SAMMY UI is optimized for resolutions with a width 1024px and higher.
Policy Exception Process
GRC-04: Is an approved exception process mandated by the governance program established and followed whenever a deviation from an established policy occurs?
The exception process should be defined and approved by the management team and communicated across the organization to promote adherence. Integrate exemptions with the information security risk management process, and review organizational risks whenever a deviation from an established policy occurs.
Control implemented
Control ownership
Description

Establish and follow an approved exception process as mandated by the governance program whenever a deviation from an established policy occurs.