CISSP GLOSSARY · RISK MANAGEMENT & GOVERNANCE
Compensating control
An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.
A compensating control is an alternative safeguard put in place when a required primary control is not feasible, whether for cost, technical, or business reasons. Rather than leaving the requirement unmet, the organisation implements a different mechanism that achieves the same protective objective. A legacy system that cannot support modern authentication might be compensated with network isolation, tightened monitoring, and restricted physical access.
The bar that decides exam answers is equivalence. A valid compensating control must meet the intent and rigour of the original requirement, provide a comparable level of defence, and be commensurate with the risk. It is not a discount option: PCI DSS, the standard that formalised the concept, requires the compensation to go above and beyond what other requirements already demand. Nor does it remove the obligation to document why the primary control was infeasible, and the residual risk that remains still needs formal acceptance.
Exam relevance: if a scenario says a required control “cannot be implemented” and asks what to deploy instead, the answer is a compensating control. When one person must hold conflicting duties because the team is too small for separation of duties, increased audit logging and supervisory review is the textbook compensation. Distinguish it from the other control types: those describe what a control does, while compensating describes why it exists, a stand-in judged against the original requirement.