denied requests may be reconsidered if the requester provides additional information or substantially revised mitigating controls. If the requester believes the denial is unwarranted, the matter may be escalated to the CISO for reconsideration. The CISO's determination is final.
3.4 Documentation and Monitoring
Approved exceptions will be documented in the ISO's exception register, including the rationale, approval authority, duration, affected system or service, and any mitigating controls. The ISO will monitor compliance with the terms of each exception and may revoke an exception if:
The mitigating controls are not maintained as agreed.
The risk profile of the exception materially changes.
A security incident occurs that is related to the excepted control.
3.5 Renewal and Expiration
All exceptions expire on the date specified in the approved request. Expired exceptions are not automatically renewed. If continued need exists, the requester must submit a new exception request prior to expiration. The ISO will issue a reminder to the requester and the associated LTS contact 30 days before expiration. If an exception expires without renewal, the system or practice must return to compliance immediately.
Responsibilities
Requester: Should be the LTS Computing Consultant or analogous individual technically supporting the device or person needing the exception. Provide complete and accurate information in the exception request. Implement and maintain any agreed-upon mitigating controls. Notify the ISO if the risk profile changes or the exception is no longer needed.
Information Security Office: Review and approve or deny requests in a timely manner. Maintain the exception register. Monitor compliance and manage risks associated with granted exceptions. Issue expiration reminders 30 days prior to exception end dates.
Contact
For questions or assistance, contact the Information Security Office at security@lehigh.edu.