11.07.2015 Views

General Exception Request with Remediation Plan Form - Office of ...

General Exception Request with Remediation Plan Form - Office of ...

General Exception Request with Remediation Plan Form - Office of ...

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>General</strong> <strong>Exception</strong> <strong>Request</strong> <strong>with</strong> <strong>Remediation</strong> <strong>Plan</strong><strong>Office</strong> <strong>of</strong> Compliance ServicesInformation Security924 Westwood Blvd, Suite #520Los Angeles, CA 90095-7067DO NOT USE THIS FORM FOR LAPTOP ENCRYPTION ,TIMEOUT EXCEPTION AND GENERAL EXCEPTION REQUESTS THAT DONOT REQUIRE A REMEDIATION PLANFor those requests, find custom forms at http://compliance.uclahealth.org/body.cfm?id=70Instructions:• Use this form to request policy exceptions when non-compliance <strong>with</strong> a policy provision is identified and there is aremediation plan to resolve the non-compliance.• <strong>Request</strong>ors should complete the first two pages and then email to the <strong>Office</strong> <strong>of</strong> Compliance Services - Information Security,InfoSecAll@mednet.ucla.edu.• If you need more space than the form provides, you may send any additional documentation <strong>with</strong> the form.• If all necessary information is not provided, the form will be returned to you. Ask your CSC if you need some help <strong>with</strong> thetechnical issues.• If you have any questions, please contact your CSC or the <strong>Office</strong> <strong>of</strong> Compliance Services - Information Security, (310)794-8638<strong>Request</strong>or InformationNamePhoneEmailDateTitleDeptIT Support ContactPolicy statement for which an <strong>Exception</strong> is being requestedAll Devices that are connected to a UCLA network whether owned by UCLA or others shall becontinually executing approved virus scanning s<strong>of</strong>tware <strong>with</strong> current virus definitions.UCLA Health shall run versions <strong>of</strong> operating systems and application s<strong>of</strong>tware for which securitypatches are made available in a timely manner on network Devices.Wireless Access Points must comply <strong>with</strong> HS Policy No. 9457, "Minimum Security Standards,"Appendix IV, "Wireless Communication Configuration Standard."OTHERIf there is not enough space on this form to describe the issue(s) and the remediationplan, please provide the information requested in a separate Word document.Describe in detail why your area is not currently in compliance on this issue. Include informationon the processes/applications/systems and users involved.Revision date: 07/22/12Page 1 <strong>of</strong> 3


<strong>General</strong> <strong>Exception</strong> <strong>Request</strong> & <strong>Remediation</strong> <strong>Plan</strong>How many systems and/or users are affected?Describe any controls that are in place now or could be added soon to mitigate the noncompliance.Describe in detail how the issue will be brought into compliance.Can remediation be done in stages so higher risk issues can be resolved earlier? If so, pleasedescribe the stages and include a timeline.What is the final completion date for the remediation?Revision date: 07/22/12 Page 2 <strong>of</strong> 3


<strong>General</strong> <strong>Exception</strong> <strong>Request</strong> & <strong>Remediation</strong> <strong>Plan</strong>Information Security ReviewReviewerDateApprove exception request?YESNOCommentsLeadership ReviewReviewerDateApprove exception request?YESNOCommentsRevision date: 07/22/12Page 3 <strong>of</strong> 3

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!