home/glossary/compensating control

compensating control

nounverified·updated May 18, 2026

A management, operational, and/or technical control (e.g., safeguard or countermeasure) employed by an organization in lieu of a recommended security control in the low, moderate, or high baselines that provides equivalent or comparable protection for an information system.

MWEFederal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

Senses

NY DFS Part 500 (NYCRR Title 23, Chapter 1, Part 500)

An internal control that reduces the risk of an existing or potential control weakness that could result in errors or omissions. Compensating controls may be considered when an organization does not wish to meet a requirement explicitly as stated, due to legitimate technical or documented business constraints but has sufficiently mitigated the risk associated with the requirement through implementation of other controls. Compensating controls must • meet the intent and rigor of the original stated requirement; • repel a compromise attempt with similar force; • be above and beyond other PCI DSS requirements (not simply in compliance with other PCI DSS requirements); and • be commensurate with the additional risk imposed by not adhering to the originally stated requirement.

NIST SP 800-171r3attested usage pack match

No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.

Classifications

Entity Type

Control95%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated85%rule-basedr:sens.regulated.framework.v1
?unassignedlast reviewed

Information Class

unclassified

Variants

plural
compensating controls
possessive
compensating control's
pluralpossessive
compensating controls'