A formal process for temporarily or permanently exempting a system or process from a security requirement with documented risk acceptance.