Alternative security measure implemented when a primary control cannot be applied.
A compensating control is an alternative security measure used when the primary or recommended control cannot be implemented—due to technical constraints, business requirements, or legacy systems. For example, if a system cannot be patched, compensating controls might include network segmentation, enhanced monitoring, and restricted access. Compensating controls must provide equivalent protection and should be documented, justified, and regularly reviewed. They're a risk management tool, not a permanent solution.
Why It Matters
The DSC Perspective:
Real-world constraints sometimes prevent ideal security controls. Compensating controls enable risk management when perfect isn't possible. Document compensating controls and plan to implement primary controls when constraints allow.
