A compensating control is a security measure implemented to satisfy the requirements of a primary security control that is impractical or impossible to implement.
A compensating control is indeed a security measure put in place when a primary security control is inadequate or cannot be implemented. These controls provide an alternative means to achieve the desired level of security, ensuring the vulnerability is still addressed adequately. For example, if an organization cannot encrypt data at rest due to performance constraints, it might implement enhanced access controls and monitoring as compensating controls.
Learn More
AI Generated Content may display inaccurate information, always double-check anything important.
What are some examples of compensating controls?
How do compensating controls fit into an overall security strategy?
Can compensating controls ever be a permanent solution?