Procedure for Cyber Security Exception Request

Cyber Security Exception Request must be raised by the person (or CSC) responsible for implementing the standards or controls. An email with the following information can be sent to Cybersecurity Operations team (security@ust.hk).

  1. State the policy / standard for which exception is being requested.
  2. State the specific servers or web applications  for which exception is being requested.
  3. Data classification category of the servers or web applications.
  4. Type of data that will be affected.
  5. Reason why an exception is required.
  6. Proposed assessment of potential risk.
  7. Proposed plan for managing or mitigating those risks.
  8. Anticipated length of non-compliance.
  9. Proposed review date to evaluate progress.
  10. Any additional information as needed.

On receiving the above information, Cybersecurity Operations team will :

  1. Check if all information are well received and documented.
  2. Evaluate the exception request by IT Security Officer. IT Security Officer may communicate and/or work with the requestor or CSC to understand the situation. If found not appropriate, IT Security Officer may reject the exception request.
  3. Confirm the receipt of the exception request. A confirmation email, together with any comments from the IT Security Officer, will be sent to the requestor and CC: the correspinding Head of Department and CSC. If no further concern being received from the Head of Department, the exception request will be assumed to be reviewed and approved by the Head of Department.
  4. File the exception request until the next proposed review date.