Press ESC to close or Enter to search

Home
About Us
Services
Pricing
Tools
Resources
Contact
Get Started
Live Security Feed
Your IPDetecting...
NCSCUK organisations urged to strengthen cyber defences ALERTPhishing attacks targeting Microsoft 365 users on the rise CISACritical vulnerabilities identified in popular software NEWSRansomware groups increasingly targeting SME businesses NCSCNew guidance released for securing remote workers ALERTBusiness email compromise attacks cost UK firms millions CISAZero-day exploits require immediate patching attention NEWSAI-powered threats becoming more sophisticated in 2025 NCSCUK organisations urged to strengthen cyber defences ALERTPhishing attacks targeting Microsoft 365 users on the rise CISACritical vulnerabilities identified in popular software NEWSRansomware groups increasingly targeting SME businesses NCSCNew guidance released for securing remote workers ALERTBusiness email compromise attacks cost UK firms millions CISAZero-day exploits require immediate patching attention NEWSAI-powered threats becoming more sophisticated in 2025
View Dashboard

Compensating Control

Vulnerability Management

Alternative security measure implemented when a primary control cannot be applied.

A compensating control is an alternative security measure used when the primary or recommended control cannot be implemented—due to technical constraints, business requirements, or legacy systems. For example, if a system cannot be patched, compensating controls might include network segmentation, enhanced monitoring, and restricted access. Compensating controls must provide equivalent protection and should be documented, justified, and regularly reviewed. They're a risk management tool, not a permanent solution.

Why It Matters

The DSC Perspective:

Real-world constraints sometimes prevent ideal security controls. Compensating controls enable risk management when perfect isn't possible. Document compensating controls and plan to implement primary controls when constraints allow.

Related Terms