ITS Standards Exception - Exclusion from Vulnerability Patching

Tags Exception

Request an exception from applying a required software update or patch due to business or technical limitations.

Description and Details

ITS regularly applies security patches and updates to County-managed systems to address known vulnerabilities. However, in rare cases, applying a patch may disrupt a critical business process, conflict with legacy software, or introduce compatibility issues.

This request allows employees or system owners to request a temporary or ongoing exception from applying a required patch or update. A valid justification is required, such as evidence that the patch breaks functionality or causes system failure.

All requests are reviewed by ITS Information Security to assess risk and determine whether compensating controls are required.

Who Can Submit This Request?

Any Gwinnett County employee or system owner with a valid technical justification.

Required Approvals

  • Manager Approval

  • ITS Information Security

  • Chief Information Security Officer (CISO)

  • Chief Information Officer (CIO)

Fulfillment Time Frame

Within one business day following manager approval. Additional time may be needed if risk analysis or coordination with vendors is required.

Support Contacts

For any questions, comments, or concerns, please contact the IT Service Desk.