Policy sprawl (and the exception register)

term

networkinggovernance & risk

The accumulation of rules and exceptions that outgrows anyone's ability to review them, ending in permits nobody can justify and nobody dares remove.

It is the practical ceiling on granularity: per-workload policy on an estate that cannot maintain per-workload rules produces stale permits that quietly become permanent. A microsegmentation deployment full of allow-any exceptions reports coverage it does not have, and is less honest than a well-run tiered design. The countermeasure is unglamorous - treat exceptions as a register with named owners and review dates, since that list, rather than the policy document, is the real record of where risk sits.

Also known as: rule explosion, stale permits, allow-any exception, firewall cruft

All glossary entries