The reference desk / In practice

Compensating control

An alternative safeguard used in place of a specified control, with evidence that it provides comparable protection for the intended security objective.

What it means

A compensating control addresses the security objective of a preferred control that cannot be implemented as intended. The reason might be a technical limitation, an operational constraint, or an incompatible system. The alternative needs a defensible relationship to the original risk; doing something convenient is not enough. Some compensating controls are temporary while a fix is prepared, while others remain necessary and require ongoing justification. Applicable standards may define specific acceptance requirements. The decision should identify the owner, remaining exposure, evidence of effectiveness, and conditions for review.

AN ILLUSTRATIVE SCENARIO

A legacy machine cannot be patched yet

A manufacturer discovers a vulnerability in software supporting a production machine. The supplier cannot validate a patch before the next maintenance window. The team examines the attack path and restricts access to a dedicated maintenance workstation, removes unnecessary network routes, and adds monitoring for the relevant activity. Operations verifies the restriction does not undermine safe operation. The risk owner records what remains exposed and the expected patch plan. The restrictions reduce particular opportunities; they do not remove the software defect.

Put it to work

  1. Describe the missing control's purpose and the actual path to harm. Record why the preferred control is unavailable and whether a requirement permits an alternative or needs a formal exception.
  2. Select an alternative that addresses that path, assess its operational effects, and test it. Explain which threats it reduces and which remain possible rather than calling the substitute equivalent without evidence.
  3. Assign an accountable owner and review condition, such as a patch release or service change. Keep temporary deadlines visible and periodically reassess ongoing alternatives against current risk and obligations.

How to check your work

Exercise the relevant attack path safely in a test environment or controlled validation. Confirm the alternative interrupts that path, legitimate work remains possible, and the exception record accurately describes residual risk and the next review.

Connect the ideas

  • Control

    A process, configuration, or technology meant to reduce a named risk or detect a named failure.

  • Residual risk

    The risk that remains after selected controls, including the uncertainty you still accept.

  • Patch

    A vendor or internal change that removes or reduces a vulnerability in running software.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.